{ "SchemaVersion": 2, "Trivy": { "Version": "0.74.0" }, "ReportID": "01a0a031-5163-772d-a4fa-e9c174ed058b", "CreatedAt": "2026-09-14T13:53:01.795473157Z", "ArtifactID": "sha256:5e3704ea581305776a643c58dbedfc0cc2e72f31ae7a3a4b073fb87e48af539a", "ArtifactName": "postgres:17-alpine", "ArtifactType": "container_image", "Metadata": { "Size": 300003840, "OS": { "Family": "alpine", "Name": "3.24.1" }, "ImageID": "sha256:18cfe3ef5e6815560c98237d6216d1e5119702fb0f3894c8785dd58b8bbe5d73", "DiffIDs": [ "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c", "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226", "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58", "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e", "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99", "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0", "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0", "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d", "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242", "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212" ], "RepoTags": [ "postgres:17-alpine" ], "RepoDigests": [ "postgres@sha256:18cfe3ef5e6815560c98237d6216d1e5119702fb0f3894c8785dd58b8bbe5d73" ], "Reference": "postgres:17-alpine", "ImageConfig": { "architecture": "amd64", "created": "2026-08-13T19:17:35.122910679Z", "history": [ { "created": "2026-06-16T00:01:29Z", "created_by": "ADD alpine-minirootfs-3.24.1-x86_64.tar.gz / # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-06-16T00:01:29Z", "created_by": "CMD [\"/bin/sh\"]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:15:15Z", "created_by": "RUN /bin/sh -c set -eux; \taddgroup -g 70 -S postgres; \tadduser -u 70 -S -D -G postgres -H -h /var/lib/postgresql -s /bin/sh postgres; \tinstall --verbose --directory --owner postgres --group postgres --mode 1777 /var/lib/postgresql # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:15:18Z", "created_by": "ENV GOSU_VERSION=1.19", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:15:18Z", "created_by": "RUN /bin/sh -c set -eux; \t\tapk add --no-cache --virtual .gosu-deps \t\tca-certificates \t\tdpkg \t\tgnupg \t; \t\tdpkgArch=\"$(dpkg --print-architecture | awk -F- '{ print $NF }')\"; \twget -O /usr/local/bin/gosu \"https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$dpkgArch\"; \twget -O /usr/local/bin/gosu.asc \"https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$dpkgArch.asc\"; \t\texport GNUPGHOME=\"$(mktemp -d)\"; \tgpg --batch --keyserver hkps://keys.openpgp.org --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4; \tgpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu; \tgpgconf --kill all; \trm -rf \"$GNUPGHOME\" /usr/local/bin/gosu.asc; \t\tapk del --no-network .gosu-deps; \t\tchmod +x /usr/local/bin/gosu; \tgosu --version; \tgosu nobody true # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:15:18Z", "created_by": "ENV LANG=en_US.utf8", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:15:18Z", "created_by": "RUN /bin/sh -c mkdir /docker-entrypoint-initdb.d # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:15:18Z", "created_by": "ENV PG_MAJOR=17", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:15:18Z", "created_by": "ENV PG_VERSION=17.11", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:15:18Z", "created_by": "ENV PG_SHA256=dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:15:18Z", "created_by": "ENV DOCKER_PG_LLVM_DEPS=llvm21-dev \t\tclang21", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:17:34Z", "created_by": "RUN /bin/sh -c set -eux; \t\twget -O postgresql.tar.bz2 \"https://ftp.postgresql.org/pub/source/v$PG_VERSION/postgresql-$PG_VERSION.tar.bz2\"; \techo \"$PG_SHA256 *postgresql.tar.bz2\" | sha256sum -c -; \tmkdir -p /usr/src/postgresql; \ttar \t\t--extract \t\t--file postgresql.tar.bz2 \t\t--directory /usr/src/postgresql \t\t--strip-components 1 \t; \trm postgresql.tar.bz2; \t\tapk add --no-cache --virtual .build-deps \t\t$DOCKER_PG_LLVM_DEPS \t\tbison \t\tcoreutils \t\tdpkg-dev dpkg \t\tflex \t\tg++ \t\tgcc \t\tkrb5-dev \t\tlibc-dev \t\tlibedit-dev \t\tlibxml2-dev \t\tlibxslt-dev \t\tlinux-headers \t\tmake \t\topenldap-dev \t\topenssl-dev \t\tperl-dev \t\tperl-ipc-run \t\tperl-utils \t\tpython3-dev \t\ttcl-dev \t\tutil-linux-dev \t\tzlib-dev \t\ticu-dev \t\tlz4-dev \t\tzstd-dev \t; \t\tcd /usr/src/postgresql; \tawk '$1 == \"#define\" \u0026\u0026 $2 == \"DEFAULT_PGSOCKET_DIR\" \u0026\u0026 $3 == \"\\\"/tmp\\\"\" { $3 = \"\\\"/var/run/postgresql\\\"\"; print; next } { print }' src/include/pg_config_manual.h \u003e src/include/pg_config_manual.h.new; \tgrep '/var/run/postgresql' src/include/pg_config_manual.h.new; \tmv src/include/pg_config_manual.h.new src/include/pg_config_manual.h; \tgnuArch=\"$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)\"; \t\texport LLVM_CONFIG=\"/usr/lib/llvm21/bin/llvm-config\"; \texport CLANG=clang-21; \t\t./configure \t\t--enable-option-checking=fatal \t\t--build=\"$gnuArch\" \t\t--enable-integer-datetimes \t\t--enable-tap-tests \t\t--disable-rpath \t\t--with-uuid=e2fs \t\t--with-pgport=5432 \t\t--with-system-tzdata=/usr/share/zoneinfo \t\t--prefix=/usr/local \t\t--with-includes=/usr/local/include \t\t--with-libraries=/usr/local/lib \t\t--with-gssapi \t\t--with-icu \t\t--with-ldap \t\t--with-libxml \t\t--with-libxslt \t\t--with-llvm \t\t--with-lz4 \t\t--with-openssl \t\t--with-perl \t\t--with-python \t\t--with-tcl \t\t--with-zstd \t; \tmake -j \"$(nproc)\" world-bin; \tmake install-world-bin; \tmake -C contrib install; \t\trunDeps=\"$( \t\tscanelf --needed --nobanner --format '%n#p' --recursive /usr/local \t\t\t| tr ',' '\\n' \t\t\t| sort -u \t\t\t| awk 'system(\"[ -e /usr/local/lib/\" $1 \" ]\") == 0 { next } { print \"so:\" $1 }' \t\t\t| grep -v -e perl -e python -e tcl \t)\"; \tapk add --no-cache --virtual .postgresql-rundeps \t\t$runDeps \t\tbash \t\ttzdata \t\tzstd \t\ticu-data-full \t\t$([ \"$(apk --print-arch)\" != 'ppc64le' ] \u0026\u0026 echo 'nss_wrapper') \t; \tapk del --no-network .build-deps; \tcd /; \trm -rf \t\t/usr/src/postgresql \t\t/usr/local/share/doc \t\t/usr/local/share/man \t; \t\tpostgres --version # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:17:34Z", "created_by": "RUN /bin/sh -c set -eux; \tcp -v /usr/local/share/postgresql/postgresql.conf.sample /usr/local/share/postgresql/postgresql.conf.sample.orig; \tsed -ri \"s!^#?(listen_addresses)\\s*=\\s*\\S+.*!\\1 = '*'!\" /usr/local/share/postgresql/postgresql.conf.sample; \tgrep -F \"listen_addresses = '*'\" /usr/local/share/postgresql/postgresql.conf.sample # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:17:34Z", "created_by": "RUN /bin/sh -c install --verbose --directory --owner postgres --group postgres --mode 3777 /var/run/postgresql # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:17:34Z", "created_by": "ENV PGDATA=/var/lib/postgresql/data", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:17:35Z", "created_by": "RUN /bin/sh -c install --verbose --directory --owner postgres --group postgres --mode 1777 \"$PGDATA\" # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:17:35Z", "created_by": "VOLUME [/var/lib/postgresql/data]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:17:35Z", "created_by": "COPY docker-entrypoint.sh docker-ensure-initdb.sh /usr/local/bin/ # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:17:35Z", "created_by": "RUN /bin/sh -c ln -sT docker-ensure-initdb.sh /usr/local/bin/docker-enforce-initdb.sh # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-08-13T19:17:35Z", "created_by": "ENTRYPOINT [\"docker-entrypoint.sh\"]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:17:35Z", "created_by": "STOPSIGNAL SIGINT", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:17:35Z", "created_by": "EXPOSE map[5432/tcp:{}]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-08-13T19:17:35Z", "created_by": "CMD [\"postgres\"]", "comment": "buildkit.dockerfile.v0", "empty_layer": true } ], "os": "linux", "rootfs": { "type": "layers", "diff_ids": [ "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c", "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226", "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58", "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e", "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99", "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0", "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0", "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d", "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242", "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212" ] }, "config": { "Cmd": [ "postgres" ], "Entrypoint": [ "docker-entrypoint.sh" ], "Env": [ "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", "GOSU_VERSION=1.19", "LANG=en_US.utf8", "PG_MAJOR=17", "PG_VERSION=17.11", "PG_SHA256=dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "DOCKER_PG_LLVM_DEPS=llvm21-dev \t\tclang21", "PGDATA=/var/lib/postgresql/data" ], "Volumes": { "/var/lib/postgresql/data": {} }, "WorkingDir": "/", "ExposedPorts": { "5432/tcp": {} }, "StopSignal": "SIGINT" } }, "Layers": [ { "Size": 8697856, "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, { "Size": 11264, "Digest": "sha256:4d80c046a9c75283330c9ea2f7f3e5b3fbfe521c980e19d4164116dd95dfc730", "DiffID": "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226" }, { "Size": 1988096, "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, { "Size": 1536, "Digest": "sha256:a12187db4b1792bf47380df49cfd84fd703811abd04c5d84568001a484afbf2d", "DiffID": "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e" }, { "Size": 289209344, "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, { "Size": 66560, "Digest": "sha256:75de48f507ff913f69fa75a49da59f83db0ece385f649eefa7bcde930a9b573e", "DiffID": "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0" }, { "Size": 2048, "Digest": "sha256:d884d6f49732553e9690257554497e612cdcc1a6d83562fe08d582dec39e34e9", "DiffID": "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0" }, { "Size": 3072, "Digest": "sha256:b36c1b75fdb7939cb2a580ab05adfa65c8b118425f42cd8811cf632f37bb8616", "DiffID": "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d" }, { "Size": 20992, "Digest": "sha256:f070a657786685e37135e54207238cd1580e6869c6f5e8e6da85b2c9871ab31e", "DiffID": "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242" }, { "Size": 3072, "Digest": "sha256:7f3590dcd8434508e0c0bd953c80ed459f14f3a9005a3ac945bdb855abe58389", "DiffID": "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212" } ] }, "Results": [ { "Target": "postgres:17-alpine (alpine 3.24.1)", "Class": "os-pkgs", "Type": "alpine", "Packages": [ { "ID": ".postgresql-rundeps@20260813.191733", "Name": ".postgresql-rundeps", "Identifier": { "PURL": "pkg:apk/alpine/.postgresql-rundeps@20260813.191733?arch=noarch\u0026distro=3.24.1", "UID": "3e859114216d029b" }, "Version": "20260813.191733", "Arch": "noarch", "DependsOn": [ "bash@5.3.9-r1", "icu-data-full@78.1-r0", "icu-libs@78.1-r0", "krb5-libs@1.22.2-r1", "libcrypto3@3.5.7-r0", "libedit@20260508.3.1-r1", "libgcc@15.2.0-r5", "libldap@2.6.14-r0", "libssl3@3.5.7-r0", "libstdc++@15.2.0-r5", "libuuid@2.42.1-r0", "libxml2@2.13.9-r2", "libxslt@1.1.43-r3", "llvm21-libs@21.1.8-r1", "lz4-libs@1.10.0-r1", "musl@1.2.6-r2", "nss_wrapper@1.1.12-r1", "tzdata@2026c-r0", "zlib@1.3.2-r0", "zstd-libs@1.5.7-r2", "zstd@1.5.7-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:e22124318c23791fa7e066f4281f078493b426be", "AnalyzedBy": "apk" }, { "ID": "alpine-baselayout@3.7.2-r1", "Name": "alpine-baselayout", "Identifier": { "PURL": "pkg:apk/alpine/alpine-baselayout@3.7.2-r1?arch=x86_64\u0026distro=3.24.1", "UID": "1b9c543300f8073e" }, "Version": "3.7.2-r1", "Arch": "x86_64", "SrcName": "alpine-baselayout", "SrcVersion": "3.7.2-r1", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "alpine-baselayout-data@3.7.2-r1", "busybox-binsh@1.37.0-r31" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:f0fcfdc2f4da058af6473bc45c4eab62916225b2", "InstalledFiles": [ "etc/motd", "etc/crontabs/root", "etc/modprobe.d/aliases.conf", "etc/modprobe.d/blacklist.conf", "etc/modprobe.d/i386.conf", "etc/profile.d/20locale.sh", "etc/profile.d/README", "etc/profile.d/color_prompt.sh.disabled", "usr/lib/sysctl.d/00-alpine.conf", "var/lock", "var/run", "var/spool/mail", "var/spool/cron/crontabs" ], "AnalyzedBy": "apk" }, { "ID": "alpine-baselayout-data@3.7.2-r1", "Name": "alpine-baselayout-data", "Identifier": { "PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.2-r1?arch=x86_64\u0026distro=3.24.1", "UID": "fcc3cd90122d8aa7" }, "Version": "3.7.2-r1", "Arch": "x86_64", "SrcName": "alpine-baselayout", "SrcVersion": "3.7.2-r1", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:c6f9bded17d844b6f1b0bb5766d2c35c0d5c8508", "InstalledFiles": [ "etc/fstab", "etc/group", "etc/hostname", "etc/hosts", "etc/inittab", "etc/modules", "etc/mtab", "etc/nsswitch.conf", "etc/passwd", "etc/profile", "etc/protocols", "etc/services", "etc/shadow", "etc/shells", "etc/sysctl.conf" ], "AnalyzedBy": "apk" }, { "ID": "alpine-keys@2.6-r0", "Name": "alpine-keys", "Identifier": { "PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.24.1", "UID": "cb1f6c8fa74713e0" }, "Version": "2.6-r0", "Arch": "x86_64", "SrcName": "alpine-keys", "SrcVersion": "2.6-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:d8d6b80e53c059a77e4915da78ba964f3ffea240", "InstalledFiles": [ "etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", "etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", "usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", "usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub" ], "AnalyzedBy": "apk" }, { "ID": "alpine-release@3.24.1-r0", "Name": "alpine-release", "Identifier": { "PURL": "pkg:apk/alpine/alpine-release@3.24.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "6cfad6f36e1f31aa" }, "Version": "3.24.1-r0", "Arch": "x86_64", "SrcName": "alpine-base", "SrcVersion": "3.24.1-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "alpine-keys@2.6-r0" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:bc6912a25cdc7733e0035ed509eceaa4026946e3", "InstalledFiles": [ "etc/alpine-release", "etc/issue", "etc/os-release", "etc/secfixes.d/alpine", "usr/lib/os-release" ], "AnalyzedBy": "apk" }, { "ID": "apk-tools@3.0.6-r0", "Name": "apk-tools", "Identifier": { "PURL": "pkg:apk/alpine/apk-tools@3.0.6-r0?arch=x86_64\u0026distro=3.24.1", "UID": "c6097cc137f3de8c" }, "Version": "3.0.6-r0", "Arch": "x86_64", "SrcName": "apk-tools", "SrcVersion": "3.0.6-r0", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "ca-certificates-bundle@20260611-r0", "libapk@3.0.6-r0", "libcrypto3@3.5.7-r0", "musl@1.2.6-r2", "zlib@1.3.2-r0" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:043333589798a1f52e09ae63f026c6c8fa676d34", "InstalledFiles": [ "sbin/apk" ], "AnalyzedBy": "apk" }, { "ID": "bash@5.3.9-r1", "Name": "bash", "Identifier": { "PURL": "pkg:apk/alpine/bash@5.3.9-r1?arch=x86_64\u0026distro=3.24.1", "UID": "89d1544dc9bae858" }, "Version": "5.3.9-r1", "Arch": "x86_64", "SrcName": "bash", "SrcVersion": "5.3.9-r1", "Licenses": [ "GPL-3.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r31", "musl@1.2.6-r2", "readline@8.3.3-r1" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:2ce9606f1c31438297b40df5875dbceb66afb675", "InstalledFiles": [ "bin/bash", "etc/bash/bashrc", "etc/profile.d/00-bashrc.sh", "usr/lib/bash/accept", "usr/lib/bash/basename", "usr/lib/bash/chmod", "usr/lib/bash/csv", "usr/lib/bash/cut", "usr/lib/bash/dirname", "usr/lib/bash/dsv", "usr/lib/bash/fdflags", "usr/lib/bash/finfo", "usr/lib/bash/fltexpr", "usr/lib/bash/getconf", "usr/lib/bash/head", "usr/lib/bash/id", "usr/lib/bash/kv", "usr/lib/bash/ln", "usr/lib/bash/logname", "usr/lib/bash/mkdir", "usr/lib/bash/mkfifo", "usr/lib/bash/mktemp", "usr/lib/bash/mypid", "usr/lib/bash/pathchk", "usr/lib/bash/print", "usr/lib/bash/printenv", "usr/lib/bash/push", "usr/lib/bash/realpath", "usr/lib/bash/rm", "usr/lib/bash/rmdir", "usr/lib/bash/seq", "usr/lib/bash/setpgid", "usr/lib/bash/sleep", "usr/lib/bash/stat", "usr/lib/bash/strftime", "usr/lib/bash/strptime", "usr/lib/bash/sync", "usr/lib/bash/tee", "usr/lib/bash/truefalse", "usr/lib/bash/tty", "usr/lib/bash/uname", "usr/lib/bash/unlink", "usr/lib/bash/whoami" ], "AnalyzedBy": "apk" }, { "ID": "busybox@1.37.0-r31", "Name": "busybox", "Identifier": { "PURL": "pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", "UID": "771020c43c8440bf" }, "Version": "1.37.0-r31", "Arch": "x86_64", "SrcName": "busybox", "SrcVersion": "1.37.0-r31", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:b5405ebc02f7dd8be95b6265c54b243d5456ab8f", "InstalledFiles": [ "bin/busybox", "etc/securetty", "etc/busybox-paths.d/busybox", "etc/logrotate.d/acpid", "etc/network/if-up.d/dad", "etc/udhcpc/udhcpc.conf", "usr/share/udhcpc/default.script" ], "AnalyzedBy": "apk" }, { "ID": "busybox-binsh@1.37.0-r31", "Name": "busybox-binsh", "Identifier": { "PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", "UID": "1ec8a3d5d2b63297" }, "Version": "1.37.0-r31", "Arch": "x86_64", "SrcName": "busybox", "SrcVersion": "1.37.0-r31", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", "DependsOn": [ "busybox@1.37.0-r31" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:5cbd14acc6f1804c5bac6c77dc2c492f010b0fc7", "InstalledFiles": [ "bin/sh" ], "AnalyzedBy": "apk" }, { "ID": "ca-certificates-bundle@20260611-r0", "Name": "ca-certificates-bundle", "Identifier": { "PURL": "pkg:apk/alpine/ca-certificates-bundle@20260611-r0?arch=x86_64\u0026distro=3.24.1", "UID": "20337c2ea28bef28" }, "Version": "20260611-r0", "Arch": "x86_64", "SrcName": "ca-certificates", "SrcVersion": "20260611-r0", "Licenses": [ "MPL-2.0", "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:c9534a03750bdfae341f10969016090fc11febbd", "InstalledFiles": [ "etc/ssl/cert.pem", "etc/ssl/certs/ca-certificates.crt", "etc/ssl1.1/cert.pem", "etc/ssl1.1/certs" ], "AnalyzedBy": "apk" }, { "ID": "gdbm@1.26-r0", "Name": "gdbm", "Identifier": { "PURL": "pkg:apk/alpine/gdbm@1.26-r0?arch=x86_64\u0026distro=3.24.1", "UID": "5eb1a3f86262ca77" }, "Version": "1.26-r0", "Arch": "x86_64", "SrcName": "gdbm", "SrcVersion": "1.26-r0", "Licenses": [ "GPL-3.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:619493d8124fe49a8ee1d8f7a1372cf7e3977337", "InstalledFiles": [ "usr/lib/libgdbm.so.6", "usr/lib/libgdbm.so.6.0.0", "usr/lib/libgdbm_compat.so.4", "usr/lib/libgdbm_compat.so.4.0.0" ], "AnalyzedBy": "apk" }, { "ID": "icu-data-full@78.1-r0", "Name": "icu-data-full", "Identifier": { "PURL": "pkg:apk/alpine/icu-data-full@78.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "4fa30f43b2e5f036" }, "Version": "78.1-r0", "Arch": "x86_64", "SrcName": "icu", "SrcVersion": "78.1-r0", "Licenses": [ "ICU" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:1a2db5e6bc16c62c85c29cfc8897570f9051cf14", "InstalledFiles": [ "usr/share/icu/78.1/icudt78l.dat" ], "AnalyzedBy": "apk" }, { "ID": "icu-libs@78.1-r0", "Name": "icu-libs", "Identifier": { "PURL": "pkg:apk/alpine/icu-libs@78.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "66c4aa79b293e4ff" }, "Version": "78.1-r0", "Arch": "x86_64", "SrcName": "icu", "SrcVersion": "78.1-r0", "Licenses": [ "ICU" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "icu-data-full@78.1-r0", "libgcc@15.2.0-r5", "libstdc++@15.2.0-r5", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:46bd3617f6d112f035d806d24c5cf8ea6e597f50", "InstalledFiles": [ "usr/lib/libicudata.so.78", "usr/lib/libicudata.so.78.1", "usr/lib/libicui18n.so.78", "usr/lib/libicui18n.so.78.1", "usr/lib/libicuio.so.78", "usr/lib/libicuio.so.78.1", "usr/lib/libicuuc.so.78", "usr/lib/libicuuc.so.78.1" ], "AnalyzedBy": "apk" }, { "ID": "keyutils-libs@1.6.3-r4", "Name": "keyutils-libs", "Identifier": { "PURL": "pkg:apk/alpine/keyutils-libs@1.6.3-r4?arch=x86_64\u0026distro=3.24.1", "UID": "a1a29120eb342032" }, "Version": "1.6.3-r4", "Arch": "x86_64", "SrcName": "keyutils", "SrcVersion": "1.6.3-r4", "Licenses": [ "GPL-2.0-or-later", "LGPL-2.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:b7331c96f077fc3522ee4361a441d1097204cd90", "InstalledFiles": [ "usr/lib/libkeyutils.so.1", "usr/lib/libkeyutils.so.1.10" ], "AnalyzedBy": "apk" }, { "ID": "krb5-conf@1.0-r2", "Name": "krb5-conf", "Identifier": { "PURL": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=3.24.1", "UID": "e7cf94ba8b6dbc33" }, "Version": "1.0-r2", "Arch": "x86_64", "SrcName": "krb5-conf", "SrcVersion": "1.0-r2", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:40a11e0690a59e110367b62a80661024e9942a2d", "InstalledFiles": [ "etc/krb5.conf" ], "AnalyzedBy": "apk" }, { "ID": "krb5-libs@1.22.2-r1", "Name": "krb5-libs", "Identifier": { "PURL": "pkg:apk/alpine/krb5-libs@1.22.2-r1?arch=x86_64\u0026distro=3.24.1", "UID": "b2a26eefd488c92b" }, "Version": "1.22.2-r1", "Arch": "x86_64", "SrcName": "krb5", "SrcVersion": "1.22.2-r1", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "keyutils-libs@1.6.3-r4", "krb5-conf@1.0-r2", "libcom_err@1.47.4-r0", "libcrypto3@3.5.7-r0", "libssl3@3.5.7-r0", "libverto@0.3.2-r2", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:ef02346e21b817ff379e4601e5b1fc9760e5e31a", "InstalledFiles": [ "usr/lib/libgssapi_krb5.so.2", "usr/lib/libgssapi_krb5.so.2.2", "usr/lib/libgssrpc.so.4", "usr/lib/libgssrpc.so.4.2", "usr/lib/libk5crypto.so.3", "usr/lib/libk5crypto.so.3.1", "usr/lib/libkadm5clnt_mit.so.12", "usr/lib/libkadm5clnt_mit.so.12.0", "usr/lib/libkadm5srv_mit.so.12", "usr/lib/libkadm5srv_mit.so.12.0", "usr/lib/libkdb5.so.10", "usr/lib/libkdb5.so.10.0", "usr/lib/libkrad.so.0", "usr/lib/libkrad.so.0.0", "usr/lib/libkrb5.so.3", "usr/lib/libkrb5.so.3.3", "usr/lib/libkrb5support.so.0", "usr/lib/libkrb5support.so.0.1", "usr/lib/krb5/plugins/kdb/db2.so", "usr/lib/krb5/plugins/preauth/otp.so", "usr/lib/krb5/plugins/preauth/spake.so", "usr/lib/krb5/plugins/preauth/test.so", "usr/lib/krb5/plugins/tls/k5tls.so" ], "AnalyzedBy": "apk" }, { "ID": "libapk@3.0.6-r0", "Name": "libapk", "Identifier": { "PURL": "pkg:apk/alpine/libapk@3.0.6-r0?arch=x86_64\u0026distro=3.24.1", "UID": "99b3039c6c4890c4" }, "Version": "3.0.6-r0", "Arch": "x86_64", "SrcName": "apk-tools", "SrcVersion": "3.0.6-r0", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libcrypto3@3.5.7-r0", "libssl3@3.5.7-r0", "musl@1.2.6-r2", "zlib@1.3.2-r0" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:523a8f58104589f74f743d501c81bf6517155378", "InstalledFiles": [ "usr/lib/libapk.so.3.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libcom_err@1.47.4-r0", "Name": "libcom_err", "Identifier": { "PURL": "pkg:apk/alpine/libcom_err@1.47.4-r0?arch=x86_64\u0026distro=3.24.1", "UID": "3fc35a3f66d192af" }, "Version": "1.47.4-r0", "Arch": "x86_64", "SrcName": "e2fsprogs", "SrcVersion": "1.47.4-r0", "Licenses": [ "GPL-2.0-or-later", "LGPL-2.0-or-later", "BSD-3-Clause", "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:4b9fb5899ea0b1c0cfbb2a2c5952704437d4ecef", "InstalledFiles": [ "usr/lib/libcom_err.so.2", "usr/lib/libcom_err.so.2.1" ], "AnalyzedBy": "apk" }, { "ID": "libcrypto3@3.5.7-r0", "Name": "libcrypto3", "Identifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", "UID": "9ce2cdb3f0bf014b" }, "Version": "3.5.7-r0", "Arch": "x86_64", "SrcName": "openssl", "SrcVersion": "3.5.7-r0", "Licenses": [ "Apache-2.0" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:481afbc52bcf06f2316c93a0a81ce8f72bed503e", "InstalledFiles": [ "etc/ssl/ct_log_list.cnf", "etc/ssl/ct_log_list.cnf.dist", "etc/ssl/openssl.cnf", "etc/ssl/openssl.cnf.dist", "usr/lib/libcrypto.so.3", "usr/lib/engines-3/afalg.so", "usr/lib/engines-3/capi.so", "usr/lib/engines-3/loader_attic.so", "usr/lib/engines-3/padlock.so", "usr/lib/ossl-modules/legacy.so" ], "AnalyzedBy": "apk" }, { "ID": "libedit@20260508.3.1-r1", "Name": "libedit", "Identifier": { "PURL": "pkg:apk/alpine/libedit@20260508.3.1-r1?arch=x86_64\u0026distro=3.24.1", "UID": "98a763e822f29606" }, "Version": "20260508.3.1-r1", "Arch": "x86_64", "SrcName": "libedit", "SrcVersion": "20260508.3.1-r1", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", "DependsOn": [ "libncursesw@6.6_p20260516-r0", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:4084f8ff8e83fe17ce0c9ec3f313604d6adc7481", "InstalledFiles": [ "usr/lib/libedit.so.0", "usr/lib/libedit.so.0.0.77" ], "AnalyzedBy": "apk" }, { "ID": "libffi@3.5.2-r1", "Name": "libffi", "Identifier": { "PURL": "pkg:apk/alpine/libffi@3.5.2-r1?arch=x86_64\u0026distro=3.24.1", "UID": "d3eaa921287b1ccd" }, "Version": "3.5.2-r1", "Arch": "x86_64", "SrcName": "libffi", "SrcVersion": "3.5.2-r1", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:2f7b261f7fcecc4eebd8b330e7f6fb80713bfe3a", "InstalledFiles": [ "usr/lib/libffi.so.8", "usr/lib/libffi.so.8.2.0" ], "AnalyzedBy": "apk" }, { "ID": "libgcc@15.2.0-r5", "Name": "libgcc", "Identifier": { "PURL": "pkg:apk/alpine/libgcc@15.2.0-r5?arch=x86_64\u0026distro=3.24.1", "UID": "8cf3d813d20beeee" }, "Version": "15.2.0-r5", "Arch": "x86_64", "SrcName": "gcc", "SrcVersion": "15.2.0-r5", "Licenses": [ "GPL-2.0-or-later", "LGPL-2.1-or-later" ], "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:379c156c53e0cc140e87c79c0a3dd22b6ee51552", "InstalledFiles": [ "usr/lib/libgcc_s.so.1" ], "AnalyzedBy": "apk" }, { "ID": "libldap@2.6.14-r0", "Name": "libldap", "Identifier": { "PURL": "pkg:apk/alpine/libldap@2.6.14-r0?arch=x86_64\u0026distro=3.24.1", "UID": "2094cbf3bb65575a" }, "Version": "2.6.14-r0", "Arch": "x86_64", "SrcName": "openldap", "SrcVersion": "2.6.14-r0", "Licenses": [ "OLDAP-2.8" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libcrypto3@3.5.7-r0", "libsasl@2.1.28-r9", "libssl3@3.5.7-r0", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:112ff31072f41119840e739c4195b6f2489fe048", "InstalledFiles": [ "etc/openldap/ldap.conf", "usr/lib/liblber.so.2", "usr/lib/liblber.so.2.0.200", "usr/lib/libldap.so.2", "usr/lib/libldap.so.2.0.200" ], "AnalyzedBy": "apk" }, { "ID": "libncursesw@6.6_p20260516-r0", "Name": "libncursesw", "Identifier": { "PURL": "pkg:apk/alpine/libncursesw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", "UID": "e8939f45e2191bcc" }, "Version": "6.6_p20260516-r0", "Arch": "x86_64", "SrcName": "ncurses", "SrcVersion": "6.6_p20260516-r0", "Licenses": [ "X-11" ], "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", "DependsOn": [ "musl@1.2.6-r2", "ncurses-terminfo-base@6.6_p20260516-r0" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:9f318e6e324d6827274829194cf6ac6afbaded12", "InstalledFiles": [ "usr/lib/libncursesw.so.6", "usr/lib/libncursesw.so.6.6" ], "AnalyzedBy": "apk" }, { "ID": "libsasl@2.1.28-r9", "Name": "libsasl", "Identifier": { "PURL": "pkg:apk/alpine/libsasl@2.1.28-r9?arch=x86_64\u0026distro=3.24.1", "UID": "28cd83afcf08300b" }, "Version": "2.1.28-r9", "Arch": "x86_64", "SrcName": "cyrus-sasl", "SrcVersion": "2.1.28-r9", "Licenses": [ "BSD-3-Clause-Attribution", "BSD-4-Clause" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "gdbm@1.26-r0", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:422ebe8defd4a2d2aaea34662f6ff853cfc2f95f", "InstalledFiles": [ "usr/lib/libsasl2.so.3", "usr/lib/libsasl2.so.3.0.0", "usr/lib/sasl2/libanonymous.so", "usr/lib/sasl2/libanonymous.so.3", "usr/lib/sasl2/libanonymous.so.3.0.0", "usr/lib/sasl2/libplain.so", "usr/lib/sasl2/libplain.so.3", "usr/lib/sasl2/libplain.so.3.0.0", "usr/lib/sasl2/libsasldb.so", "usr/lib/sasl2/libsasldb.so.3", "usr/lib/sasl2/libsasldb.so.3.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libssl3@3.5.7-r0", "Name": "libssl3", "Identifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", "UID": "a25152af95b643e0" }, "Version": "3.5.7-r0", "Arch": "x86_64", "SrcName": "openssl", "SrcVersion": "3.5.7-r0", "Licenses": [ "Apache-2.0" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libcrypto3@3.5.7-r0", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:240c8252d1ca145873c03c997966698eb509f745", "InstalledFiles": [ "usr/lib/libssl.so.3" ], "AnalyzedBy": "apk" }, { "ID": "libstdc++@15.2.0-r5", "Name": "libstdc++", "Identifier": { "PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r5?arch=x86_64\u0026distro=3.24.1", "UID": "2eed307edf277aae" }, "Version": "15.2.0-r5", "Arch": "x86_64", "SrcName": "gcc", "SrcVersion": "15.2.0-r5", "Licenses": [ "GPL-2.0-or-later", "LGPL-2.1-or-later" ], "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", "DependsOn": [ "libgcc@15.2.0-r5", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:5f7a2ad7646128ba02cc0d6fb94672b6845648d5", "InstalledFiles": [ "usr/lib/libstdc++.so.6", "usr/lib/libstdc++.so.6.0.34" ], "AnalyzedBy": "apk" }, { "ID": "libuuid@2.42.1-r0", "Name": "libuuid", "Identifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "Version": "2.42.1-r0", "Arch": "x86_64", "SrcName": "util-linux", "SrcVersion": "2.42.1-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:6acb0e27112dfb784e6f7ccceb0e968fafa09713", "InstalledFiles": [ "usr/lib/libuuid.so.1", "usr/lib/libuuid.so.1.3.0" ], "AnalyzedBy": "apk" }, { "ID": "libverto@0.3.2-r2", "Name": "libverto", "Identifier": { "PURL": "pkg:apk/alpine/libverto@0.3.2-r2?arch=x86_64\u0026distro=3.24.1", "UID": "9df4321a283a6cf6" }, "Version": "0.3.2-r2", "Arch": "x86_64", "SrcName": "libverto", "SrcVersion": "0.3.2-r2", "Licenses": [ "MIT" ], "Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:73233059338142e4ac6d8fb8bb0074e93da75dc1", "InstalledFiles": [ "usr/lib/libverto.so.1", "usr/lib/libverto.so.1.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libxml2@2.13.9-r2", "Name": "libxml2", "Identifier": { "PURL": "pkg:apk/alpine/libxml2@2.13.9-r2?arch=x86_64\u0026distro=3.24.1", "UID": "661e2a4b0a2b6c43" }, "Version": "2.13.9-r2", "Arch": "x86_64", "SrcName": "libxml2", "SrcVersion": "2.13.9-r2", "Licenses": [ "MIT" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2", "xz-libs@5.8.3-r0", "zlib@1.3.2-r0" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:c2c2cb44647ddc8c82ae78c8aca9bd4ad5a736da", "InstalledFiles": [ "usr/lib/libxml2.so.2", "usr/lib/libxml2.so.2.13.9" ], "AnalyzedBy": "apk" }, { "ID": "libxslt@1.1.43-r3", "Name": "libxslt", "Identifier": { "PURL": "pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64\u0026distro=3.24.1", "UID": "2810f2fbfcee454a" }, "Version": "1.1.43-r3", "Arch": "x86_64", "SrcName": "libxslt", "SrcVersion": "1.1.43-r3", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libxml2@2.13.9-r2", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:a78a1c96aa4f4a763ab8d2eeb285734c0387eb31", "InstalledFiles": [ "usr/bin/xsltproc", "usr/lib/libexslt.so.0", "usr/lib/libexslt.so.0.8.24", "usr/lib/libxslt.so.1", "usr/lib/libxslt.so.1.1.43" ], "AnalyzedBy": "apk" }, { "ID": "llvm21-libs@21.1.8-r1", "Name": "llvm21-libs", "Identifier": { "PURL": "pkg:apk/alpine/llvm21-libs@21.1.8-r1?arch=x86_64\u0026distro=3.24.1", "UID": "b4a6fa05ae868a0d" }, "Version": "21.1.8-r1", "Arch": "x86_64", "SrcName": "llvm21", "SrcVersion": "21.1.8-r1", "Licenses": [ "Apache-2.0" ], "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", "DependsOn": [ "libffi@3.5.2-r1", "libgcc@15.2.0-r5", "libstdc++@15.2.0-r5", "libxml2@2.13.9-r2", "musl@1.2.6-r2", "zlib@1.3.2-r0", "zstd-libs@1.5.7-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:d9f9cafee3a86cc6103c92614ea769b3a169cff3", "InstalledFiles": [ "usr/lib/libLLVM-21.so", "usr/lib/libLLVM.so.21.1", "usr/lib/llvm21/lib/libLLVM.so.21.1" ], "AnalyzedBy": "apk" }, { "ID": "lz4-libs@1.10.0-r1", "Name": "lz4-libs", "Identifier": { "PURL": "pkg:apk/alpine/lz4-libs@1.10.0-r1?arch=x86_64\u0026distro=3.24.1", "UID": "697c5d416b5775fb" }, "Version": "1.10.0-r1", "Arch": "x86_64", "SrcName": "lz4", "SrcVersion": "1.10.0-r1", "Licenses": [ "BSD-2-Clause", "GPL-2.0-or-later" ], "Maintainer": "Stuart Cardall \u003cdeveloper@it-offshore.co.uk\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:d63bb2e1707aa4ca0b75a867706ea03df70bc5bd", "InstalledFiles": [ "usr/lib/liblz4.so.1", "usr/lib/liblz4.so.1.10.0" ], "AnalyzedBy": "apk" }, { "ID": "musl@1.2.6-r2", "Name": "musl", "Identifier": { "PURL": "pkg:apk/alpine/musl@1.2.6-r2?arch=x86_64\u0026distro=3.24.1", "UID": "1f8cb44befe503d4" }, "Version": "1.2.6-r2", "Arch": "x86_64", "SrcName": "musl", "SrcVersion": "1.2.6-r2", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:0f7e5827e4e1a73631beda27b78431a8ba240e05", "InstalledFiles": [ "lib/ld-musl-x86_64.so.1", "lib/libc.musl-x86_64.so.1" ], "AnalyzedBy": "apk" }, { "ID": "musl-utils@1.2.6-r2", "Name": "musl-utils", "Identifier": { "PURL": "pkg:apk/alpine/musl-utils@1.2.6-r2?arch=x86_64\u0026distro=3.24.1", "UID": "4497482ec1d943e1" }, "Version": "1.2.6-r2", "Arch": "x86_64", "SrcName": "musl", "SrcVersion": "1.2.6-r2", "Licenses": [ "MIT", "BSD-2-Clause", "GPL-2.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2", "scanelf@1.3.9-r1" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:75ada3c48d63ec5d87c42fdf934a3fdd11298dc5", "InstalledFiles": [ "sbin/ldconfig", "usr/bin/getconf", "usr/bin/getent", "usr/bin/iconv", "usr/bin/ldd" ], "AnalyzedBy": "apk" }, { "ID": "ncurses-terminfo-base@6.6_p20260516-r0", "Name": "ncurses-terminfo-base", "Identifier": { "PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", "UID": "e7fac5c6a6e9ae8" }, "Version": "6.6_p20260516-r0", "Arch": "x86_64", "SrcName": "ncurses", "SrcVersion": "6.6_p20260516-r0", "Licenses": [ "X-11" ], "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:9d551d828e9c8ee52c5801c1d6046828ebf15752", "InstalledFiles": [ "etc/terminfo/a/alacritty", "etc/terminfo/a/ansi", "etc/terminfo/d/dumb", "etc/terminfo/g/gnome", "etc/terminfo/g/gnome-256color", "etc/terminfo/k/konsole", "etc/terminfo/k/konsole-256color", "etc/terminfo/k/konsole-linux", "etc/terminfo/l/linux", "etc/terminfo/p/putty", "etc/terminfo/p/putty-256color", "etc/terminfo/r/rxvt", "etc/terminfo/r/rxvt-256color", "etc/terminfo/s/screen", "etc/terminfo/s/screen-256color", "etc/terminfo/s/st-0.6", "etc/terminfo/s/st-0.7", "etc/terminfo/s/st-0.8", "etc/terminfo/s/st-0.8.5", "etc/terminfo/s/st-16color", "etc/terminfo/s/st-256color", "etc/terminfo/s/st-direct", "etc/terminfo/s/sun", "etc/terminfo/t/terminator", "etc/terminfo/t/terminology", "etc/terminfo/t/terminology-0.6.1", "etc/terminfo/t/terminology-1.0.0", "etc/terminfo/t/terminology-1.8.1", "etc/terminfo/t/tmux", "etc/terminfo/t/tmux-256color", "etc/terminfo/v/vt100", "etc/terminfo/v/vt102", "etc/terminfo/v/vt200", "etc/terminfo/v/vt220", "etc/terminfo/v/vt52", "etc/terminfo/v/vte", "etc/terminfo/v/vte-256color", "etc/terminfo/x/xterm", "etc/terminfo/x/xterm-256color", "etc/terminfo/x/xterm-color", "etc/terminfo/x/xterm-xfree86" ], "AnalyzedBy": "apk" }, { "ID": "nss_wrapper@1.1.12-r1", "Name": "nss_wrapper", "Identifier": { "PURL": "pkg:apk/alpine/nss_wrapper@1.1.12-r1?arch=x86_64\u0026distro=3.24.1", "UID": "da8371470b181c32" }, "Version": "1.1.12-r1", "Arch": "x86_64", "SrcName": "nss_wrapper", "SrcVersion": "1.1.12-r1", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Wolfgang Walther \u003copensource@technowledgy.de\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:46b34dd323a8388eb2480dc65ee56d9179148ffe", "InstalledFiles": [ "usr/lib/libnss_wrapper.so", "usr/lib/libnss_wrapper.so.0", "usr/lib/libnss_wrapper.so.0.3.2" ], "AnalyzedBy": "apk" }, { "ID": "readline@8.3.3-r1", "Name": "readline", "Identifier": { "PURL": "pkg:apk/alpine/readline@8.3.3-r1?arch=x86_64\u0026distro=3.24.1", "UID": "f50058781c93e1f2" }, "Version": "8.3.3-r1", "Arch": "x86_64", "SrcName": "readline", "SrcVersion": "8.3.3-r1", "Licenses": [ "GPL-3.0-or-later" ], "Maintainer": "qaqland \u003cqaq@qaq.land\u003e", "DependsOn": [ "libncursesw@6.6_p20260516-r0", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:945b16e378bc00e44d89d4de8124bba7647fdf4d", "InstalledFiles": [ "etc/inputrc", "usr/lib/libreadline.so.8", "usr/lib/libreadline.so.8.3" ], "AnalyzedBy": "apk" }, { "ID": "scanelf@1.3.9-r1", "Name": "scanelf", "Identifier": { "PURL": "pkg:apk/alpine/scanelf@1.3.9-r1?arch=x86_64\u0026distro=3.24.1", "UID": "936394657a1626fb" }, "Version": "1.3.9-r1", "Arch": "x86_64", "SrcName": "pax-utils", "SrcVersion": "1.3.9-r1", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:013f903d0ba219673aebbdd04f74bb5ed82b01f0", "InstalledFiles": [ "usr/bin/scanelf" ], "AnalyzedBy": "apk" }, { "ID": "ssl_client@1.37.0-r31", "Name": "ssl_client", "Identifier": { "PURL": "pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", "UID": "2884df80ae89778e" }, "Version": "1.37.0-r31", "Arch": "x86_64", "SrcName": "busybox", "SrcVersion": "1.37.0-r31", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", "DependsOn": [ "libcrypto3@3.5.7-r0", "libssl3@3.5.7-r0", "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:c220f4a5125a313af733e98def94132bb1e9d40d", "InstalledFiles": [ "usr/bin/ssl_client" ], "AnalyzedBy": "apk" }, { "ID": "tzdata@2026c-r0", "Name": "tzdata", "Identifier": { "PURL": "pkg:apk/alpine/tzdata@2026c-r0?arch=x86_64\u0026distro=3.24.1", "UID": "52c6b50eff629f9d" }, "Version": "2026c-r0", "Arch": "x86_64", "SrcName": "tzdata", "SrcVersion": "2026c-r0", "Licenses": [ "Public-Domain" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:61f7544ecd8dd63eac23fe3e645702fda92ef02a", "InstalledFiles": [ "usr/share/zoneinfo/CET", "usr/share/zoneinfo/CST6CDT", "usr/share/zoneinfo/Cuba", "usr/share/zoneinfo/EET", "usr/share/zoneinfo/EST", "usr/share/zoneinfo/EST5EDT", "usr/share/zoneinfo/Egypt", "usr/share/zoneinfo/Eire", "usr/share/zoneinfo/Factory", "usr/share/zoneinfo/GB", "usr/share/zoneinfo/GB-Eire", "usr/share/zoneinfo/GMT", "usr/share/zoneinfo/GMT+0", "usr/share/zoneinfo/GMT-0", "usr/share/zoneinfo/GMT0", "usr/share/zoneinfo/Greenwich", "usr/share/zoneinfo/HST", "usr/share/zoneinfo/Hongkong", "usr/share/zoneinfo/Iceland", "usr/share/zoneinfo/Iran", "usr/share/zoneinfo/Israel", "usr/share/zoneinfo/Jamaica", "usr/share/zoneinfo/Japan", "usr/share/zoneinfo/Kwajalein", "usr/share/zoneinfo/Libya", "usr/share/zoneinfo/MET", "usr/share/zoneinfo/MST", "usr/share/zoneinfo/MST7MDT", "usr/share/zoneinfo/NZ", "usr/share/zoneinfo/NZ-CHAT", "usr/share/zoneinfo/Navajo", "usr/share/zoneinfo/PRC", "usr/share/zoneinfo/PST8PDT", "usr/share/zoneinfo/Poland", "usr/share/zoneinfo/Portugal", "usr/share/zoneinfo/ROC", "usr/share/zoneinfo/ROK", "usr/share/zoneinfo/Singapore", "usr/share/zoneinfo/Turkey", "usr/share/zoneinfo/UCT", "usr/share/zoneinfo/UTC", "usr/share/zoneinfo/Universal", "usr/share/zoneinfo/W-SU", "usr/share/zoneinfo/WET", "usr/share/zoneinfo/Zulu", "usr/share/zoneinfo/iso3166.tab", "usr/share/zoneinfo/leap-seconds.list", "usr/share/zoneinfo/posixrules", "usr/share/zoneinfo/zone.tab", "usr/share/zoneinfo/zone1970.tab", "usr/share/zoneinfo/Africa/Abidjan", "usr/share/zoneinfo/Africa/Accra", "usr/share/zoneinfo/Africa/Addis_Ababa", "usr/share/zoneinfo/Africa/Algiers", "usr/share/zoneinfo/Africa/Asmara", "usr/share/zoneinfo/Africa/Asmera", "usr/share/zoneinfo/Africa/Bamako", "usr/share/zoneinfo/Africa/Bangui", "usr/share/zoneinfo/Africa/Banjul", "usr/share/zoneinfo/Africa/Bissau", "usr/share/zoneinfo/Africa/Blantyre", "usr/share/zoneinfo/Africa/Brazzaville", "usr/share/zoneinfo/Africa/Bujumbura", "usr/share/zoneinfo/Africa/Cairo", "usr/share/zoneinfo/Africa/Casablanca", "usr/share/zoneinfo/Africa/Ceuta", "usr/share/zoneinfo/Africa/Conakry", "usr/share/zoneinfo/Africa/Dakar", "usr/share/zoneinfo/Africa/Dar_es_Salaam", "usr/share/zoneinfo/Africa/Djibouti", "usr/share/zoneinfo/Africa/Douala", "usr/share/zoneinfo/Africa/El_Aaiun", "usr/share/zoneinfo/Africa/Freetown", "usr/share/zoneinfo/Africa/Gaborone", "usr/share/zoneinfo/Africa/Harare", "usr/share/zoneinfo/Africa/Johannesburg", "usr/share/zoneinfo/Africa/Juba", "usr/share/zoneinfo/Africa/Kampala", "usr/share/zoneinfo/Africa/Khartoum", "usr/share/zoneinfo/Africa/Kigali", "usr/share/zoneinfo/Africa/Kinshasa", "usr/share/zoneinfo/Africa/Lagos", "usr/share/zoneinfo/Africa/Libreville", "usr/share/zoneinfo/Africa/Lome", "usr/share/zoneinfo/Africa/Luanda", "usr/share/zoneinfo/Africa/Lubumbashi", "usr/share/zoneinfo/Africa/Lusaka", "usr/share/zoneinfo/Africa/Malabo", "usr/share/zoneinfo/Africa/Maputo", "usr/share/zoneinfo/Africa/Maseru", "usr/share/zoneinfo/Africa/Mbabane", "usr/share/zoneinfo/Africa/Mogadishu", "usr/share/zoneinfo/Africa/Monrovia", "usr/share/zoneinfo/Africa/Nairobi", "usr/share/zoneinfo/Africa/Ndjamena", "usr/share/zoneinfo/Africa/Niamey", "usr/share/zoneinfo/Africa/Nouakchott", "usr/share/zoneinfo/Africa/Ouagadougou", "usr/share/zoneinfo/Africa/Porto-Novo", "usr/share/zoneinfo/Africa/Sao_Tome", "usr/share/zoneinfo/Africa/Timbuktu", "usr/share/zoneinfo/Africa/Tripoli", "usr/share/zoneinfo/Africa/Tunis", "usr/share/zoneinfo/Africa/Windhoek", "usr/share/zoneinfo/America/Adak", "usr/share/zoneinfo/America/Anchorage", "usr/share/zoneinfo/America/Anguilla", "usr/share/zoneinfo/America/Antigua", "usr/share/zoneinfo/America/Araguaina", "usr/share/zoneinfo/America/Aruba", "usr/share/zoneinfo/America/Asuncion", "usr/share/zoneinfo/America/Atikokan", "usr/share/zoneinfo/America/Atka", "usr/share/zoneinfo/America/Bahia", "usr/share/zoneinfo/America/Bahia_Banderas", "usr/share/zoneinfo/America/Barbados", "usr/share/zoneinfo/America/Belem", "usr/share/zoneinfo/America/Belize", "usr/share/zoneinfo/America/Blanc-Sablon", "usr/share/zoneinfo/America/Boa_Vista", "usr/share/zoneinfo/America/Bogota", "usr/share/zoneinfo/America/Boise", "usr/share/zoneinfo/America/Buenos_Aires", "usr/share/zoneinfo/America/Cambridge_Bay", "usr/share/zoneinfo/America/Campo_Grande", "usr/share/zoneinfo/America/Cancun", "usr/share/zoneinfo/America/Caracas", "usr/share/zoneinfo/America/Catamarca", "usr/share/zoneinfo/America/Cayenne", "usr/share/zoneinfo/America/Cayman", "usr/share/zoneinfo/America/Chicago", "usr/share/zoneinfo/America/Chihuahua", "usr/share/zoneinfo/America/Ciudad_Juarez", "usr/share/zoneinfo/America/Coral_Harbour", "usr/share/zoneinfo/America/Cordoba", "usr/share/zoneinfo/America/Costa_Rica", "usr/share/zoneinfo/America/Coyhaique", "usr/share/zoneinfo/America/Creston", "usr/share/zoneinfo/America/Cuiaba", "usr/share/zoneinfo/America/Curacao", "usr/share/zoneinfo/America/Danmarkshavn", "usr/share/zoneinfo/America/Dawson", "usr/share/zoneinfo/America/Dawson_Creek", "usr/share/zoneinfo/America/Denver", "usr/share/zoneinfo/America/Detroit", "usr/share/zoneinfo/America/Dominica", "usr/share/zoneinfo/America/Edmonton", "usr/share/zoneinfo/America/Eirunepe", "usr/share/zoneinfo/America/El_Salvador", "usr/share/zoneinfo/America/Ensenada", "usr/share/zoneinfo/America/Fort_Nelson", "usr/share/zoneinfo/America/Fort_Wayne", "usr/share/zoneinfo/America/Fortaleza", "usr/share/zoneinfo/America/Glace_Bay", "usr/share/zoneinfo/America/Godthab", "usr/share/zoneinfo/America/Goose_Bay", "usr/share/zoneinfo/America/Grand_Turk", "usr/share/zoneinfo/America/Grenada", "usr/share/zoneinfo/America/Guadeloupe", "usr/share/zoneinfo/America/Guatemala", "usr/share/zoneinfo/America/Guayaquil", "usr/share/zoneinfo/America/Guyana", "usr/share/zoneinfo/America/Halifax", "usr/share/zoneinfo/America/Havana", "usr/share/zoneinfo/America/Hermosillo", "usr/share/zoneinfo/America/Indianapolis", "usr/share/zoneinfo/America/Inuvik", "usr/share/zoneinfo/America/Iqaluit", "usr/share/zoneinfo/America/Jamaica", "usr/share/zoneinfo/America/Jujuy", "usr/share/zoneinfo/America/Juneau", "usr/share/zoneinfo/America/Knox_IN", "usr/share/zoneinfo/America/Kralendijk", "usr/share/zoneinfo/America/La_Paz", "usr/share/zoneinfo/America/Lima", "usr/share/zoneinfo/America/Los_Angeles", "usr/share/zoneinfo/America/Louisville", "usr/share/zoneinfo/America/Lower_Princes", "usr/share/zoneinfo/America/Maceio", "usr/share/zoneinfo/America/Managua", "usr/share/zoneinfo/America/Manaus", "usr/share/zoneinfo/America/Marigot", "usr/share/zoneinfo/America/Martinique", "usr/share/zoneinfo/America/Matamoros", "usr/share/zoneinfo/America/Mazatlan", "usr/share/zoneinfo/America/Mendoza", "usr/share/zoneinfo/America/Menominee", "usr/share/zoneinfo/America/Merida", "usr/share/zoneinfo/America/Metlakatla", "usr/share/zoneinfo/America/Mexico_City", "usr/share/zoneinfo/America/Miquelon", "usr/share/zoneinfo/America/Moncton", "usr/share/zoneinfo/America/Monterrey", "usr/share/zoneinfo/America/Montevideo", "usr/share/zoneinfo/America/Montreal", "usr/share/zoneinfo/America/Montserrat", "usr/share/zoneinfo/America/Nassau", "usr/share/zoneinfo/America/New_York", "usr/share/zoneinfo/America/Nipigon", "usr/share/zoneinfo/America/Nome", "usr/share/zoneinfo/America/Noronha", "usr/share/zoneinfo/America/Nuuk", "usr/share/zoneinfo/America/Ojinaga", "usr/share/zoneinfo/America/Panama", "usr/share/zoneinfo/America/Pangnirtung", "usr/share/zoneinfo/America/Paramaribo", "usr/share/zoneinfo/America/Phoenix", "usr/share/zoneinfo/America/Port-au-Prince", "usr/share/zoneinfo/America/Port_of_Spain", "usr/share/zoneinfo/America/Porto_Acre", "usr/share/zoneinfo/America/Porto_Velho", "usr/share/zoneinfo/America/Puerto_Rico", "usr/share/zoneinfo/America/Punta_Arenas", "usr/share/zoneinfo/America/Rainy_River", "usr/share/zoneinfo/America/Rankin_Inlet", "usr/share/zoneinfo/America/Recife", "usr/share/zoneinfo/America/Regina", "usr/share/zoneinfo/America/Resolute", "usr/share/zoneinfo/America/Rio_Branco", "usr/share/zoneinfo/America/Rosario", "usr/share/zoneinfo/America/Santa_Isabel", "usr/share/zoneinfo/America/Santarem", "usr/share/zoneinfo/America/Santiago", "usr/share/zoneinfo/America/Santo_Domingo", "usr/share/zoneinfo/America/Sao_Paulo", "usr/share/zoneinfo/America/Scoresbysund", "usr/share/zoneinfo/America/Shiprock", "usr/share/zoneinfo/America/Sitka", "usr/share/zoneinfo/America/St_Barthelemy", "usr/share/zoneinfo/America/St_Johns", "usr/share/zoneinfo/America/St_Kitts", "usr/share/zoneinfo/America/St_Lucia", "usr/share/zoneinfo/America/St_Thomas", "usr/share/zoneinfo/America/St_Vincent", "usr/share/zoneinfo/America/Swift_Current", "usr/share/zoneinfo/America/Tegucigalpa", "usr/share/zoneinfo/America/Thule", "usr/share/zoneinfo/America/Thunder_Bay", "usr/share/zoneinfo/America/Tijuana", "usr/share/zoneinfo/America/Toronto", "usr/share/zoneinfo/America/Tortola", "usr/share/zoneinfo/America/Vancouver", "usr/share/zoneinfo/America/Virgin", "usr/share/zoneinfo/America/Whitehorse", "usr/share/zoneinfo/America/Winnipeg", "usr/share/zoneinfo/America/Yakutat", "usr/share/zoneinfo/America/Yellowknife", "usr/share/zoneinfo/America/Argentina/Buenos_Aires", "usr/share/zoneinfo/America/Argentina/Catamarca", "usr/share/zoneinfo/America/Argentina/ComodRivadavia", "usr/share/zoneinfo/America/Argentina/Cordoba", "usr/share/zoneinfo/America/Argentina/Jujuy", "usr/share/zoneinfo/America/Argentina/La_Rioja", "usr/share/zoneinfo/America/Argentina/Mendoza", "usr/share/zoneinfo/America/Argentina/Rio_Gallegos", "usr/share/zoneinfo/America/Argentina/Salta", "usr/share/zoneinfo/America/Argentina/San_Juan", "usr/share/zoneinfo/America/Argentina/San_Luis", "usr/share/zoneinfo/America/Argentina/Tucuman", "usr/share/zoneinfo/America/Argentina/Ushuaia", "usr/share/zoneinfo/America/Indiana/Indianapolis", "usr/share/zoneinfo/America/Indiana/Knox", "usr/share/zoneinfo/America/Indiana/Marengo", "usr/share/zoneinfo/America/Indiana/Petersburg", "usr/share/zoneinfo/America/Indiana/Tell_City", "usr/share/zoneinfo/America/Indiana/Vevay", "usr/share/zoneinfo/America/Indiana/Vincennes", "usr/share/zoneinfo/America/Indiana/Winamac", "usr/share/zoneinfo/America/Kentucky/Louisville", "usr/share/zoneinfo/America/Kentucky/Monticello", "usr/share/zoneinfo/America/North_Dakota/Beulah", "usr/share/zoneinfo/America/North_Dakota/Center", "usr/share/zoneinfo/America/North_Dakota/New_Salem", "usr/share/zoneinfo/Antarctica/Casey", "usr/share/zoneinfo/Antarctica/Davis", "usr/share/zoneinfo/Antarctica/DumontDUrville", "usr/share/zoneinfo/Antarctica/Macquarie", "usr/share/zoneinfo/Antarctica/Mawson", "usr/share/zoneinfo/Antarctica/McMurdo", "usr/share/zoneinfo/Antarctica/Palmer", "usr/share/zoneinfo/Antarctica/Rothera", "usr/share/zoneinfo/Antarctica/South_Pole", "usr/share/zoneinfo/Antarctica/Syowa", "usr/share/zoneinfo/Antarctica/Troll", "usr/share/zoneinfo/Antarctica/Vostok", "usr/share/zoneinfo/Arctic/Longyearbyen", "usr/share/zoneinfo/Asia/Aden", "usr/share/zoneinfo/Asia/Almaty", "usr/share/zoneinfo/Asia/Amman", "usr/share/zoneinfo/Asia/Anadyr", "usr/share/zoneinfo/Asia/Aqtau", "usr/share/zoneinfo/Asia/Aqtobe", "usr/share/zoneinfo/Asia/Ashgabat", "usr/share/zoneinfo/Asia/Ashkhabad", "usr/share/zoneinfo/Asia/Atyrau", "usr/share/zoneinfo/Asia/Baghdad", "usr/share/zoneinfo/Asia/Bahrain", "usr/share/zoneinfo/Asia/Baku", "usr/share/zoneinfo/Asia/Bangkok", "usr/share/zoneinfo/Asia/Barnaul", "usr/share/zoneinfo/Asia/Beirut", "usr/share/zoneinfo/Asia/Bishkek", "usr/share/zoneinfo/Asia/Brunei", "usr/share/zoneinfo/Asia/Calcutta", "usr/share/zoneinfo/Asia/Chita", "usr/share/zoneinfo/Asia/Choibalsan", "usr/share/zoneinfo/Asia/Chongqing", "usr/share/zoneinfo/Asia/Chungking", "usr/share/zoneinfo/Asia/Colombo", "usr/share/zoneinfo/Asia/Dacca", "usr/share/zoneinfo/Asia/Damascus", "usr/share/zoneinfo/Asia/Dhaka", "usr/share/zoneinfo/Asia/Dili", "usr/share/zoneinfo/Asia/Dubai", "usr/share/zoneinfo/Asia/Dushanbe", "usr/share/zoneinfo/Asia/Famagusta", "usr/share/zoneinfo/Asia/Gaza", "usr/share/zoneinfo/Asia/Harbin", "usr/share/zoneinfo/Asia/Hebron", "usr/share/zoneinfo/Asia/Ho_Chi_Minh", "usr/share/zoneinfo/Asia/Hong_Kong", "usr/share/zoneinfo/Asia/Hovd", "usr/share/zoneinfo/Asia/Irkutsk", "usr/share/zoneinfo/Asia/Istanbul", "usr/share/zoneinfo/Asia/Jakarta", "usr/share/zoneinfo/Asia/Jayapura", "usr/share/zoneinfo/Asia/Jerusalem", "usr/share/zoneinfo/Asia/Kabul", "usr/share/zoneinfo/Asia/Kamchatka", "usr/share/zoneinfo/Asia/Karachi", "usr/share/zoneinfo/Asia/Kashgar", "usr/share/zoneinfo/Asia/Kathmandu", "usr/share/zoneinfo/Asia/Katmandu", "usr/share/zoneinfo/Asia/Khandyga", "usr/share/zoneinfo/Asia/Kolkata", "usr/share/zoneinfo/Asia/Krasnoyarsk", "usr/share/zoneinfo/Asia/Kuala_Lumpur", "usr/share/zoneinfo/Asia/Kuching", "usr/share/zoneinfo/Asia/Kuwait", "usr/share/zoneinfo/Asia/Macao", "usr/share/zoneinfo/Asia/Macau", "usr/share/zoneinfo/Asia/Magadan", "usr/share/zoneinfo/Asia/Makassar", "usr/share/zoneinfo/Asia/Manila", "usr/share/zoneinfo/Asia/Muscat", "usr/share/zoneinfo/Asia/Nicosia", "usr/share/zoneinfo/Asia/Novokuznetsk", "usr/share/zoneinfo/Asia/Novosibirsk", "usr/share/zoneinfo/Asia/Omsk", "usr/share/zoneinfo/Asia/Oral", "usr/share/zoneinfo/Asia/Phnom_Penh", "usr/share/zoneinfo/Asia/Pontianak", "usr/share/zoneinfo/Asia/Pyongyang", "usr/share/zoneinfo/Asia/Qatar", "usr/share/zoneinfo/Asia/Qostanay", "usr/share/zoneinfo/Asia/Qyzylorda", "usr/share/zoneinfo/Asia/Rangoon", "usr/share/zoneinfo/Asia/Riyadh", "usr/share/zoneinfo/Asia/Saigon", "usr/share/zoneinfo/Asia/Sakhalin", "usr/share/zoneinfo/Asia/Samarkand", "usr/share/zoneinfo/Asia/Seoul", "usr/share/zoneinfo/Asia/Shanghai", "usr/share/zoneinfo/Asia/Singapore", "usr/share/zoneinfo/Asia/Srednekolymsk", "usr/share/zoneinfo/Asia/Taipei", "usr/share/zoneinfo/Asia/Tashkent", "usr/share/zoneinfo/Asia/Tbilisi", "usr/share/zoneinfo/Asia/Tehran", "usr/share/zoneinfo/Asia/Tel_Aviv", "usr/share/zoneinfo/Asia/Thimbu", "usr/share/zoneinfo/Asia/Thimphu", "usr/share/zoneinfo/Asia/Tokyo", "usr/share/zoneinfo/Asia/Tomsk", "usr/share/zoneinfo/Asia/Ujung_Pandang", "usr/share/zoneinfo/Asia/Ulaanbaatar", "usr/share/zoneinfo/Asia/Ulan_Bator", "usr/share/zoneinfo/Asia/Urumqi", "usr/share/zoneinfo/Asia/Ust-Nera", "usr/share/zoneinfo/Asia/Vientiane", "usr/share/zoneinfo/Asia/Vladivostok", "usr/share/zoneinfo/Asia/Yakutsk", "usr/share/zoneinfo/Asia/Yangon", "usr/share/zoneinfo/Asia/Yekaterinburg", "usr/share/zoneinfo/Asia/Yerevan", "usr/share/zoneinfo/Atlantic/Azores", "usr/share/zoneinfo/Atlantic/Bermuda", "usr/share/zoneinfo/Atlantic/Canary", "usr/share/zoneinfo/Atlantic/Cape_Verde", "usr/share/zoneinfo/Atlantic/Faeroe", "usr/share/zoneinfo/Atlantic/Faroe", "usr/share/zoneinfo/Atlantic/Jan_Mayen", "usr/share/zoneinfo/Atlantic/Madeira", "usr/share/zoneinfo/Atlantic/Reykjavik", "usr/share/zoneinfo/Atlantic/South_Georgia", "usr/share/zoneinfo/Atlantic/St_Helena", "usr/share/zoneinfo/Atlantic/Stanley", "usr/share/zoneinfo/Australia/ACT", "usr/share/zoneinfo/Australia/Adelaide", "usr/share/zoneinfo/Australia/Brisbane", "usr/share/zoneinfo/Australia/Broken_Hill", "usr/share/zoneinfo/Australia/Canberra", "usr/share/zoneinfo/Australia/Currie", "usr/share/zoneinfo/Australia/Darwin", "usr/share/zoneinfo/Australia/Eucla", "usr/share/zoneinfo/Australia/Hobart", "usr/share/zoneinfo/Australia/LHI", "usr/share/zoneinfo/Australia/Lindeman", "usr/share/zoneinfo/Australia/Lord_Howe", "usr/share/zoneinfo/Australia/Melbourne", "usr/share/zoneinfo/Australia/NSW", "usr/share/zoneinfo/Australia/North", "usr/share/zoneinfo/Australia/Perth", "usr/share/zoneinfo/Australia/Queensland", "usr/share/zoneinfo/Australia/South", "usr/share/zoneinfo/Australia/Sydney", "usr/share/zoneinfo/Australia/Tasmania", "usr/share/zoneinfo/Australia/Victoria", "usr/share/zoneinfo/Australia/West", "usr/share/zoneinfo/Australia/Yancowinna", "usr/share/zoneinfo/Brazil/Acre", "usr/share/zoneinfo/Brazil/DeNoronha", "usr/share/zoneinfo/Brazil/East", "usr/share/zoneinfo/Brazil/West", "usr/share/zoneinfo/Canada/Atlantic", "usr/share/zoneinfo/Canada/Central", "usr/share/zoneinfo/Canada/Eastern", "usr/share/zoneinfo/Canada/Mountain", "usr/share/zoneinfo/Canada/Newfoundland", "usr/share/zoneinfo/Canada/Pacific", "usr/share/zoneinfo/Canada/Saskatchewan", "usr/share/zoneinfo/Canada/Yukon", "usr/share/zoneinfo/Chile/Continental", "usr/share/zoneinfo/Chile/EasterIsland", "usr/share/zoneinfo/Etc/GMT", "usr/share/zoneinfo/Etc/GMT+0", "usr/share/zoneinfo/Etc/GMT+1", "usr/share/zoneinfo/Etc/GMT+10", "usr/share/zoneinfo/Etc/GMT+11", "usr/share/zoneinfo/Etc/GMT+12", "usr/share/zoneinfo/Etc/GMT+2", "usr/share/zoneinfo/Etc/GMT+3", "usr/share/zoneinfo/Etc/GMT+4", "usr/share/zoneinfo/Etc/GMT+5", "usr/share/zoneinfo/Etc/GMT+6", "usr/share/zoneinfo/Etc/GMT+7", "usr/share/zoneinfo/Etc/GMT+8", "usr/share/zoneinfo/Etc/GMT+9", "usr/share/zoneinfo/Etc/GMT-0", "usr/share/zoneinfo/Etc/GMT-1", "usr/share/zoneinfo/Etc/GMT-10", "usr/share/zoneinfo/Etc/GMT-11", "usr/share/zoneinfo/Etc/GMT-12", "usr/share/zoneinfo/Etc/GMT-13", "usr/share/zoneinfo/Etc/GMT-14", "usr/share/zoneinfo/Etc/GMT-2", "usr/share/zoneinfo/Etc/GMT-3", "usr/share/zoneinfo/Etc/GMT-4", "usr/share/zoneinfo/Etc/GMT-5", "usr/share/zoneinfo/Etc/GMT-6", "usr/share/zoneinfo/Etc/GMT-7", "usr/share/zoneinfo/Etc/GMT-8", "usr/share/zoneinfo/Etc/GMT-9", "usr/share/zoneinfo/Etc/GMT0", "usr/share/zoneinfo/Etc/Greenwich", "usr/share/zoneinfo/Etc/UCT", "usr/share/zoneinfo/Etc/UTC", "usr/share/zoneinfo/Etc/Universal", "usr/share/zoneinfo/Etc/Zulu", "usr/share/zoneinfo/Europe/Amsterdam", "usr/share/zoneinfo/Europe/Andorra", "usr/share/zoneinfo/Europe/Astrakhan", "usr/share/zoneinfo/Europe/Athens", "usr/share/zoneinfo/Europe/Belfast", "usr/share/zoneinfo/Europe/Belgrade", "usr/share/zoneinfo/Europe/Berlin", "usr/share/zoneinfo/Europe/Bratislava", "usr/share/zoneinfo/Europe/Brussels", "usr/share/zoneinfo/Europe/Bucharest", "usr/share/zoneinfo/Europe/Budapest", "usr/share/zoneinfo/Europe/Busingen", "usr/share/zoneinfo/Europe/Chisinau", "usr/share/zoneinfo/Europe/Copenhagen", "usr/share/zoneinfo/Europe/Dublin", "usr/share/zoneinfo/Europe/Gibraltar", "usr/share/zoneinfo/Europe/Guernsey", "usr/share/zoneinfo/Europe/Helsinki", "usr/share/zoneinfo/Europe/Isle_of_Man", "usr/share/zoneinfo/Europe/Istanbul", "usr/share/zoneinfo/Europe/Jersey", "usr/share/zoneinfo/Europe/Kaliningrad", "usr/share/zoneinfo/Europe/Kiev", "usr/share/zoneinfo/Europe/Kirov", "usr/share/zoneinfo/Europe/Kyiv", "usr/share/zoneinfo/Europe/Lisbon", "usr/share/zoneinfo/Europe/Ljubljana", "usr/share/zoneinfo/Europe/London", "usr/share/zoneinfo/Europe/Luxembourg", "usr/share/zoneinfo/Europe/Madrid", "usr/share/zoneinfo/Europe/Malta", "usr/share/zoneinfo/Europe/Mariehamn", "usr/share/zoneinfo/Europe/Minsk", "usr/share/zoneinfo/Europe/Monaco", "usr/share/zoneinfo/Europe/Moscow", "usr/share/zoneinfo/Europe/Nicosia", "usr/share/zoneinfo/Europe/Oslo", "usr/share/zoneinfo/Europe/Paris", "usr/share/zoneinfo/Europe/Podgorica", "usr/share/zoneinfo/Europe/Prague", "usr/share/zoneinfo/Europe/Riga", "usr/share/zoneinfo/Europe/Rome", "usr/share/zoneinfo/Europe/Samara", "usr/share/zoneinfo/Europe/San_Marino", "usr/share/zoneinfo/Europe/Sarajevo", "usr/share/zoneinfo/Europe/Saratov", "usr/share/zoneinfo/Europe/Simferopol", "usr/share/zoneinfo/Europe/Skopje", "usr/share/zoneinfo/Europe/Sofia", "usr/share/zoneinfo/Europe/Stockholm", "usr/share/zoneinfo/Europe/Tallinn", "usr/share/zoneinfo/Europe/Tirane", "usr/share/zoneinfo/Europe/Tiraspol", "usr/share/zoneinfo/Europe/Ulyanovsk", "usr/share/zoneinfo/Europe/Uzhgorod", "usr/share/zoneinfo/Europe/Vaduz", "usr/share/zoneinfo/Europe/Vatican", "usr/share/zoneinfo/Europe/Vienna", "usr/share/zoneinfo/Europe/Vilnius", "usr/share/zoneinfo/Europe/Volgograd", "usr/share/zoneinfo/Europe/Warsaw", "usr/share/zoneinfo/Europe/Zagreb", "usr/share/zoneinfo/Europe/Zaporozhye", "usr/share/zoneinfo/Europe/Zurich", "usr/share/zoneinfo/Indian/Antananarivo", "usr/share/zoneinfo/Indian/Chagos", "usr/share/zoneinfo/Indian/Christmas", "usr/share/zoneinfo/Indian/Cocos", "usr/share/zoneinfo/Indian/Comoro", "usr/share/zoneinfo/Indian/Kerguelen", "usr/share/zoneinfo/Indian/Mahe", "usr/share/zoneinfo/Indian/Maldives", "usr/share/zoneinfo/Indian/Mauritius", "usr/share/zoneinfo/Indian/Mayotte", "usr/share/zoneinfo/Indian/Reunion", "usr/share/zoneinfo/Mexico/BajaNorte", "usr/share/zoneinfo/Mexico/BajaSur", "usr/share/zoneinfo/Mexico/General", "usr/share/zoneinfo/Pacific/Apia", "usr/share/zoneinfo/Pacific/Auckland", "usr/share/zoneinfo/Pacific/Bougainville", "usr/share/zoneinfo/Pacific/Chatham", "usr/share/zoneinfo/Pacific/Chuuk", "usr/share/zoneinfo/Pacific/Easter", "usr/share/zoneinfo/Pacific/Efate", "usr/share/zoneinfo/Pacific/Enderbury", "usr/share/zoneinfo/Pacific/Fakaofo", "usr/share/zoneinfo/Pacific/Fiji", "usr/share/zoneinfo/Pacific/Funafuti", "usr/share/zoneinfo/Pacific/Galapagos", "usr/share/zoneinfo/Pacific/Gambier", "usr/share/zoneinfo/Pacific/Guadalcanal", "usr/share/zoneinfo/Pacific/Guam", "usr/share/zoneinfo/Pacific/Honolulu", "usr/share/zoneinfo/Pacific/Johnston", "usr/share/zoneinfo/Pacific/Kanton", "usr/share/zoneinfo/Pacific/Kiritimati", "usr/share/zoneinfo/Pacific/Kosrae", "usr/share/zoneinfo/Pacific/Kwajalein", "usr/share/zoneinfo/Pacific/Majuro", "usr/share/zoneinfo/Pacific/Marquesas", "usr/share/zoneinfo/Pacific/Midway", "usr/share/zoneinfo/Pacific/Nauru", "usr/share/zoneinfo/Pacific/Niue", "usr/share/zoneinfo/Pacific/Norfolk", "usr/share/zoneinfo/Pacific/Noumea", "usr/share/zoneinfo/Pacific/Pago_Pago", "usr/share/zoneinfo/Pacific/Palau", "usr/share/zoneinfo/Pacific/Pitcairn", "usr/share/zoneinfo/Pacific/Pohnpei", "usr/share/zoneinfo/Pacific/Ponape", "usr/share/zoneinfo/Pacific/Port_Moresby", "usr/share/zoneinfo/Pacific/Rarotonga", "usr/share/zoneinfo/Pacific/Saipan", "usr/share/zoneinfo/Pacific/Samoa", "usr/share/zoneinfo/Pacific/Tahiti", "usr/share/zoneinfo/Pacific/Tarawa", "usr/share/zoneinfo/Pacific/Tongatapu", "usr/share/zoneinfo/Pacific/Truk", "usr/share/zoneinfo/Pacific/Wake", "usr/share/zoneinfo/Pacific/Wallis", "usr/share/zoneinfo/Pacific/Yap", "usr/share/zoneinfo/US/Alaska", "usr/share/zoneinfo/US/Aleutian", "usr/share/zoneinfo/US/Arizona", "usr/share/zoneinfo/US/Central", "usr/share/zoneinfo/US/East-Indiana", "usr/share/zoneinfo/US/Eastern", "usr/share/zoneinfo/US/Hawaii", "usr/share/zoneinfo/US/Indiana-Starke", "usr/share/zoneinfo/US/Michigan", "usr/share/zoneinfo/US/Mountain", "usr/share/zoneinfo/US/Pacific", "usr/share/zoneinfo/US/Samoa" ], "AnalyzedBy": "apk" }, { "ID": "xz-libs@5.8.3-r0", "Name": "xz-libs", "Identifier": { "PURL": "pkg:apk/alpine/xz-libs@5.8.3-r0?arch=x86_64\u0026distro=3.24.1", "UID": "1ae658a5f132a091" }, "Version": "5.8.3-r0", "Arch": "x86_64", "SrcName": "xz", "SrcVersion": "5.8.3-r0", "Licenses": [ "GPL-2.0-or-later", "0BSD", "Public-Domain", "LGPL-2.1-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:4c92c5be0c5bef404e93c880eba9037a9b147347", "InstalledFiles": [ "usr/lib/liblzma.so.5", "usr/lib/liblzma.so.5.8.3" ], "AnalyzedBy": "apk" }, { "ID": "zlib@1.3.2-r0", "Name": "zlib", "Identifier": { "PURL": "pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64\u0026distro=3.24.1", "UID": "e37054a2982d6c16" }, "Version": "1.3.2-r0", "Arch": "x86_64", "SrcName": "zlib", "SrcVersion": "1.3.2-r0", "Licenses": [ "Zlib" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "Digest": "sha1:dd4c3d102acaef2a71a1495951d55fabc8680613", "InstalledFiles": [ "usr/lib/libz.so.1", "usr/lib/libz.so.1.3.2" ], "AnalyzedBy": "apk" }, { "ID": "zstd@1.5.7-r2", "Name": "zstd", "Identifier": { "PURL": "pkg:apk/alpine/zstd@1.5.7-r2?arch=x86_64\u0026distro=3.24.1", "UID": "71f39af918e4d14c" }, "Version": "1.5.7-r2", "Arch": "x86_64", "SrcName": "zstd", "SrcVersion": "1.5.7-r2", "Licenses": [ "BSD-3-Clause", "GPL-2.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libgcc@15.2.0-r5", "libstdc++@15.2.0-r5", "musl@1.2.6-r2", "zstd-libs@1.5.7-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:ff3000882c17e89e5e13c020554b5bccc1bfd4df", "InstalledFiles": [ "usr/bin/pzstd", "usr/bin/unzstd", "usr/bin/zstd", "usr/bin/zstdcat", "usr/bin/zstdgrep", "usr/bin/zstdless", "usr/bin/zstdmt" ], "AnalyzedBy": "apk" }, { "ID": "zstd-libs@1.5.7-r2", "Name": "zstd-libs", "Identifier": { "PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.24.1", "UID": "b33716e8bc222f1f" }, "Version": "1.5.7-r2", "Arch": "x86_64", "SrcName": "zstd", "SrcVersion": "1.5.7-r2", "Licenses": [ "BSD-3-Clause", "GPL-2.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.6-r2" ], "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "Digest": "sha1:9569ce3a97c4109e8e53ddde9f3e1bd272613540", "InstalledFiles": [ "usr/lib/libzstd.so.1", "usr/lib/libzstd.so.1.5.7" ], "AnalyzedBy": "apk" } ], "Vulnerabilities": [ { "VulnerabilityID": "CVE-2026-14456", "PkgID": "libcrypto3@3.5.7-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", "UID": "9ce2cdb3f0bf014b" }, "InstalledVersion": "3.5.7-r0", "FixedVersion": "3.5.8-r0", "Status": "fixed", "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:66effbd554e6873981bdd52ae60692654faf106690b53c78751499d91ea7a8d6", "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "amazon": 3, "photon": 3, "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/08/13/4", "https://access.redhat.com/security/cve/CVE-2026-14456", "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", "https://openssl-library.org/news/secadv/20260813.txt", "https://ubuntu.com/security/notices/USN-8678-1", "https://www.cve.org/CVERecord?id=CVE-2026-14456" ], "PublishedDate": "2026-08-13T15:19:31.82Z", "LastModifiedDate": "2026-08-28T19:46:29.323Z" }, { "VulnerabilityID": "CVE-2026-14456", "PkgID": "libssl3@3.5.7-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", "UID": "a25152af95b643e0" }, "InstalledVersion": "3.5.7-r0", "FixedVersion": "3.5.8-r0", "Status": "fixed", "Layer": { "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:bd686aaa2ece4a82e1ad494f4a7598bb66d77b700c2133b3ab3ab8585d4e7ca9", "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "amazon": 3, "photon": 3, "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/08/13/4", "https://access.redhat.com/security/cve/CVE-2026-14456", "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", "https://openssl-library.org/news/secadv/20260813.txt", "https://ubuntu.com/security/notices/USN-8678-1", "https://www.cve.org/CVERecord?id=CVE-2026-14456" ], "PublishedDate": "2026-08-13T15:19:31.82Z", "LastModifiedDate": "2026-08-28T19:46:29.323Z" }, { "VulnerabilityID": "CVE-2026-53612", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r0", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53612", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:81113f5360d14790e635b7331d78d5ed14e9be40a6e43bf022263dda73ce75b0", "Title": "util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes", "Description": "A flaw was found in util-linux. When an /etc/fstab entry uses the user option together with X-mount.owner, X-mount.group, or X-mount.mode, mount(8) changes ownership or permissions on the mount target after mounting without re-verifying the path. A local unprivileged user can exploit this Time-of-Check-Time-of-Use (TOCTOU) window by swapping the target directory, redirecting the ownership/permission change to an arbitrary file and potentially escalating privileges to root.", "Severity": "HIGH", "VendorSeverity": { "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-53612", "https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh", "https://nvd.nist.gov/vuln/detail/CVE-2026-53612", "https://ubuntu.com/security/notices/USN-8702-1", "https://www.cve.org/CVERecord?id=CVE-2026-53612" ] }, { "VulnerabilityID": "CVE-2026-53613", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r0", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53613", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:54e037da093c8c174ad0e2d784253fc9a9814e055fd0549ad80221defddd87a1", "Title": "util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path", "Description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.", "Severity": "HIGH", "VendorSeverity": { "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-53613", "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g", "https://nvd.nist.gov/vuln/detail/CVE-2026-53613", "https://ubuntu.com/security/notices/USN-8702-1", "https://www.cve.org/CVERecord?id=CVE-2026-53613" ] }, { "VulnerabilityID": "CVE-2026-53614", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r0", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53614", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:dece0b29d6edc204a95c04c1c1f0eeeec1528eccf524218f803681d69aafe7d5", "Title": "util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2", "Description": "A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root.", "Severity": "HIGH", "VendorSeverity": { "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-53614", "https://github.com/util-linux/util-linux/security/advisories/GHSA-67r7-8m5w-22wx", "https://nvd.nist.gov/vuln/detail/CVE-2026-53614", "https://ubuntu.com/security/notices/USN-8702-1", "https://www.cve.org/CVERecord?id=CVE-2026-53614" ] }, { "VulnerabilityID": "CVE-2026-76642", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r0", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:c142dcd00764dca9205218728a4d9d7f698986302926f2816106eaa9bbae8774", "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", "Severity": "HIGH", "CweIDs": [ "CWE-390" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-76642", "https://github.com/util-linux/util-linux", "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", "https://www.cve.org/CVERecord?id=CVE-2026-76642", "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" ], "PublishedDate": "2026-09-03T13:06:08.44Z", "LastModifiedDate": "2026-09-03T15:17:33.49Z" }, { "VulnerabilityID": "CVE-2026-78408", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r1", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:c639fbde964fa844de700c2d7a0665d771dcc8ee4a143560cc0c74f12355cbc6", "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", "Severity": "HIGH", "CweIDs": [ "CWE-775" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", "V3Score": 7.9 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/09/05/2", "https://access.redhat.com/errata/RHSA-2026:63162", "https://access.redhat.com/security/cve/CVE-2026-78408", "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", "https://www.cve.org/CVERecord?id=CVE-2026-78408" ], "PublishedDate": "2026-09-02T16:17:23.687Z", "LastModifiedDate": "2026-09-05T14:17:23.727Z" }, { "VulnerabilityID": "CVE-2026-78409", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r0", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:e1ecbe00c3f557417e81e566a983e8869f8972ee1499e6de061810bffa516dc2", "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", "Severity": "HIGH", "CweIDs": [ "CWE-59" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:63162", "https://access.redhat.com/security/cve/CVE-2026-78409", "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", "https://www.cve.org/CVERecord?id=CVE-2026-78409" ], "PublishedDate": "2026-09-02T16:17:23.833Z", "LastModifiedDate": "2026-09-03T18:12:56.407Z" }, { "VulnerabilityID": "CVE-2026-78410", "PkgID": "libuuid@2.42.1-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", "UID": "61e289a52fcab6f6" }, "InstalledVersion": "2.42.1-r0", "FixedVersion": "2.42.3-r0", "Status": "fixed", "Layer": { "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:0916dc51e28a7f0613d801b5b47f1f387bfaa9a446dd75898a4903017e142f5c", "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", "Severity": "HIGH", "CweIDs": [ "CWE-367" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:63162", "https://access.redhat.com/security/cve/CVE-2026-78410", "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", "https://www.cve.org/CVERecord?id=CVE-2026-78410" ], "PublishedDate": "2026-09-02T16:17:23.983Z", "LastModifiedDate": "2026-09-04T19:17:27.567Z" } ] }, { "Target": "usr/local/bin/gosu", "Class": "lang-pkgs", "Type": "gobinary", "Packages": [ { "ID": "github.com/tianon/gosu@v1.19.0", "Name": "github.com/tianon/gosu", "Identifier": { "PURL": "pkg:golang/github.com/tianon/gosu@v1.19.0", "UID": "1057a82ec313601" }, "Version": "v1.19.0", "Relationship": "root", "DependsOn": [ "github.com/moby/sys/user@v0.1.0", "golang.org/x/sys@v0.1.0", "stdlib@v1.24.6" ], "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "AnalyzedBy": "gobinary" }, { "ID": "stdlib@v1.24.6", "Name": "stdlib", "Identifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "Version": "v1.24.6", "Relationship": "direct", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "AnalyzedBy": "gobinary" }, { "ID": "github.com/moby/sys/user@v0.1.0", "Name": "github.com/moby/sys/user", "Identifier": { "PURL": "pkg:golang/github.com/moby/sys/user@v0.1.0", "UID": "cfd815b74e215fdf" }, "Version": "v0.1.0", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "AnalyzedBy": "gobinary" }, { "ID": "golang.org/x/sys@v0.1.0", "Name": "golang.org/x/sys", "Identifier": { "PURL": "pkg:golang/golang.org/x/sys@v0.1.0", "UID": "11ab2e48c80f8e7d" }, "Version": "v0.1.0", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "AnalyzedBy": "gobinary" } ], "Vulnerabilities": [ { "VulnerabilityID": "CVE-2025-68121", "VendorIDs": [ "GO-2026-4337" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:85e5aa144410093742432b138a09862fced9579b0f57deb4cbdd217755d26e54", "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", "Severity": "CRITICAL", "CweIDs": [ "CWE-295" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 2, "bitnami": 4, "cbl-mariner": 2, "nvd": 4, "oracle-oval": 3, "photon": 4, "redhat": 2, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 9.1 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "V3Score": 10 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 7.4 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:4177", "https://access.redhat.com/security/cve/CVE-2025-68121", "https://bugzilla.redhat.com/2434432", "https://bugzilla.redhat.com/2437111", "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", "https://errata.almalinux.org/9/ALSA-2026-4177.html", "https://errata.rockylinux.org/RLSA-2026:4177", "https://github.com/golang/go/issues/77113", "https://go.dev/cl/737700", "https://go.dev/issue/77217", "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", "https://linux.oracle.com/cve/CVE-2025-68121.html", "https://linux.oracle.com/errata/ELSA-2026-5146.html", "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", "https://pkg.go.dev/vuln/GO-2026-4337", "https://www.cve.org/CVERecord?id=CVE-2025-68121" ], "PublishedDate": "2026-02-05T18:16:10.857Z", "LastModifiedDate": "2026-06-17T09:58:33.833Z" }, { "VulnerabilityID": "CVE-2025-61726", "VendorIDs": [ "GO-2026-4341" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.24.12, 1.25.6", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:376f163e2679190aec7e2c2067f0d65ec348cf7c5697676194fffc9ae4598d32", "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 2, "bitnami": 3, "cbl-mariner": 2, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:10096", "https://access.redhat.com/errata/RHSA-2026:10104", "https://access.redhat.com/errata/RHSA-2026:10184", "https://access.redhat.com/errata/RHSA-2026:10225", "https://access.redhat.com/errata/RHSA-2026:10250", "https://access.redhat.com/errata/RHSA-2026:11408", "https://access.redhat.com/errata/RHSA-2026:11414", "https://access.redhat.com/errata/RHSA-2026:11747", "https://access.redhat.com/errata/RHSA-2026:11749", "https://access.redhat.com/errata/RHSA-2026:12028", "https://access.redhat.com/errata/RHSA-2026:12029", "https://access.redhat.com/errata/RHSA-2026:12030", "https://access.redhat.com/errata/RHSA-2026:12031", "https://access.redhat.com/errata/RHSA-2026:12032", "https://access.redhat.com/errata/RHSA-2026:12033", "https://access.redhat.com/errata/RHSA-2026:12279", "https://access.redhat.com/errata/RHSA-2026:12282", "https://access.redhat.com/errata/RHSA-2026:13542", "https://access.redhat.com/errata/RHSA-2026:13548", "https://access.redhat.com/errata/RHSA-2026:13571", "https://access.redhat.com/errata/RHSA-2026:14100", "https://access.redhat.com/errata/RHSA-2026:14774", "https://access.redhat.com/errata/RHSA-2026:14868", "https://access.redhat.com/errata/RHSA-2026:14879", "https://access.redhat.com/errata/RHSA-2026:15091", "https://access.redhat.com/errata/RHSA-2026:15984", "https://access.redhat.com/errata/RHSA-2026:16102", "https://access.redhat.com/errata/RHSA-2026:16696", "https://access.redhat.com/errata/RHSA-2026:17040", "https://access.redhat.com/errata/RHSA-2026:17084", "https://access.redhat.com/errata/RHSA-2026:17446", "https://access.redhat.com/errata/RHSA-2026:17460", "https://access.redhat.com/errata/RHSA-2026:17463", "https://access.redhat.com/errata/RHSA-2026:17468", "https://access.redhat.com/errata/RHSA-2026:17595", "https://access.redhat.com/errata/RHSA-2026:17598", "https://access.redhat.com/errata/RHSA-2026:18913", "https://access.redhat.com/errata/RHSA-2026:19013", "https://access.redhat.com/errata/RHSA-2026:19132", "https://access.redhat.com/errata/RHSA-2026:19375", "https://access.redhat.com/errata/RHSA-2026:19634", "https://access.redhat.com/errata/RHSA-2026:19712", "https://access.redhat.com/errata/RHSA-2026:20041", "https://access.redhat.com/errata/RHSA-2026:21017", "https://access.redhat.com/errata/RHSA-2026:21657", "https://access.redhat.com/errata/RHSA-2026:21691", "https://access.redhat.com/errata/RHSA-2026:22450", "https://access.redhat.com/errata/RHSA-2026:22627", "https://access.redhat.com/errata/RHSA-2026:22714", "https://access.redhat.com/errata/RHSA-2026:22937", "https://access.redhat.com/errata/RHSA-2026:23228", "https://access.redhat.com/errata/RHSA-2026:23361", "https://access.redhat.com/errata/RHSA-2026:24977", "https://access.redhat.com/errata/RHSA-2026:25089", "https://access.redhat.com/errata/RHSA-2026:25127", "https://access.redhat.com/errata/RHSA-2026:25248", "https://access.redhat.com/errata/RHSA-2026:25250", "https://access.redhat.com/errata/RHSA-2026:25251", "https://access.redhat.com/errata/RHSA-2026:25252", "https://access.redhat.com/errata/RHSA-2026:25253", "https://access.redhat.com/errata/RHSA-2026:26420", "https://access.redhat.com/errata/RHSA-2026:26527", "https://access.redhat.com/errata/RHSA-2026:26541", "https://access.redhat.com/errata/RHSA-2026:26636", "https://access.redhat.com/errata/RHSA-2026:2681", "https://access.redhat.com/errata/RHSA-2026:2706", "https://access.redhat.com/errata/RHSA-2026:2708", "https://access.redhat.com/errata/RHSA-2026:2709", "https://access.redhat.com/errata/RHSA-2026:2754", "https://access.redhat.com/errata/RHSA-2026:28047", "https://access.redhat.com/errata/RHSA-2026:2844", "https://access.redhat.com/errata/RHSA-2026:28441", "https://access.redhat.com/errata/RHSA-2026:28886", "https://access.redhat.com/errata/RHSA-2026:28961", "https://access.redhat.com/errata/RHSA-2026:2914", "https://access.redhat.com/errata/RHSA-2026:2920", "https://access.redhat.com/errata/RHSA-2026:3035", "https://access.redhat.com/errata/RHSA-2026:3040", "https://access.redhat.com/errata/RHSA-2026:3089", "https://access.redhat.com/errata/RHSA-2026:3092", "https://access.redhat.com/errata/RHSA-2026:3184", "https://access.redhat.com/errata/RHSA-2026:3186", "https://access.redhat.com/errata/RHSA-2026:3187", "https://access.redhat.com/errata/RHSA-2026:3188", "https://access.redhat.com/errata/RHSA-2026:3192", "https://access.redhat.com/errata/RHSA-2026:3193", "https://access.redhat.com/errata/RHSA-2026:3291", "https://access.redhat.com/errata/RHSA-2026:3296", "https://access.redhat.com/errata/RHSA-2026:3297", "https://access.redhat.com/errata/RHSA-2026:3298", "https://access.redhat.com/errata/RHSA-2026:3336", "https://access.redhat.com/errata/RHSA-2026:3337", "https://access.redhat.com/errata/RHSA-2026:3340", "https://access.redhat.com/errata/RHSA-2026:3341", "https://access.redhat.com/errata/RHSA-2026:3343", "https://access.redhat.com/errata/RHSA-2026:3391", "https://access.redhat.com/errata/RHSA-2026:3416", "https://access.redhat.com/errata/RHSA-2026:3427", "https://access.redhat.com/errata/RHSA-2026:3459", "https://access.redhat.com/errata/RHSA-2026:3468", "https://access.redhat.com/errata/RHSA-2026:3469", "https://access.redhat.com/errata/RHSA-2026:3470", "https://access.redhat.com/errata/RHSA-2026:3471", "https://access.redhat.com/errata/RHSA-2026:3472", "https://access.redhat.com/errata/RHSA-2026:3473", "https://access.redhat.com/errata/RHSA-2026:3489", "https://access.redhat.com/errata/RHSA-2026:3506", "https://access.redhat.com/errata/RHSA-2026:3556", "https://access.redhat.com/errata/RHSA-2026:3559", "https://access.redhat.com/errata/RHSA-2026:3668", "https://access.redhat.com/errata/RHSA-2026:3669", "https://access.redhat.com/errata/RHSA-2026:36873", "https://access.redhat.com/errata/RHSA-2026:36882", "https://access.redhat.com/errata/RHSA-2026:3699", "https://access.redhat.com/errata/RHSA-2026:3713", "https://access.redhat.com/errata/RHSA-2026:37275", "https://access.redhat.com/errata/RHSA-2026:3752", "https://access.redhat.com/errata/RHSA-2026:3753", "https://access.redhat.com/errata/RHSA-2026:3782", "https://access.redhat.com/errata/RHSA-2026:3812", "https://access.redhat.com/errata/RHSA-2026:3813", "https://access.redhat.com/errata/RHSA-2026:3814", "https://access.redhat.com/errata/RHSA-2026:3815", "https://access.redhat.com/errata/RHSA-2026:3816", "https://access.redhat.com/errata/RHSA-2026:3817", "https://access.redhat.com/errata/RHSA-2026:3818", "https://access.redhat.com/errata/RHSA-2026:3820", "https://access.redhat.com/errata/RHSA-2026:3821", "https://access.redhat.com/errata/RHSA-2026:3822", "https://access.redhat.com/errata/RHSA-2026:3831", "https://access.redhat.com/errata/RHSA-2026:3833", "https://access.redhat.com/errata/RHSA-2026:3835", "https://access.redhat.com/errata/RHSA-2026:3836", "https://access.redhat.com/errata/RHSA-2026:3838", "https://access.redhat.com/errata/RHSA-2026:3839", "https://access.redhat.com/errata/RHSA-2026:3840", "https://access.redhat.com/errata/RHSA-2026:3841", "https://access.redhat.com/errata/RHSA-2026:3843", "https://access.redhat.com/errata/RHSA-2026:3854", "https://access.redhat.com/errata/RHSA-2026:3855", "https://access.redhat.com/errata/RHSA-2026:3856", "https://access.redhat.com/errata/RHSA-2026:3864", "https://access.redhat.com/errata/RHSA-2026:3869", "https://access.redhat.com/errata/RHSA-2026:3874", "https://access.redhat.com/errata/RHSA-2026:3875", "https://access.redhat.com/errata/RHSA-2026:3879", "https://access.redhat.com/errata/RHSA-2026:3880", "https://access.redhat.com/errata/RHSA-2026:3884", "https://access.redhat.com/errata/RHSA-2026:3898", "https://access.redhat.com/errata/RHSA-2026:3905", "https://access.redhat.com/errata/RHSA-2026:3906", "https://access.redhat.com/errata/RHSA-2026:3928", "https://access.redhat.com/errata/RHSA-2026:3929", "https://access.redhat.com/errata/RHSA-2026:3930", "https://access.redhat.com/errata/RHSA-2026:3931", "https://access.redhat.com/errata/RHSA-2026:3932", "https://access.redhat.com/errata/RHSA-2026:3958", "https://access.redhat.com/errata/RHSA-2026:3959", "https://access.redhat.com/errata/RHSA-2026:3960", "https://access.redhat.com/errata/RHSA-2026:3970", "https://access.redhat.com/errata/RHSA-2026:3971", "https://access.redhat.com/errata/RHSA-2026:3972", "https://access.redhat.com/errata/RHSA-2026:3973", "https://access.redhat.com/errata/RHSA-2026:3974", "https://access.redhat.com/errata/RHSA-2026:3977", "https://access.redhat.com/errata/RHSA-2026:39810", "https://access.redhat.com/errata/RHSA-2026:3985", "https://access.redhat.com/errata/RHSA-2026:40924", "https://access.redhat.com/errata/RHSA-2026:4164", "https://access.redhat.com/errata/RHSA-2026:4166", "https://access.redhat.com/errata/RHSA-2026:4170", "https://access.redhat.com/errata/RHSA-2026:4174", "https://access.redhat.com/errata/RHSA-2026:4177", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:41941", "https://access.redhat.com/errata/RHSA-2026:4211", "https://access.redhat.com/errata/RHSA-2026:4220", "https://access.redhat.com/errata/RHSA-2026:4256", "https://access.redhat.com/errata/RHSA-2026:4264", "https://access.redhat.com/errata/RHSA-2026:4267", "https://access.redhat.com/errata/RHSA-2026:4270", "https://access.redhat.com/errata/RHSA-2026:4276", "https://access.redhat.com/errata/RHSA-2026:4434", "https://access.redhat.com/errata/RHSA-2026:4435", "https://access.redhat.com/errata/RHSA-2026:4460", "https://access.redhat.com/errata/RHSA-2026:4466", "https://access.redhat.com/errata/RHSA-2026:4467", "https://access.redhat.com/errata/RHSA-2026:4498", "https://access.redhat.com/errata/RHSA-2026:4500", "https://access.redhat.com/errata/RHSA-2026:4510", "https://access.redhat.com/errata/RHSA-2026:4511", "https://access.redhat.com/errata/RHSA-2026:4672", "https://access.redhat.com/errata/RHSA-2026:46903", "https://access.redhat.com/errata/RHSA-2026:4753", "https://access.redhat.com/errata/RHSA-2026:4892", "https://access.redhat.com/errata/RHSA-2026:4901", "https://access.redhat.com/errata/RHSA-2026:4907", "https://access.redhat.com/errata/RHSA-2026:4939", "https://access.redhat.com/errata/RHSA-2026:4942", "https://access.redhat.com/errata/RHSA-2026:4943", "https://access.redhat.com/errata/RHSA-2026:4952", "https://access.redhat.com/errata/RHSA-2026:49944", "https://access.redhat.com/errata/RHSA-2026:5022", "https://access.redhat.com/errata/RHSA-2026:5030", "https://access.redhat.com/errata/RHSA-2026:5031", "https://access.redhat.com/errata/RHSA-2026:5076", "https://access.redhat.com/errata/RHSA-2026:5077", "https://access.redhat.com/errata/RHSA-2026:5078", "https://access.redhat.com/errata/RHSA-2026:5079", "https://access.redhat.com/errata/RHSA-2026:51033", "https://access.redhat.com/errata/RHSA-2026:5110", "https://access.redhat.com/errata/RHSA-2026:51288", "https://access.redhat.com/errata/RHSA-2026:5129", "https://access.redhat.com/errata/RHSA-2026:5130", "https://access.redhat.com/errata/RHSA-2026:5131", "https://access.redhat.com/errata/RHSA-2026:5132", "https://access.redhat.com/errata/RHSA-2026:5145", "https://access.redhat.com/errata/RHSA-2026:5146", "https://access.redhat.com/errata/RHSA-2026:5168", "https://access.redhat.com/errata/RHSA-2026:5327", "https://access.redhat.com/errata/RHSA-2026:5394", "https://access.redhat.com/errata/RHSA-2026:5439", "https://access.redhat.com/errata/RHSA-2026:5444", "https://access.redhat.com/errata/RHSA-2026:5447", "https://access.redhat.com/errata/RHSA-2026:5452", "https://access.redhat.com/errata/RHSA-2026:5461", "https://access.redhat.com/errata/RHSA-2026:5463", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:5533", "https://access.redhat.com/errata/RHSA-2026:5544", "https://access.redhat.com/errata/RHSA-2026:5549", "https://access.redhat.com/errata/RHSA-2026:5636", "https://access.redhat.com/errata/RHSA-2026:56366", "https://access.redhat.com/errata/RHSA-2026:56431", "https://access.redhat.com/errata/RHSA-2026:5645", "https://access.redhat.com/errata/RHSA-2026:5649", "https://access.redhat.com/errata/RHSA-2026:5665", "https://access.redhat.com/errata/RHSA-2026:57013", "https://access.redhat.com/errata/RHSA-2026:5807", "https://access.redhat.com/errata/RHSA-2026:5851", "https://access.redhat.com/errata/RHSA-2026:5852", "https://access.redhat.com/errata/RHSA-2026:5853", "https://access.redhat.com/errata/RHSA-2026:5948", "https://access.redhat.com/errata/RHSA-2026:5950", "https://access.redhat.com/errata/RHSA-2026:5952", "https://access.redhat.com/errata/RHSA-2026:5968", "https://access.redhat.com/errata/RHSA-2026:6184", "https://access.redhat.com/errata/RHSA-2026:6192", "https://access.redhat.com/errata/RHSA-2026:6226", "https://access.redhat.com/errata/RHSA-2026:6251", "https://access.redhat.com/errata/RHSA-2026:6277", "https://access.redhat.com/errata/RHSA-2026:6278", "https://access.redhat.com/errata/RHSA-2026:6428", "https://access.redhat.com/errata/RHSA-2026:6429", "https://access.redhat.com/errata/RHSA-2026:6497", "https://access.redhat.com/errata/RHSA-2026:6554", "https://access.redhat.com/errata/RHSA-2026:6564", "https://access.redhat.com/errata/RHSA-2026:6567", "https://access.redhat.com/errata/RHSA-2026:6568", "https://access.redhat.com/errata/RHSA-2026:66401", "https://access.redhat.com/errata/RHSA-2026:7052", "https://access.redhat.com/errata/RHSA-2026:7249", "https://access.redhat.com/errata/RHSA-2026:7291", "https://access.redhat.com/errata/RHSA-2026:7385", "https://access.redhat.com/errata/RHSA-2026:7676", "https://access.redhat.com/errata/RHSA-2026:7854", "https://access.redhat.com/errata/RHSA-2026:7942", "https://access.redhat.com/errata/RHSA-2026:8151", "https://access.redhat.com/errata/RHSA-2026:8167", "https://access.redhat.com/errata/RHSA-2026:8218", "https://access.redhat.com/errata/RHSA-2026:8229", "https://access.redhat.com/errata/RHSA-2026:8337", "https://access.redhat.com/errata/RHSA-2026:8338", "https://access.redhat.com/errata/RHSA-2026:8431", "https://access.redhat.com/errata/RHSA-2026:8433", "https://access.redhat.com/errata/RHSA-2026:8483", "https://access.redhat.com/errata/RHSA-2026:9097", "https://access.redhat.com/errata/RHSA-2026:9098", "https://access.redhat.com/errata/RHSA-2026:9108", "https://access.redhat.com/errata/RHSA-2026:9109", "https://access.redhat.com/errata/RHSA-2026:9848", "https://access.redhat.com/security/cve/CVE-2025-61726", "https://bugzilla.redhat.com/2434432", "https://bugzilla.redhat.com/2437111", "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", "https://errata.almalinux.org/9/ALSA-2026-4177.html", "https://errata.rockylinux.org/RLSA-2026:4177", "https://go.dev/cl/736712", "https://go.dev/issue/77101", "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", "https://linux.oracle.com/cve/CVE-2025-61726.html", "https://linux.oracle.com/errata/ELSA-2026-5146.html", "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", "https://pkg.go.dev/vuln/GO-2026-4341", "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", "https://www.cve.org/CVERecord?id=CVE-2025-61726" ], "PublishedDate": "2026-01-28T20:16:09.713Z", "LastModifiedDate": "2026-09-11T13:16:49.81Z" }, { "VulnerabilityID": "CVE-2025-61729", "VendorIDs": [ "GO-2025-4155" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.24.11, 1.25.5", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:d7e5e7734c69cbd7621f0b90b22f75df51bbf1668935979fe9f2f86054824576", "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", "Severity": "HIGH", "CweIDs": [ "CWE-295" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "bitnami": 3, "cbl-mariner": 1, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:3928", "https://access.redhat.com/security/cve/CVE-2025-61729", "https://bugzilla.redhat.com/2418462", "https://bugzilla.redhat.com/2434432", "https://bugzilla.redhat.com/2437111", "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", "https://errata.almalinux.org/9/ALSA-2026-3928.html", "https://errata.rockylinux.org/RLSA-2026:3928", "https://go.dev/cl/725920", "https://go.dev/issue/76445", "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", "https://linux.oracle.com/cve/CVE-2025-61729.html", "https://linux.oracle.com/errata/ELSA-2026-5146.html", "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", "https://pkg.go.dev/vuln/GO-2025-4155", "https://www.cve.org/CVERecord?id=CVE-2025-61729" ], "PublishedDate": "2025-12-02T19:15:51.447Z", "LastModifiedDate": "2026-06-17T09:50:48.507Z" }, { "VulnerabilityID": "CVE-2026-25679", "VendorIDs": [ "GO-2026-4601" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.8, 1.26.1", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:56e02f7cd346e0e23b77d3b151ceb12bd4d1daf93a5328ceceea0634ece1a7ac", "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", "Severity": "HIGH", "CweIDs": [ "CWE-425", "CWE-1286" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:10065", "https://access.redhat.com/errata/RHSA-2026:10125", "https://access.redhat.com/errata/RHSA-2026:10133", "https://access.redhat.com/errata/RHSA-2026:10140", "https://access.redhat.com/errata/RHSA-2026:10141", "https://access.redhat.com/errata/RHSA-2026:10158", "https://access.redhat.com/errata/RHSA-2026:10169", "https://access.redhat.com/errata/RHSA-2026:10175", "https://access.redhat.com/errata/RHSA-2026:10184", "https://access.redhat.com/errata/RHSA-2026:10225", "https://access.redhat.com/errata/RHSA-2026:10250", "https://access.redhat.com/errata/RHSA-2026:10701", "https://access.redhat.com/errata/RHSA-2026:10712", "https://access.redhat.com/errata/RHSA-2026:10929", "https://access.redhat.com/errata/RHSA-2026:11217", "https://access.redhat.com/errata/RHSA-2026:11375", "https://access.redhat.com/errata/RHSA-2026:11412", "https://access.redhat.com/errata/RHSA-2026:11413", "https://access.redhat.com/errata/RHSA-2026:11686", "https://access.redhat.com/errata/RHSA-2026:11688", "https://access.redhat.com/errata/RHSA-2026:11747", "https://access.redhat.com/errata/RHSA-2026:11749", "https://access.redhat.com/errata/RHSA-2026:11768", "https://access.redhat.com/errata/RHSA-2026:11800", "https://access.redhat.com/errata/RHSA-2026:11856", "https://access.redhat.com/errata/RHSA-2026:11916", "https://access.redhat.com/errata/RHSA-2026:11996", "https://access.redhat.com/errata/RHSA-2026:12028", "https://access.redhat.com/errata/RHSA-2026:12029", "https://access.redhat.com/errata/RHSA-2026:12030", "https://access.redhat.com/errata/RHSA-2026:12031", "https://access.redhat.com/errata/RHSA-2026:12032", "https://access.redhat.com/errata/RHSA-2026:12033", "https://access.redhat.com/errata/RHSA-2026:12282", "https://access.redhat.com/errata/RHSA-2026:13508", "https://access.redhat.com/errata/RHSA-2026:13512", "https://access.redhat.com/errata/RHSA-2026:13545", "https://access.redhat.com/errata/RHSA-2026:13642", "https://access.redhat.com/errata/RHSA-2026:13643", "https://access.redhat.com/errata/RHSA-2026:13671", "https://access.redhat.com/errata/RHSA-2026:13791", "https://access.redhat.com/errata/RHSA-2026:13829", "https://access.redhat.com/errata/RHSA-2026:14020", "https://access.redhat.com/errata/RHSA-2026:14100", "https://access.redhat.com/errata/RHSA-2026:14774", "https://access.redhat.com/errata/RHSA-2026:14868", "https://access.redhat.com/errata/RHSA-2026:14879", "https://access.redhat.com/errata/RHSA-2026:15091", "https://access.redhat.com/errata/RHSA-2026:16102", "https://access.redhat.com/errata/RHSA-2026:16696", "https://access.redhat.com/errata/RHSA-2026:16874", "https://access.redhat.com/errata/RHSA-2026:16875", "https://access.redhat.com/errata/RHSA-2026:17040", "https://access.redhat.com/errata/RHSA-2026:17084", "https://access.redhat.com/errata/RHSA-2026:17287", "https://access.redhat.com/errata/RHSA-2026:17598", "https://access.redhat.com/errata/RHSA-2026:19017", "https://access.redhat.com/errata/RHSA-2026:19022", "https://access.redhat.com/errata/RHSA-2026:19026", "https://access.redhat.com/errata/RHSA-2026:19027", "https://access.redhat.com/errata/RHSA-2026:19031", "https://access.redhat.com/errata/RHSA-2026:19032", "https://access.redhat.com/errata/RHSA-2026:19049", "https://access.redhat.com/errata/RHSA-2026:19055", "https://access.redhat.com/errata/RHSA-2026:19126", "https://access.redhat.com/errata/RHSA-2026:19128", "https://access.redhat.com/errata/RHSA-2026:19132", "https://access.redhat.com/errata/RHSA-2026:19133", "https://access.redhat.com/errata/RHSA-2026:19135", "https://access.redhat.com/errata/RHSA-2026:19181", "https://access.redhat.com/errata/RHSA-2026:19184", "https://access.redhat.com/errata/RHSA-2026:19185", "https://access.redhat.com/errata/RHSA-2026:19207", "https://access.redhat.com/errata/RHSA-2026:19350", "https://access.redhat.com/errata/RHSA-2026:19353", "https://access.redhat.com/errata/RHSA-2026:19375", "https://access.redhat.com/errata/RHSA-2026:19475", "https://access.redhat.com/errata/RHSA-2026:19634", "https://access.redhat.com/errata/RHSA-2026:19719", "https://access.redhat.com/errata/RHSA-2026:19720", "https://access.redhat.com/errata/RHSA-2026:19721", "https://access.redhat.com/errata/RHSA-2026:19750", "https://access.redhat.com/errata/RHSA-2026:20041", "https://access.redhat.com/errata/RHSA-2026:20088", "https://access.redhat.com/errata/RHSA-2026:20581", "https://access.redhat.com/errata/RHSA-2026:20582", "https://access.redhat.com/errata/RHSA-2026:20584", "https://access.redhat.com/errata/RHSA-2026:20889", "https://access.redhat.com/errata/RHSA-2026:21017", "https://access.redhat.com/errata/RHSA-2026:21655", "https://access.redhat.com/errata/RHSA-2026:21657", "https://access.redhat.com/errata/RHSA-2026:21691", "https://access.redhat.com/errata/RHSA-2026:21696", "https://access.redhat.com/errata/RHSA-2026:21769", "https://access.redhat.com/errata/RHSA-2026:22347", "https://access.redhat.com/errata/RHSA-2026:22423", "https://access.redhat.com/errata/RHSA-2026:22450", "https://access.redhat.com/errata/RHSA-2026:22627", "https://access.redhat.com/errata/RHSA-2026:22714", "https://access.redhat.com/errata/RHSA-2026:22733", "https://access.redhat.com/errata/RHSA-2026:22862", "https://access.redhat.com/errata/RHSA-2026:22937", "https://access.redhat.com/errata/RHSA-2026:23228", "https://access.redhat.com/errata/RHSA-2026:23345", "https://access.redhat.com/errata/RHSA-2026:24386", "https://access.redhat.com/errata/RHSA-2026:24853", "https://access.redhat.com/errata/RHSA-2026:25043", "https://access.redhat.com/errata/RHSA-2026:25127", "https://access.redhat.com/errata/RHSA-2026:25180", "https://access.redhat.com/errata/RHSA-2026:25248", "https://access.redhat.com/errata/RHSA-2026:25250", "https://access.redhat.com/errata/RHSA-2026:25251", "https://access.redhat.com/errata/RHSA-2026:25252", "https://access.redhat.com/errata/RHSA-2026:25253", "https://access.redhat.com/errata/RHSA-2026:26445", "https://access.redhat.com/errata/RHSA-2026:26527", "https://access.redhat.com/errata/RHSA-2026:26541", "https://access.redhat.com/errata/RHSA-2026:26568", "https://access.redhat.com/errata/RHSA-2026:26585", "https://access.redhat.com/errata/RHSA-2026:26636", "https://access.redhat.com/errata/RHSA-2026:27076", "https://access.redhat.com/errata/RHSA-2026:28047", "https://access.redhat.com/errata/RHSA-2026:28441", "https://access.redhat.com/errata/RHSA-2026:28886", "https://access.redhat.com/errata/RHSA-2026:28893", "https://access.redhat.com/errata/RHSA-2026:28961", "https://access.redhat.com/errata/RHSA-2026:29035", "https://access.redhat.com/errata/RHSA-2026:29195", "https://access.redhat.com/errata/RHSA-2026:29455", "https://access.redhat.com/errata/RHSA-2026:29702", "https://access.redhat.com/errata/RHSA-2026:29703", "https://access.redhat.com/errata/RHSA-2026:29854", "https://access.redhat.com/errata/RHSA-2026:33722", "https://access.redhat.com/errata/RHSA-2026:34097", "https://access.redhat.com/errata/RHSA-2026:34365", "https://access.redhat.com/errata/RHSA-2026:36317", "https://access.redhat.com/errata/RHSA-2026:36319", "https://access.redhat.com/errata/RHSA-2026:36651", "https://access.redhat.com/errata/RHSA-2026:36796", "https://access.redhat.com/errata/RHSA-2026:39810", "https://access.redhat.com/errata/RHSA-2026:40118", "https://access.redhat.com/errata/RHSA-2026:40945", "https://access.redhat.com/errata/RHSA-2026:41019", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:42150", "https://access.redhat.com/errata/RHSA-2026:42151", "https://access.redhat.com/errata/RHSA-2026:48036", "https://access.redhat.com/errata/RHSA-2026:49944", "https://access.redhat.com/errata/RHSA-2026:5110", "https://access.redhat.com/errata/RHSA-2026:51288", "https://access.redhat.com/errata/RHSA-2026:52389", "https://access.redhat.com/errata/RHSA-2026:52390", "https://access.redhat.com/errata/RHSA-2026:52391", "https://access.redhat.com/errata/RHSA-2026:54191", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:5549", "https://access.redhat.com/errata/RHSA-2026:56785", "https://access.redhat.com/errata/RHSA-2026:56852", "https://access.redhat.com/errata/RHSA-2026:56910", "https://access.redhat.com/errata/RHSA-2026:57482", "https://access.redhat.com/errata/RHSA-2026:5941", "https://access.redhat.com/errata/RHSA-2026:5942", "https://access.redhat.com/errata/RHSA-2026:5943", "https://access.redhat.com/errata/RHSA-2026:5944", "https://access.redhat.com/errata/RHSA-2026:59830", "https://access.redhat.com/errata/RHSA-2026:60018", "https://access.redhat.com/errata/RHSA-2026:6341", "https://access.redhat.com/errata/RHSA-2026:6344", "https://access.redhat.com/errata/RHSA-2026:6382", "https://access.redhat.com/errata/RHSA-2026:6383", "https://access.redhat.com/errata/RHSA-2026:6388", "https://access.redhat.com/errata/RHSA-2026:6564", "https://access.redhat.com/errata/RHSA-2026:66401", "https://access.redhat.com/errata/RHSA-2026:6720", "https://access.redhat.com/errata/RHSA-2026:6802", "https://access.redhat.com/errata/RHSA-2026:6949", "https://access.redhat.com/errata/RHSA-2026:7005", "https://access.redhat.com/errata/RHSA-2026:7009", "https://access.redhat.com/errata/RHSA-2026:7011", "https://access.redhat.com/errata/RHSA-2026:7259", "https://access.redhat.com/errata/RHSA-2026:7291", "https://access.redhat.com/errata/RHSA-2026:7315", "https://access.redhat.com/errata/RHSA-2026:7328", "https://access.redhat.com/errata/RHSA-2026:7385", "https://access.redhat.com/errata/RHSA-2026:7665", "https://access.redhat.com/errata/RHSA-2026:7669", "https://access.redhat.com/errata/RHSA-2026:7674", "https://access.redhat.com/errata/RHSA-2026:7833", "https://access.redhat.com/errata/RHSA-2026:7834", "https://access.redhat.com/errata/RHSA-2026:7876", "https://access.redhat.com/errata/RHSA-2026:7877", "https://access.redhat.com/errata/RHSA-2026:7878", "https://access.redhat.com/errata/RHSA-2026:7879", "https://access.redhat.com/errata/RHSA-2026:7883", "https://access.redhat.com/errata/RHSA-2026:7992", "https://access.redhat.com/errata/RHSA-2026:8151", "https://access.redhat.com/errata/RHSA-2026:8167", "https://access.redhat.com/errata/RHSA-2026:8314", "https://access.redhat.com/errata/RHSA-2026:8322", "https://access.redhat.com/errata/RHSA-2026:8324", "https://access.redhat.com/errata/RHSA-2026:8337", "https://access.redhat.com/errata/RHSA-2026:8338", "https://access.redhat.com/errata/RHSA-2026:8433", "https://access.redhat.com/errata/RHSA-2026:8434", "https://access.redhat.com/errata/RHSA-2026:8456", "https://access.redhat.com/errata/RHSA-2026:8483", "https://access.redhat.com/errata/RHSA-2026:8484", "https://access.redhat.com/errata/RHSA-2026:8490", "https://access.redhat.com/errata/RHSA-2026:8491", "https://access.redhat.com/errata/RHSA-2026:8493", "https://access.redhat.com/errata/RHSA-2026:8840", "https://access.redhat.com/errata/RHSA-2026:8841", "https://access.redhat.com/errata/RHSA-2026:8842", "https://access.redhat.com/errata/RHSA-2026:8845", "https://access.redhat.com/errata/RHSA-2026:8847", "https://access.redhat.com/errata/RHSA-2026:8848", "https://access.redhat.com/errata/RHSA-2026:8849", "https://access.redhat.com/errata/RHSA-2026:8851", "https://access.redhat.com/errata/RHSA-2026:8852", "https://access.redhat.com/errata/RHSA-2026:8853", "https://access.redhat.com/errata/RHSA-2026:8855", "https://access.redhat.com/errata/RHSA-2026:8856", "https://access.redhat.com/errata/RHSA-2026:8860", "https://access.redhat.com/errata/RHSA-2026:8877", "https://access.redhat.com/errata/RHSA-2026:8878", "https://access.redhat.com/errata/RHSA-2026:8879", "https://access.redhat.com/errata/RHSA-2026:8881", "https://access.redhat.com/errata/RHSA-2026:8882", "https://access.redhat.com/errata/RHSA-2026:8930", "https://access.redhat.com/errata/RHSA-2026:8931", "https://access.redhat.com/errata/RHSA-2026:8949", "https://access.redhat.com/errata/RHSA-2026:9043", "https://access.redhat.com/errata/RHSA-2026:9044", "https://access.redhat.com/errata/RHSA-2026:9052", "https://access.redhat.com/errata/RHSA-2026:9090", "https://access.redhat.com/errata/RHSA-2026:9093", "https://access.redhat.com/errata/RHSA-2026:9094", "https://access.redhat.com/errata/RHSA-2026:9097", "https://access.redhat.com/errata/RHSA-2026:9098", "https://access.redhat.com/errata/RHSA-2026:9108", "https://access.redhat.com/errata/RHSA-2026:9109", "https://access.redhat.com/errata/RHSA-2026:9385", "https://access.redhat.com/errata/RHSA-2026:9434", "https://access.redhat.com/errata/RHSA-2026:9435", "https://access.redhat.com/errata/RHSA-2026:9436", "https://access.redhat.com/errata/RHSA-2026:9439", "https://access.redhat.com/errata/RHSA-2026:9440", "https://access.redhat.com/errata/RHSA-2026:9448", "https://access.redhat.com/errata/RHSA-2026:9453", "https://access.redhat.com/errata/RHSA-2026:9461", "https://access.redhat.com/errata/RHSA-2026:9695", "https://access.redhat.com/errata/RHSA-2026:9742", "https://access.redhat.com/errata/RHSA-2026:9872", "https://access.redhat.com/security/cve/CVE-2026-25679", "https://bugzilla.redhat.com/2445356", "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "https://errata.almalinux.org/9/ALSA-2026-9044.html", "https://errata.rockylinux.org/RLSA-2026:9044", "https://go.dev/cl/752180", "https://go.dev/issue/77578", "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", "https://linux.oracle.com/cve/CVE-2026-25679.html", "https://linux.oracle.com/errata/ELSA-2026-9044.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", "https://pkg.go.dev/vuln/GO-2026-4601", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", "https://www.cve.org/CVERecord?id=CVE-2026-25679" ], "PublishedDate": "2026-03-06T22:16:00.72Z", "LastModifiedDate": "2026-09-11T13:17:13.637Z" }, { "VulnerabilityID": "CVE-2026-27145", "VendorIDs": [ "GO-2026-5037" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.11, 1.26.4", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:3a7c09b1d1aae4c56ea7871cfa8b82a1887516521bbe983e8dcf0a1b590fb325", "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", "Severity": "HIGH", "CweIDs": [ "CWE-606" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 2, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:23262", "https://access.redhat.com/errata/RHSA-2026:23264", "https://access.redhat.com/errata/RHSA-2026:29980", "https://access.redhat.com/errata/RHSA-2026:29981", "https://access.redhat.com/errata/RHSA-2026:33574", "https://access.redhat.com/errata/RHSA-2026:34357", "https://access.redhat.com/errata/RHSA-2026:34359", "https://access.redhat.com/errata/RHSA-2026:35832", "https://access.redhat.com/errata/RHSA-2026:36317", "https://access.redhat.com/errata/RHSA-2026:36648", "https://access.redhat.com/errata/RHSA-2026:36797", "https://access.redhat.com/errata/RHSA-2026:38995", "https://access.redhat.com/errata/RHSA-2026:39005", "https://access.redhat.com/errata/RHSA-2026:39573", "https://access.redhat.com/errata/RHSA-2026:39879", "https://access.redhat.com/errata/RHSA-2026:41030", "https://access.redhat.com/errata/RHSA-2026:41036", "https://access.redhat.com/errata/RHSA-2026:41930", "https://access.redhat.com/errata/RHSA-2026:42043", "https://access.redhat.com/errata/RHSA-2026:42047", "https://access.redhat.com/errata/RHSA-2026:42049", "https://access.redhat.com/errata/RHSA-2026:42050", "https://access.redhat.com/errata/RHSA-2026:42051", "https://access.redhat.com/errata/RHSA-2026:42079", "https://access.redhat.com/errata/RHSA-2026:42080", "https://access.redhat.com/errata/RHSA-2026:42082", "https://access.redhat.com/errata/RHSA-2026:42142", "https://access.redhat.com/errata/RHSA-2026:42150", "https://access.redhat.com/errata/RHSA-2026:42151", "https://access.redhat.com/errata/RHSA-2026:42240", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:42946", "https://access.redhat.com/errata/RHSA-2026:44622", "https://access.redhat.com/errata/RHSA-2026:46394", "https://access.redhat.com/errata/RHSA-2026:46395", "https://access.redhat.com/errata/RHSA-2026:47149", "https://access.redhat.com/errata/RHSA-2026:47735", "https://access.redhat.com/errata/RHSA-2026:47737", "https://access.redhat.com/errata/RHSA-2026:49702", "https://access.redhat.com/errata/RHSA-2026:49703", "https://access.redhat.com/errata/RHSA-2026:49705", "https://access.redhat.com/errata/RHSA-2026:49712", "https://access.redhat.com/errata/RHSA-2026:49729", "https://access.redhat.com/errata/RHSA-2026:49744", "https://access.redhat.com/errata/RHSA-2026:49765", "https://access.redhat.com/errata/RHSA-2026:49770", "https://access.redhat.com/errata/RHSA-2026:50205", "https://access.redhat.com/errata/RHSA-2026:50319", "https://access.redhat.com/errata/RHSA-2026:51057", "https://access.redhat.com/errata/RHSA-2026:51187", "https://access.redhat.com/errata/RHSA-2026:52946", "https://access.redhat.com/errata/RHSA-2026:53374", "https://access.redhat.com/errata/RHSA-2026:53412", "https://access.redhat.com/errata/RHSA-2026:53413", "https://access.redhat.com/errata/RHSA-2026:53415", "https://access.redhat.com/errata/RHSA-2026:53416", "https://access.redhat.com/errata/RHSA-2026:53530", "https://access.redhat.com/errata/RHSA-2026:54168", "https://access.redhat.com/errata/RHSA-2026:54401", "https://access.redhat.com/errata/RHSA-2026:54427", "https://access.redhat.com/errata/RHSA-2026:54432", "https://access.redhat.com/errata/RHSA-2026:54435", "https://access.redhat.com/errata/RHSA-2026:54441", "https://access.redhat.com/errata/RHSA-2026:54500", "https://access.redhat.com/errata/RHSA-2026:54525", "https://access.redhat.com/errata/RHSA-2026:54531", "https://access.redhat.com/errata/RHSA-2026:54603", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:55899", "https://access.redhat.com/errata/RHSA-2026:57194", "https://access.redhat.com/errata/RHSA-2026:57482", "https://access.redhat.com/errata/RHSA-2026:57488", "https://access.redhat.com/errata/RHSA-2026:57649", "https://access.redhat.com/errata/RHSA-2026:59556", "https://access.redhat.com/errata/RHSA-2026:59557", "https://access.redhat.com/errata/RHSA-2026:59558", "https://access.redhat.com/errata/RHSA-2026:59559", "https://access.redhat.com/errata/RHSA-2026:59579", "https://access.redhat.com/errata/RHSA-2026:59593", "https://access.redhat.com/errata/RHSA-2026:60025", "https://access.redhat.com/errata/RHSA-2026:60315", "https://access.redhat.com/errata/RHSA-2026:60354", "https://access.redhat.com/errata/RHSA-2026:60386", "https://access.redhat.com/errata/RHSA-2026:60387", "https://access.redhat.com/errata/RHSA-2026:60388", "https://access.redhat.com/errata/RHSA-2026:60390", "https://access.redhat.com/errata/RHSA-2026:60391", "https://access.redhat.com/errata/RHSA-2026:61253", "https://access.redhat.com/errata/RHSA-2026:61314", "https://access.redhat.com/errata/RHSA-2026:63016", "https://access.redhat.com/errata/RHSA-2026:66022", "https://access.redhat.com/security/cve/CVE-2026-27145", "https://bugzilla.redhat.com/2445356", "https://bugzilla.redhat.com/2484207", "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", "https://errata.almalinux.org/9/ALSA-2026-36317.html", "https://errata.rockylinux.org/RLSA-2026:36317", "https://go.dev/cl/783621", "https://go.dev/issue/79694", "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", "https://linux.oracle.com/cve/CVE-2026-27145.html", "https://linux.oracle.com/errata/ELSA-2026-46395.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", "https://pkg.go.dev/vuln/GO-2026-5037", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", "https://www.cve.org/CVERecord?id=CVE-2026-27145" ], "PublishedDate": "2026-06-02T23:16:35.57Z", "LastModifiedDate": "2026-09-11T13:17:23.34Z" }, { "VulnerabilityID": "CVE-2026-32280", "VendorIDs": [ "GO-2026-4947" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.9, 1.26.2", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:410ae40aee7fb35c67628e5cd49f29fceb7608c091a712b76b32aa59d9e10eac", "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:10217", "https://access.redhat.com/errata/RHSA-2026:10219", "https://access.redhat.com/errata/RHSA-2026:10704", "https://access.redhat.com/errata/RHSA-2026:11507", "https://access.redhat.com/errata/RHSA-2026:11514", "https://access.redhat.com/errata/RHSA-2026:11688", "https://access.redhat.com/errata/RHSA-2026:13545", "https://access.redhat.com/errata/RHSA-2026:13791", "https://access.redhat.com/errata/RHSA-2026:13826", "https://access.redhat.com/errata/RHSA-2026:13829", "https://access.redhat.com/errata/RHSA-2026:14020", "https://access.redhat.com/errata/RHSA-2026:14162", "https://access.redhat.com/errata/RHSA-2026:14200", "https://access.redhat.com/errata/RHSA-2026:14391", "https://access.redhat.com/errata/RHSA-2026:15980", "https://access.redhat.com/errata/RHSA-2026:16021", "https://access.redhat.com/errata/RHSA-2026:16024", "https://access.redhat.com/errata/RHSA-2026:16101", "https://access.redhat.com/errata/RHSA-2026:16476", "https://access.redhat.com/errata/RHSA-2026:16477", "https://access.redhat.com/errata/RHSA-2026:16505", "https://access.redhat.com/errata/RHSA-2026:16508", "https://access.redhat.com/errata/RHSA-2026:16532", "https://access.redhat.com/errata/RHSA-2026:16534", "https://access.redhat.com/errata/RHSA-2026:16535", "https://access.redhat.com/errata/RHSA-2026:16537", "https://access.redhat.com/errata/RHSA-2026:16542", "https://access.redhat.com/errata/RHSA-2026:16874", "https://access.redhat.com/errata/RHSA-2026:16875", "https://access.redhat.com/errata/RHSA-2026:17084", "https://access.redhat.com/errata/RHSA-2026:17287", "https://access.redhat.com/errata/RHSA-2026:18027", "https://access.redhat.com/errata/RHSA-2026:18032", "https://access.redhat.com/errata/RHSA-2026:19133", "https://access.redhat.com/errata/RHSA-2026:19135", "https://access.redhat.com/errata/RHSA-2026:19144", "https://access.redhat.com/errata/RHSA-2026:19350", "https://access.redhat.com/errata/RHSA-2026:19353", "https://access.redhat.com/errata/RHSA-2026:19375", "https://access.redhat.com/errata/RHSA-2026:19450", "https://access.redhat.com/errata/RHSA-2026:19550", "https://access.redhat.com/errata/RHSA-2026:19634", "https://access.redhat.com/errata/RHSA-2026:19714", "https://access.redhat.com/errata/RHSA-2026:19715", "https://access.redhat.com/errata/RHSA-2026:19719", "https://access.redhat.com/errata/RHSA-2026:19720", "https://access.redhat.com/errata/RHSA-2026:19721", "https://access.redhat.com/errata/RHSA-2026:19722", "https://access.redhat.com/errata/RHSA-2026:19750", "https://access.redhat.com/errata/RHSA-2026:19839", "https://access.redhat.com/errata/RHSA-2026:20556", "https://access.redhat.com/errata/RHSA-2026:20569", "https://access.redhat.com/errata/RHSA-2026:20570", "https://access.redhat.com/errata/RHSA-2026:20571", "https://access.redhat.com/errata/RHSA-2026:20607", "https://access.redhat.com/errata/RHSA-2026:20608", "https://access.redhat.com/errata/RHSA-2026:20609", "https://access.redhat.com/errata/RHSA-2026:20889", "https://access.redhat.com/errata/RHSA-2026:21017", "https://access.redhat.com/errata/RHSA-2026:21338", "https://access.redhat.com/errata/RHSA-2026:21655", "https://access.redhat.com/errata/RHSA-2026:21769", "https://access.redhat.com/errata/RHSA-2026:21772", "https://access.redhat.com/errata/RHSA-2026:22130", "https://access.redhat.com/errata/RHSA-2026:22141", "https://access.redhat.com/errata/RHSA-2026:22258", "https://access.redhat.com/errata/RHSA-2026:22260", "https://access.redhat.com/errata/RHSA-2026:22268", "https://access.redhat.com/errata/RHSA-2026:22309", "https://access.redhat.com/errata/RHSA-2026:22347", "https://access.redhat.com/errata/RHSA-2026:22415", "https://access.redhat.com/errata/RHSA-2026:22422", "https://access.redhat.com/errata/RHSA-2026:22465", "https://access.redhat.com/errata/RHSA-2026:22485", "https://access.redhat.com/errata/RHSA-2026:22709", "https://access.redhat.com/errata/RHSA-2026:22713", "https://access.redhat.com/errata/RHSA-2026:22840", "https://access.redhat.com/errata/RHSA-2026:22862", "https://access.redhat.com/errata/RHSA-2026:22958", "https://access.redhat.com/errata/RHSA-2026:22959", "https://access.redhat.com/errata/RHSA-2026:22960", "https://access.redhat.com/errata/RHSA-2026:22961", "https://access.redhat.com/errata/RHSA-2026:22962", "https://access.redhat.com/errata/RHSA-2026:23102", "https://access.redhat.com/errata/RHSA-2026:23103", "https://access.redhat.com/errata/RHSA-2026:23244", "https://access.redhat.com/errata/RHSA-2026:23345", "https://access.redhat.com/errata/RHSA-2026:23361", "https://access.redhat.com/errata/RHSA-2026:24337", "https://access.redhat.com/errata/RHSA-2026:24359", "https://access.redhat.com/errata/RHSA-2026:24470", "https://access.redhat.com/errata/RHSA-2026:24478", "https://access.redhat.com/errata/RHSA-2026:24716", "https://access.redhat.com/errata/RHSA-2026:24761", "https://access.redhat.com/errata/RHSA-2026:24762", "https://access.redhat.com/errata/RHSA-2026:24853", "https://access.redhat.com/errata/RHSA-2026:24977", "https://access.redhat.com/errata/RHSA-2026:25089", "https://access.redhat.com/errata/RHSA-2026:25127", "https://access.redhat.com/errata/RHSA-2026:25180", "https://access.redhat.com/errata/RHSA-2026:25248", "https://access.redhat.com/errata/RHSA-2026:25250", "https://access.redhat.com/errata/RHSA-2026:25251", "https://access.redhat.com/errata/RHSA-2026:25252", "https://access.redhat.com/errata/RHSA-2026:25253", "https://access.redhat.com/errata/RHSA-2026:26447", "https://access.redhat.com/errata/RHSA-2026:26568", "https://access.redhat.com/errata/RHSA-2026:26571", "https://access.redhat.com/errata/RHSA-2026:26585", "https://access.redhat.com/errata/RHSA-2026:26636", "https://access.redhat.com/errata/RHSA-2026:27076", "https://access.redhat.com/errata/RHSA-2026:28038", "https://access.redhat.com/errata/RHSA-2026:28047", "https://access.redhat.com/errata/RHSA-2026:28074", "https://access.redhat.com/errata/RHSA-2026:28196", "https://access.redhat.com/errata/RHSA-2026:28198", "https://access.redhat.com/errata/RHSA-2026:28441", "https://access.redhat.com/errata/RHSA-2026:28886", "https://access.redhat.com/errata/RHSA-2026:28961", "https://access.redhat.com/errata/RHSA-2026:29035", "https://access.redhat.com/errata/RHSA-2026:29195", "https://access.redhat.com/errata/RHSA-2026:29455", "https://access.redhat.com/errata/RHSA-2026:29702", "https://access.redhat.com/errata/RHSA-2026:29703", "https://access.redhat.com/errata/RHSA-2026:29854", "https://access.redhat.com/errata/RHSA-2026:33722", "https://access.redhat.com/errata/RHSA-2026:34097", "https://access.redhat.com/errata/RHSA-2026:34192", "https://access.redhat.com/errata/RHSA-2026:34196", "https://access.redhat.com/errata/RHSA-2026:34197", "https://access.redhat.com/errata/RHSA-2026:34365", "https://access.redhat.com/errata/RHSA-2026:36319", "https://access.redhat.com/errata/RHSA-2026:36625", "https://access.redhat.com/errata/RHSA-2026:36651", "https://access.redhat.com/errata/RHSA-2026:36796", "https://access.redhat.com/errata/RHSA-2026:39810", "https://access.redhat.com/errata/RHSA-2026:39894", "https://access.redhat.com/errata/RHSA-2026:40118", "https://access.redhat.com/errata/RHSA-2026:40945", "https://access.redhat.com/errata/RHSA-2026:41019", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:42043", "https://access.redhat.com/errata/RHSA-2026:42047", "https://access.redhat.com/errata/RHSA-2026:42049", "https://access.redhat.com/errata/RHSA-2026:42050", "https://access.redhat.com/errata/RHSA-2026:42051", "https://access.redhat.com/errata/RHSA-2026:47712", "https://access.redhat.com/errata/RHSA-2026:47714", "https://access.redhat.com/errata/RHSA-2026:47716", "https://access.redhat.com/errata/RHSA-2026:47719", "https://access.redhat.com/errata/RHSA-2026:47721", "https://access.redhat.com/errata/RHSA-2026:47722", "https://access.redhat.com/errata/RHSA-2026:47910", "https://access.redhat.com/errata/RHSA-2026:47952", "https://access.redhat.com/errata/RHSA-2026:48036", "https://access.redhat.com/errata/RHSA-2026:48790", "https://access.redhat.com/errata/RHSA-2026:49509", "https://access.redhat.com/errata/RHSA-2026:49526", "https://access.redhat.com/errata/RHSA-2026:49600", "https://access.redhat.com/errata/RHSA-2026:49838", "https://access.redhat.com/errata/RHSA-2026:49944", "https://access.redhat.com/errata/RHSA-2026:51033", "https://access.redhat.com/errata/RHSA-2026:51288", "https://access.redhat.com/errata/RHSA-2026:54191", "https://access.redhat.com/errata/RHSA-2026:54603", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:56785", "https://access.redhat.com/errata/RHSA-2026:56789", "https://access.redhat.com/errata/RHSA-2026:56852", "https://access.redhat.com/errata/RHSA-2026:56855", "https://access.redhat.com/errata/RHSA-2026:56910", "https://access.redhat.com/errata/RHSA-2026:56912", "https://access.redhat.com/errata/RHSA-2026:56913", "https://access.redhat.com/errata/RHSA-2026:57409", "https://access.redhat.com/errata/RHSA-2026:57482", "https://access.redhat.com/errata/RHSA-2026:57488", "https://access.redhat.com/errata/RHSA-2026:59830", "https://access.redhat.com/errata/RHSA-2026:59833", "https://access.redhat.com/errata/RHSA-2026:59834", "https://access.redhat.com/errata/RHSA-2026:60018", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:61685", "https://access.redhat.com/errata/RHSA-2026:61906", "https://access.redhat.com/errata/RHSA-2026:61907", "https://access.redhat.com/errata/RHSA-2026:65534", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/errata/RHSA-2026:66401", "https://access.redhat.com/errata/RHSA-2026:9385", "https://access.redhat.com/security/cve/CVE-2026-32280", "https://bugzilla.redhat.com/2456333", "https://bugzilla.redhat.com/2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-49838.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/758320", "https://go.dev/issue/78282", "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", "https://linux.oracle.com/cve/CVE-2026-32280.html", "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", "https://pkg.go.dev/vuln/GO-2026-4947", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", "https://www.cve.org/CVERecord?id=CVE-2026-32280" ], "PublishedDate": "2026-04-08T02:16:03.247Z", "LastModifiedDate": "2026-09-11T13:17:25.78Z" }, { "VulnerabilityID": "CVE-2026-32281", "VendorIDs": [ "GO-2026-4946" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.9, 1.26.2", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:3947214e46925b7bcc5973fb91791daf2df731a64d5664c98c3670ffb6aef6e8", "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", "Severity": "HIGH", "CweIDs": [ "CWE-295" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 2, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:49838", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/security/cve/CVE-2026-32281", "https://bugzilla.redhat.com/2456333", "https://bugzilla.redhat.com/2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-49838.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/758061", "https://go.dev/issue/78281", "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", "https://linux.oracle.com/cve/CVE-2026-32281.html", "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", "https://pkg.go.dev/vuln/GO-2026-4946", "https://www.cve.org/CVERecord?id=CVE-2026-32281" ], "PublishedDate": "2026-04-08T02:16:03.35Z", "LastModifiedDate": "2026-07-25T10:10:00.167Z" }, { "VulnerabilityID": "CVE-2026-32283", "VendorIDs": [ "GO-2026-4870" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.9, 1.26.2", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:965802bb9463307b15770c73fae0a2f95f237afbd1db40c33004e4bc4f732115", "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", "Severity": "HIGH", "CweIDs": [ "CWE-770", "CWE-764" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:10217", "https://access.redhat.com/errata/RHSA-2026:10219", "https://access.redhat.com/errata/RHSA-2026:10704", "https://access.redhat.com/errata/RHSA-2026:11507", "https://access.redhat.com/errata/RHSA-2026:11514", "https://access.redhat.com/errata/RHSA-2026:11704", "https://access.redhat.com/errata/RHSA-2026:11711", "https://access.redhat.com/errata/RHSA-2026:11712", "https://access.redhat.com/errata/RHSA-2026:11863", "https://access.redhat.com/errata/RHSA-2026:11881", "https://access.redhat.com/errata/RHSA-2026:14162", "https://access.redhat.com/errata/RHSA-2026:14200", "https://access.redhat.com/errata/RHSA-2026:14391", "https://access.redhat.com/errata/RHSA-2026:15980", "https://access.redhat.com/errata/RHSA-2026:16021", "https://access.redhat.com/errata/RHSA-2026:16024", "https://access.redhat.com/errata/RHSA-2026:16101", "https://access.redhat.com/errata/RHSA-2026:16102", "https://access.redhat.com/errata/RHSA-2026:16875", "https://access.redhat.com/errata/RHSA-2026:17075", "https://access.redhat.com/errata/RHSA-2026:17084", "https://access.redhat.com/errata/RHSA-2026:17287", "https://access.redhat.com/errata/RHSA-2026:18027", "https://access.redhat.com/errata/RHSA-2026:18032", "https://access.redhat.com/errata/RHSA-2026:19126", "https://access.redhat.com/errata/RHSA-2026:19132", "https://access.redhat.com/errata/RHSA-2026:19133", "https://access.redhat.com/errata/RHSA-2026:19134", "https://access.redhat.com/errata/RHSA-2026:19135", "https://access.redhat.com/errata/RHSA-2026:19136", "https://access.redhat.com/errata/RHSA-2026:19137", "https://access.redhat.com/errata/RHSA-2026:19139", "https://access.redhat.com/errata/RHSA-2026:19144", "https://access.redhat.com/errata/RHSA-2026:19156", "https://access.redhat.com/errata/RHSA-2026:19350", "https://access.redhat.com/errata/RHSA-2026:19351", "https://access.redhat.com/errata/RHSA-2026:19352", "https://access.redhat.com/errata/RHSA-2026:19353", "https://access.redhat.com/errata/RHSA-2026:19369", "https://access.redhat.com/errata/RHSA-2026:19450", "https://access.redhat.com/errata/RHSA-2026:19550", "https://access.redhat.com/errata/RHSA-2026:19634", "https://access.redhat.com/errata/RHSA-2026:19714", "https://access.redhat.com/errata/RHSA-2026:19715", "https://access.redhat.com/errata/RHSA-2026:19719", "https://access.redhat.com/errata/RHSA-2026:19720", "https://access.redhat.com/errata/RHSA-2026:19721", "https://access.redhat.com/errata/RHSA-2026:19722", "https://access.redhat.com/errata/RHSA-2026:19750", "https://access.redhat.com/errata/RHSA-2026:19839", "https://access.redhat.com/errata/RHSA-2026:20556", "https://access.redhat.com/errata/RHSA-2026:20569", "https://access.redhat.com/errata/RHSA-2026:20570", "https://access.redhat.com/errata/RHSA-2026:20571", "https://access.redhat.com/errata/RHSA-2026:20607", "https://access.redhat.com/errata/RHSA-2026:20608", "https://access.redhat.com/errata/RHSA-2026:20609", "https://access.redhat.com/errata/RHSA-2026:21769", "https://access.redhat.com/errata/RHSA-2026:22347", "https://access.redhat.com/errata/RHSA-2026:22423", "https://access.redhat.com/errata/RHSA-2026:22450", "https://access.redhat.com/errata/RHSA-2026:22485", "https://access.redhat.com/errata/RHSA-2026:22709", "https://access.redhat.com/errata/RHSA-2026:22713", "https://access.redhat.com/errata/RHSA-2026:22714", "https://access.redhat.com/errata/RHSA-2026:22937", "https://access.redhat.com/errata/RHSA-2026:23102", "https://access.redhat.com/errata/RHSA-2026:23103", "https://access.redhat.com/errata/RHSA-2026:23228", "https://access.redhat.com/errata/RHSA-2026:23345", "https://access.redhat.com/errata/RHSA-2026:24337", "https://access.redhat.com/errata/RHSA-2026:24470", "https://access.redhat.com/errata/RHSA-2026:24761", "https://access.redhat.com/errata/RHSA-2026:24762", "https://access.redhat.com/errata/RHSA-2026:25248", "https://access.redhat.com/errata/RHSA-2026:25250", "https://access.redhat.com/errata/RHSA-2026:25251", "https://access.redhat.com/errata/RHSA-2026:25252", "https://access.redhat.com/errata/RHSA-2026:26447", "https://access.redhat.com/errata/RHSA-2026:26571", "https://access.redhat.com/errata/RHSA-2026:26636", "https://access.redhat.com/errata/RHSA-2026:27076", "https://access.redhat.com/errata/RHSA-2026:28038", "https://access.redhat.com/errata/RHSA-2026:28047", "https://access.redhat.com/errata/RHSA-2026:28074", "https://access.redhat.com/errata/RHSA-2026:29035", "https://access.redhat.com/errata/RHSA-2026:29195", "https://access.redhat.com/errata/RHSA-2026:29455", "https://access.redhat.com/errata/RHSA-2026:29703", "https://access.redhat.com/errata/RHSA-2026:33722", "https://access.redhat.com/errata/RHSA-2026:34192", "https://access.redhat.com/errata/RHSA-2026:34196", "https://access.redhat.com/errata/RHSA-2026:34197", "https://access.redhat.com/errata/RHSA-2026:34365", "https://access.redhat.com/errata/RHSA-2026:36796", "https://access.redhat.com/errata/RHSA-2026:39810", "https://access.redhat.com/errata/RHSA-2026:41019", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:47712", "https://access.redhat.com/errata/RHSA-2026:47714", "https://access.redhat.com/errata/RHSA-2026:47716", "https://access.redhat.com/errata/RHSA-2026:47719", "https://access.redhat.com/errata/RHSA-2026:47721", "https://access.redhat.com/errata/RHSA-2026:47722", "https://access.redhat.com/errata/RHSA-2026:47910", "https://access.redhat.com/errata/RHSA-2026:48036", "https://access.redhat.com/errata/RHSA-2026:48790", "https://access.redhat.com/errata/RHSA-2026:49509", "https://access.redhat.com/errata/RHSA-2026:49600", "https://access.redhat.com/errata/RHSA-2026:49944", "https://access.redhat.com/errata/RHSA-2026:51288", "https://access.redhat.com/errata/RHSA-2026:54191", "https://access.redhat.com/errata/RHSA-2026:54435", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:55898", "https://access.redhat.com/errata/RHSA-2026:55900", "https://access.redhat.com/errata/RHSA-2026:55901", "https://access.redhat.com/errata/RHSA-2026:55902", "https://access.redhat.com/errata/RHSA-2026:55903", "https://access.redhat.com/errata/RHSA-2026:56910", "https://access.redhat.com/errata/RHSA-2026:57409", "https://access.redhat.com/errata/RHSA-2026:57801", "https://access.redhat.com/errata/RHSA-2026:57802", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:65126", "https://access.redhat.com/errata/RHSA-2026:65343", "https://access.redhat.com/errata/RHSA-2026:65514", "https://access.redhat.com/errata/RHSA-2026:66022", "https://access.redhat.com/errata/RHSA-2026:66084", "https://access.redhat.com/errata/RHSA-2026:66401", "https://access.redhat.com/errata/RHSA-2026:66523", "https://access.redhat.com/errata/RHSA-2026:7291", "https://access.redhat.com/errata/RHSA-2026:7385", "https://access.redhat.com/security/cve/CVE-2026-32283", "https://bugzilla.redhat.com/2445356", "https://bugzilla.redhat.com/2456333", "https://bugzilla.redhat.com/2456338", "https://bugzilla.redhat.com/2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", "https://errata.almalinux.org/9/ALSA-2026-29703.html", "https://errata.rockylinux.org/RLSA-2026:29703", "https://go.dev/cl/763767", "https://go.dev/issue/78334", "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", "https://linux.oracle.com/cve/CVE-2026-32283.html", "https://linux.oracle.com/errata/ELSA-2026-48790.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", "https://pkg.go.dev/vuln/GO-2026-4870", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", "https://www.cve.org/CVERecord?id=CVE-2026-32283" ], "PublishedDate": "2026-04-08T02:16:03.58Z", "LastModifiedDate": "2026-09-11T13:17:28.143Z" }, { "VulnerabilityID": "CVE-2026-33811", "VendorIDs": [ "GO-2026-4981" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.10, 1.26.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:004312b4e1707e898ddf8ceb2af30341987542cfd2599ecdf4ee230992ae6179", "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", "Severity": "HIGH", "CweIDs": [ "CWE-415", "CWE-1341" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:22112", "https://access.redhat.com/errata/RHSA-2026:22120", "https://access.redhat.com/errata/RHSA-2026:22121", "https://access.redhat.com/errata/RHSA-2026:23262", "https://access.redhat.com/errata/RHSA-2026:23264", "https://access.redhat.com/errata/RHSA-2026:33120", "https://access.redhat.com/errata/RHSA-2026:33123", "https://access.redhat.com/errata/RHSA-2026:33142", "https://access.redhat.com/errata/RHSA-2026:33150", "https://access.redhat.com/errata/RHSA-2026:33574", "https://access.redhat.com/errata/RHSA-2026:34357", "https://access.redhat.com/errata/RHSA-2026:34359", "https://access.redhat.com/errata/RHSA-2026:34364", "https://access.redhat.com/errata/RHSA-2026:35832", "https://access.redhat.com/errata/RHSA-2026:35993", "https://access.redhat.com/errata/RHSA-2026:35994", "https://access.redhat.com/errata/RHSA-2026:35995", "https://access.redhat.com/errata/RHSA-2026:36207", "https://access.redhat.com/errata/RHSA-2026:36319", "https://access.redhat.com/errata/RHSA-2026:36617", "https://access.redhat.com/errata/RHSA-2026:36625", "https://access.redhat.com/errata/RHSA-2026:36648", "https://access.redhat.com/errata/RHSA-2026:36651", "https://access.redhat.com/errata/RHSA-2026:36776", "https://access.redhat.com/errata/RHSA-2026:36796", "https://access.redhat.com/errata/RHSA-2026:36797", "https://access.redhat.com/errata/RHSA-2026:38504", "https://access.redhat.com/errata/RHSA-2026:39266", "https://access.redhat.com/errata/RHSA-2026:39272", "https://access.redhat.com/errata/RHSA-2026:39319", "https://access.redhat.com/errata/RHSA-2026:39573", "https://access.redhat.com/errata/RHSA-2026:39810", "https://access.redhat.com/errata/RHSA-2026:40118", "https://access.redhat.com/errata/RHSA-2026:40119", "https://access.redhat.com/errata/RHSA-2026:40945", "https://access.redhat.com/errata/RHSA-2026:41019", "https://access.redhat.com/errata/RHSA-2026:41030", "https://access.redhat.com/errata/RHSA-2026:41055", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:42043", "https://access.redhat.com/errata/RHSA-2026:42047", "https://access.redhat.com/errata/RHSA-2026:42048", "https://access.redhat.com/errata/RHSA-2026:42049", "https://access.redhat.com/errata/RHSA-2026:42050", "https://access.redhat.com/errata/RHSA-2026:42051", "https://access.redhat.com/errata/RHSA-2026:42078", "https://access.redhat.com/errata/RHSA-2026:42079", "https://access.redhat.com/errata/RHSA-2026:42082", "https://access.redhat.com/errata/RHSA-2026:42132", "https://access.redhat.com/errata/RHSA-2026:42150", "https://access.redhat.com/errata/RHSA-2026:42151", "https://access.redhat.com/errata/RHSA-2026:42240", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:42852", "https://access.redhat.com/errata/RHSA-2026:42946", "https://access.redhat.com/errata/RHSA-2026:43038", "https://access.redhat.com/errata/RHSA-2026:43692", "https://access.redhat.com/errata/RHSA-2026:44622", "https://access.redhat.com/errata/RHSA-2026:46885", "https://access.redhat.com/errata/RHSA-2026:47149", "https://access.redhat.com/errata/RHSA-2026:47735", "https://access.redhat.com/errata/RHSA-2026:47952", "https://access.redhat.com/errata/RHSA-2026:48151", "https://access.redhat.com/errata/RHSA-2026:49702", "https://access.redhat.com/errata/RHSA-2026:49703", "https://access.redhat.com/errata/RHSA-2026:49712", "https://access.redhat.com/errata/RHSA-2026:50205", "https://access.redhat.com/errata/RHSA-2026:50300", "https://access.redhat.com/errata/RHSA-2026:50319", "https://access.redhat.com/errata/RHSA-2026:50336", "https://access.redhat.com/errata/RHSA-2026:50843", "https://access.redhat.com/errata/RHSA-2026:51033", "https://access.redhat.com/errata/RHSA-2026:51057", "https://access.redhat.com/errata/RHSA-2026:51187", "https://access.redhat.com/errata/RHSA-2026:51194", "https://access.redhat.com/errata/RHSA-2026:51341", "https://access.redhat.com/errata/RHSA-2026:53412", "https://access.redhat.com/errata/RHSA-2026:53413", "https://access.redhat.com/errata/RHSA-2026:53415", "https://access.redhat.com/errata/RHSA-2026:53530", "https://access.redhat.com/errata/RHSA-2026:54168", "https://access.redhat.com/errata/RHSA-2026:54191", "https://access.redhat.com/errata/RHSA-2026:54274", "https://access.redhat.com/errata/RHSA-2026:54283", "https://access.redhat.com/errata/RHSA-2026:54284", "https://access.redhat.com/errata/RHSA-2026:54285", "https://access.redhat.com/errata/RHSA-2026:54286", "https://access.redhat.com/errata/RHSA-2026:54287", "https://access.redhat.com/errata/RHSA-2026:54435", "https://access.redhat.com/errata/RHSA-2026:54441", "https://access.redhat.com/errata/RHSA-2026:54500", "https://access.redhat.com/errata/RHSA-2026:54552", "https://access.redhat.com/errata/RHSA-2026:54556", "https://access.redhat.com/errata/RHSA-2026:54584", "https://access.redhat.com/errata/RHSA-2026:54602", "https://access.redhat.com/errata/RHSA-2026:54603", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:56340", "https://access.redhat.com/errata/RHSA-2026:56785", "https://access.redhat.com/errata/RHSA-2026:56789", "https://access.redhat.com/errata/RHSA-2026:56790", "https://access.redhat.com/errata/RHSA-2026:56852", "https://access.redhat.com/errata/RHSA-2026:56855", "https://access.redhat.com/errata/RHSA-2026:56910", "https://access.redhat.com/errata/RHSA-2026:56912", "https://access.redhat.com/errata/RHSA-2026:56913", "https://access.redhat.com/errata/RHSA-2026:57191", "https://access.redhat.com/errata/RHSA-2026:57194", "https://access.redhat.com/errata/RHSA-2026:57482", "https://access.redhat.com/errata/RHSA-2026:57488", "https://access.redhat.com/errata/RHSA-2026:57649", "https://access.redhat.com/errata/RHSA-2026:59467", "https://access.redhat.com/errata/RHSA-2026:59559", "https://access.redhat.com/errata/RHSA-2026:60018", "https://access.redhat.com/errata/RHSA-2026:60025", "https://access.redhat.com/errata/RHSA-2026:60302", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:61253", "https://access.redhat.com/errata/RHSA-2026:61313", "https://access.redhat.com/errata/RHSA-2026:65126", "https://access.redhat.com/errata/RHSA-2026:65534", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/errata/RHSA-2026:66022", "https://access.redhat.com/security/cve/CVE-2026-33811", "https://bugzilla.redhat.com/2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-39319.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/767860", "https://go.dev/issue/78803", "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", "https://linux.oracle.com/cve/CVE-2026-33811.html", "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", "https://pkg.go.dev/vuln/GO-2026-4981", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", "https://www.cve.org/CVERecord?id=CVE-2026-33811" ], "PublishedDate": "2026-05-07T20:16:42.77Z", "LastModifiedDate": "2026-09-11T13:17:36.897Z" }, { "VulnerabilityID": "CVE-2026-33814", "VendorIDs": [ "GO-2026-4918" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.10, 1.26.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:4a7b8118d6015a5713995ff44a1b2afc1358fbdf564b3deb943a8be585211fe2", "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", "Severity": "HIGH", "CweIDs": [ "CWE-835", "CWE-606" ], "VendorSeverity": { "amazon": 3, "azure": 2, "bitnami": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:22112", "https://access.redhat.com/errata/RHSA-2026:22120", "https://access.redhat.com/errata/RHSA-2026:22121", "https://access.redhat.com/errata/RHSA-2026:23262", "https://access.redhat.com/errata/RHSA-2026:23264", "https://access.redhat.com/errata/RHSA-2026:33120", "https://access.redhat.com/errata/RHSA-2026:33123", "https://access.redhat.com/errata/RHSA-2026:33142", "https://access.redhat.com/errata/RHSA-2026:33150", "https://access.redhat.com/errata/RHSA-2026:34342", "https://access.redhat.com/errata/RHSA-2026:37387", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:43692", "https://access.redhat.com/errata/RHSA-2026:49702", "https://access.redhat.com/errata/RHSA-2026:49712", "https://access.redhat.com/errata/RHSA-2026:50205", "https://access.redhat.com/errata/RHSA-2026:54274", "https://access.redhat.com/errata/RHSA-2026:54283", "https://access.redhat.com/errata/RHSA-2026:54284", "https://access.redhat.com/errata/RHSA-2026:54285", "https://access.redhat.com/errata/RHSA-2026:54286", "https://access.redhat.com/errata/RHSA-2026:54287", "https://access.redhat.com/errata/RHSA-2026:56854", "https://access.redhat.com/errata/RHSA-2026:56912", "https://access.redhat.com/errata/RHSA-2026:57191", "https://access.redhat.com/errata/RHSA-2026:57194", "https://access.redhat.com/errata/RHSA-2026:57365", "https://access.redhat.com/errata/RHSA-2026:57367", "https://access.redhat.com/errata/RHSA-2026:57408", "https://access.redhat.com/errata/RHSA-2026:57545", "https://access.redhat.com/errata/RHSA-2026:57649", "https://access.redhat.com/errata/RHSA-2026:57845", "https://access.redhat.com/errata/RHSA-2026:59833", "https://access.redhat.com/errata/RHSA-2026:60023", "https://access.redhat.com/errata/RHSA-2026:60025", "https://access.redhat.com/errata/RHSA-2026:60441", "https://access.redhat.com/errata/RHSA-2026:60442", "https://access.redhat.com/errata/RHSA-2026:60446", "https://access.redhat.com/errata/RHSA-2026:60447", "https://access.redhat.com/errata/RHSA-2026:60454", "https://access.redhat.com/errata/RHSA-2026:60477", "https://access.redhat.com/errata/RHSA-2026:60478", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:60668", "https://access.redhat.com/errata/RHSA-2026:61253", "https://access.redhat.com/errata/RHSA-2026:62550", "https://access.redhat.com/errata/RHSA-2026:62551", "https://access.redhat.com/errata/RHSA-2026:63046", "https://access.redhat.com/errata/RHSA-2026:63047", "https://access.redhat.com/errata/RHSA-2026:63048", "https://access.redhat.com/errata/RHSA-2026:63050", "https://access.redhat.com/errata/RHSA-2026:63091", "https://access.redhat.com/errata/RHSA-2026:63096", "https://access.redhat.com/errata/RHSA-2026:63097", "https://access.redhat.com/errata/RHSA-2026:63103", "https://access.redhat.com/errata/RHSA-2026:63104", "https://access.redhat.com/errata/RHSA-2026:63636", "https://access.redhat.com/errata/RHSA-2026:63637", "https://access.redhat.com/errata/RHSA-2026:63639", "https://access.redhat.com/errata/RHSA-2026:65126", "https://access.redhat.com/security/cve/CVE-2026-33814", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", "https://errata.rockylinux.org/RLSA-2026:22121", "https://github.com/golang/go/issues/78476", "https://go-review.googlesource.com/c/go/+/761581", "https://go-review.googlesource.com/c/net/+/761640", "https://go.dev/cl/761581", "https://go.dev/cl/761640", "https://go.dev/issue/78476", "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", "https://linux.oracle.com/cve/CVE-2026-33814.html", "https://linux.oracle.com/errata/ELSA-2026-22121.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", "https://pkg.go.dev/vuln/GO-2026-4918", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", "https://ubuntu.com/security/notices/USN-8430-1", "https://ubuntu.com/security/notices/USN-8471-1", "https://ubuntu.com/security/notices/USN-8472-1", "https://ubuntu.com/security/notices/USN-8473-1", "https://www.cve.org/CVERecord?id=CVE-2026-33814" ], "PublishedDate": "2026-05-07T20:16:42.88Z", "LastModifiedDate": "2026-09-10T13:18:21.31Z" }, { "VulnerabilityID": "CVE-2026-33818", "VendorIDs": [ "GO-2026-5972" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:21423acbb2f332d0c0700e765ddce51b45aa9858321f74ef03a70715096882c2", "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", "Severity": "HIGH", "CweIDs": [ "CWE-400" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:66364", "https://access.redhat.com/security/cve/CVE-2026-33818", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-66364.html", "https://errata.rockylinux.org/RLSA-2026:66364", "https://go.dev/cl/814980", "https://go.dev/issue/80405", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://linux.oracle.com/cve/CVE-2026-33818.html", "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", "https://pkg.go.dev/vuln/GO-2026-5972", "https://www.cve.org/CVERecord?id=CVE-2026-33818" ], "PublishedDate": "2026-08-13T22:17:19.84Z", "LastModifiedDate": "2026-09-03T16:37:52.17Z" }, { "VulnerabilityID": "CVE-2026-39820", "VendorIDs": [ "GO-2026-4986" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.10, 1.26.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:b9afbb8ba13f7400e14d3ffe6f645c0ae91f9935214373052359edeb17762135", "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", "Severity": "HIGH", "CweIDs": [ "CWE-770", "CWE-606" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:22112", "https://access.redhat.com/errata/RHSA-2026:22120", "https://access.redhat.com/errata/RHSA-2026:22121", "https://access.redhat.com/errata/RHSA-2026:23262", "https://access.redhat.com/errata/RHSA-2026:23264", "https://access.redhat.com/errata/RHSA-2026:33120", "https://access.redhat.com/errata/RHSA-2026:33123", "https://access.redhat.com/errata/RHSA-2026:33142", "https://access.redhat.com/errata/RHSA-2026:33150", "https://access.redhat.com/errata/RHSA-2026:33574", "https://access.redhat.com/errata/RHSA-2026:34364", "https://access.redhat.com/errata/RHSA-2026:36319", "https://access.redhat.com/errata/RHSA-2026:36625", "https://access.redhat.com/errata/RHSA-2026:36754", "https://access.redhat.com/errata/RHSA-2026:36797", "https://access.redhat.com/errata/RHSA-2026:40262", "https://access.redhat.com/errata/RHSA-2026:41031", "https://access.redhat.com/errata/RHSA-2026:41066", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:42146", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:42796", "https://access.redhat.com/errata/RHSA-2026:43038", "https://access.redhat.com/errata/RHSA-2026:43052", "https://access.redhat.com/errata/RHSA-2026:43692", "https://access.redhat.com/errata/RHSA-2026:47952", "https://access.redhat.com/errata/RHSA-2026:49702", "https://access.redhat.com/errata/RHSA-2026:49712", "https://access.redhat.com/errata/RHSA-2026:50205", "https://access.redhat.com/errata/RHSA-2026:50300", "https://access.redhat.com/errata/RHSA-2026:50843", "https://access.redhat.com/errata/RHSA-2026:51033", "https://access.redhat.com/errata/RHSA-2026:51112", "https://access.redhat.com/errata/RHSA-2026:54274", "https://access.redhat.com/errata/RHSA-2026:54283", "https://access.redhat.com/errata/RHSA-2026:54284", "https://access.redhat.com/errata/RHSA-2026:54285", "https://access.redhat.com/errata/RHSA-2026:54286", "https://access.redhat.com/errata/RHSA-2026:54287", "https://access.redhat.com/errata/RHSA-2026:54531", "https://access.redhat.com/errata/RHSA-2026:54552", "https://access.redhat.com/errata/RHSA-2026:54555", "https://access.redhat.com/errata/RHSA-2026:54583", "https://access.redhat.com/errata/RHSA-2026:54602", "https://access.redhat.com/errata/RHSA-2026:54883", "https://access.redhat.com/errata/RHSA-2026:56340", "https://access.redhat.com/errata/RHSA-2026:56789", "https://access.redhat.com/errata/RHSA-2026:56852", "https://access.redhat.com/errata/RHSA-2026:56854", "https://access.redhat.com/errata/RHSA-2026:57194", "https://access.redhat.com/errata/RHSA-2026:57401", "https://access.redhat.com/errata/RHSA-2026:57482", "https://access.redhat.com/errata/RHSA-2026:57487", "https://access.redhat.com/errata/RHSA-2026:57649", "https://access.redhat.com/errata/RHSA-2026:57845", "https://access.redhat.com/errata/RHSA-2026:57914", "https://access.redhat.com/errata/RHSA-2026:59467", "https://access.redhat.com/errata/RHSA-2026:59830", "https://access.redhat.com/errata/RHSA-2026:59833", "https://access.redhat.com/errata/RHSA-2026:60018", "https://access.redhat.com/errata/RHSA-2026:60023", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:61253", "https://access.redhat.com/errata/RHSA-2026:62260", "https://access.redhat.com/errata/RHSA-2026:62406", "https://access.redhat.com/errata/RHSA-2026:62407", "https://access.redhat.com/errata/RHSA-2026:62753", "https://access.redhat.com/errata/RHSA-2026:62754", "https://access.redhat.com/errata/RHSA-2026:62803", "https://access.redhat.com/errata/RHSA-2026:63022", "https://access.redhat.com/errata/RHSA-2026:65116", "https://access.redhat.com/errata/RHSA-2026:65117", "https://access.redhat.com/errata/RHSA-2026:65153", "https://access.redhat.com/errata/RHSA-2026:65335", "https://access.redhat.com/errata/RHSA-2026:65336", "https://access.redhat.com/errata/RHSA-2026:65534", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/errata/RHSA-2026:65895", "https://access.redhat.com/errata/RHSA-2026:66016", "https://access.redhat.com/errata/RHSA-2026:66022", "https://access.redhat.com/errata/RHSA-2026:66327", "https://access.redhat.com/security/cve/CVE-2026-39820", "https://bugzilla.redhat.com/2467809", "https://bugzilla.redhat.com/2467820", "https://bugzilla.redhat.com/2484204", "https://bugzilla.redhat.com/2484830", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515827", "https://bugzilla.redhat.com/2515838", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/2515840", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-65117.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/759940", "https://go.dev/issue/78566", "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", "https://linux.oracle.com/cve/CVE-2026-39820.html", "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", "https://pkg.go.dev/vuln/GO-2026-4986", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", "https://www.cve.org/CVERecord?id=CVE-2026-39820" ], "PublishedDate": "2026-05-07T20:16:43.187Z", "LastModifiedDate": "2026-09-11T13:17:48.093Z" }, { "VulnerabilityID": "CVE-2026-39821", "VendorIDs": [ "GO-2026-5026" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:2be5ddbedd46473bb90605212e4e00a96dce84ee4d0bdf8f0d9667f60eba259e", "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", "Severity": "HIGH", "CweIDs": [ "CWE-1289" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 4, "oracle-oval": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", "V3Score": 8.2 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:23262", "https://access.redhat.com/errata/RHSA-2026:23264", "https://access.redhat.com/errata/RHSA-2026:26546", "https://access.redhat.com/errata/RHSA-2026:26547", "https://access.redhat.com/errata/RHSA-2026:30650", "https://access.redhat.com/errata/RHSA-2026:30651", "https://access.redhat.com/errata/RHSA-2026:30853", "https://access.redhat.com/errata/RHSA-2026:30854", "https://access.redhat.com/errata/RHSA-2026:30855", "https://access.redhat.com/errata/RHSA-2026:33155", "https://access.redhat.com/errata/RHSA-2026:33160", "https://access.redhat.com/errata/RHSA-2026:33163", "https://access.redhat.com/errata/RHSA-2026:33173", "https://access.redhat.com/errata/RHSA-2026:33183", "https://access.redhat.com/errata/RHSA-2026:33524", "https://access.redhat.com/errata/RHSA-2026:33531", "https://access.redhat.com/errata/RHSA-2026:34342", "https://access.redhat.com/errata/RHSA-2026:34357", "https://access.redhat.com/errata/RHSA-2026:34359", "https://access.redhat.com/errata/RHSA-2026:34364", "https://access.redhat.com/errata/RHSA-2026:34789", "https://access.redhat.com/errata/RHSA-2026:35826", "https://access.redhat.com/errata/RHSA-2026:35827", "https://access.redhat.com/errata/RHSA-2026:35828", "https://access.redhat.com/errata/RHSA-2026:35829", "https://access.redhat.com/errata/RHSA-2026:35830", "https://access.redhat.com/errata/RHSA-2026:35831", "https://access.redhat.com/errata/RHSA-2026:35993", "https://access.redhat.com/errata/RHSA-2026:35994", "https://access.redhat.com/errata/RHSA-2026:36105", "https://access.redhat.com/errata/RHSA-2026:36167", "https://access.redhat.com/errata/RHSA-2026:36207", "https://access.redhat.com/errata/RHSA-2026:36648", "https://access.redhat.com/errata/RHSA-2026:36651", "https://access.redhat.com/errata/RHSA-2026:36796", "https://access.redhat.com/errata/RHSA-2026:36797", "https://access.redhat.com/errata/RHSA-2026:36808", "https://access.redhat.com/errata/RHSA-2026:36820", "https://access.redhat.com/errata/RHSA-2026:36883", "https://access.redhat.com/errata/RHSA-2026:37387", "https://access.redhat.com/errata/RHSA-2026:37435", "https://access.redhat.com/errata/RHSA-2026:37436", "https://access.redhat.com/errata/RHSA-2026:38995", "https://access.redhat.com/errata/RHSA-2026:39005", "https://access.redhat.com/errata/RHSA-2026:39573", "https://access.redhat.com/errata/RHSA-2026:39879", "https://access.redhat.com/errata/RHSA-2026:40118", "https://access.redhat.com/errata/RHSA-2026:40262", "https://access.redhat.com/errata/RHSA-2026:40945", "https://access.redhat.com/errata/RHSA-2026:41019", "https://access.redhat.com/errata/RHSA-2026:41030", "https://access.redhat.com/errata/RHSA-2026:41031", "https://access.redhat.com/errata/RHSA-2026:41036", "https://access.redhat.com/errata/RHSA-2026:41055", "https://access.redhat.com/errata/RHSA-2026:41066", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:41930", "https://access.redhat.com/errata/RHSA-2026:42043", "https://access.redhat.com/errata/RHSA-2026:42047", "https://access.redhat.com/errata/RHSA-2026:42048", "https://access.redhat.com/errata/RHSA-2026:42049", "https://access.redhat.com/errata/RHSA-2026:42050", "https://access.redhat.com/errata/RHSA-2026:42051", "https://access.redhat.com/errata/RHSA-2026:42078", "https://access.redhat.com/errata/RHSA-2026:42079", "https://access.redhat.com/errata/RHSA-2026:42080", "https://access.redhat.com/errata/RHSA-2026:42082", "https://access.redhat.com/errata/RHSA-2026:42132", "https://access.redhat.com/errata/RHSA-2026:42142", "https://access.redhat.com/errata/RHSA-2026:42146", "https://access.redhat.com/errata/RHSA-2026:42150", "https://access.redhat.com/errata/RHSA-2026:42151", "https://access.redhat.com/errata/RHSA-2026:42240", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:42796", "https://access.redhat.com/errata/RHSA-2026:42852", "https://access.redhat.com/errata/RHSA-2026:43038", "https://access.redhat.com/errata/RHSA-2026:43052", "https://access.redhat.com/errata/RHSA-2026:43692", "https://access.redhat.com/errata/RHSA-2026:44622", "https://access.redhat.com/errata/RHSA-2026:44624", "https://access.redhat.com/errata/RHSA-2026:46395", "https://access.redhat.com/errata/RHSA-2026:47149", "https://access.redhat.com/errata/RHSA-2026:47735", "https://access.redhat.com/errata/RHSA-2026:47737", "https://access.redhat.com/errata/RHSA-2026:47952", "https://access.redhat.com/errata/RHSA-2026:49702", "https://access.redhat.com/errata/RHSA-2026:49712", "https://access.redhat.com/errata/RHSA-2026:50300", "https://access.redhat.com/errata/RHSA-2026:50843", "https://access.redhat.com/errata/RHSA-2026:51033", "https://access.redhat.com/errata/RHSA-2026:51112", "https://access.redhat.com/errata/RHSA-2026:51187", "https://access.redhat.com/errata/RHSA-2026:51194", "https://access.redhat.com/errata/RHSA-2026:51341", "https://access.redhat.com/errata/RHSA-2026:52826", "https://access.redhat.com/errata/RHSA-2026:53374", "https://access.redhat.com/errata/RHSA-2026:53412", "https://access.redhat.com/errata/RHSA-2026:53413", "https://access.redhat.com/errata/RHSA-2026:53415", "https://access.redhat.com/errata/RHSA-2026:53530", "https://access.redhat.com/errata/RHSA-2026:54191", "https://access.redhat.com/errata/RHSA-2026:54274", "https://access.redhat.com/errata/RHSA-2026:54283", "https://access.redhat.com/errata/RHSA-2026:54284", "https://access.redhat.com/errata/RHSA-2026:54285", "https://access.redhat.com/errata/RHSA-2026:54286", "https://access.redhat.com/errata/RHSA-2026:54287", "https://access.redhat.com/errata/RHSA-2026:54395", "https://access.redhat.com/errata/RHSA-2026:54401", "https://access.redhat.com/errata/RHSA-2026:54435", "https://access.redhat.com/errata/RHSA-2026:54441", "https://access.redhat.com/errata/RHSA-2026:54531", "https://access.redhat.com/errata/RHSA-2026:54580", "https://access.redhat.com/errata/RHSA-2026:54757", "https://access.redhat.com/errata/RHSA-2026:56143", "https://access.redhat.com/errata/RHSA-2026:56223", "https://access.redhat.com/errata/RHSA-2026:56340", "https://access.redhat.com/errata/RHSA-2026:56431", "https://access.redhat.com/errata/RHSA-2026:57194", "https://access.redhat.com/errata/RHSA-2026:57541", "https://access.redhat.com/errata/RHSA-2026:57649", "https://access.redhat.com/errata/RHSA-2026:57845", "https://access.redhat.com/errata/RHSA-2026:59546", "https://access.redhat.com/errata/RHSA-2026:59549", "https://access.redhat.com/errata/RHSA-2026:59562", "https://access.redhat.com/errata/RHSA-2026:60315", "https://access.redhat.com/errata/RHSA-2026:60354", "https://access.redhat.com/errata/RHSA-2026:60387", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:61245", "https://access.redhat.com/errata/RHSA-2026:61253", "https://access.redhat.com/errata/RHSA-2026:62549", "https://access.redhat.com/errata/RHSA-2026:63134", "https://access.redhat.com/errata/RHSA-2026:65126", "https://access.redhat.com/errata/RHSA-2026:65153", "https://access.redhat.com/errata/RHSA-2026:65359", "https://access.redhat.com/errata/RHSA-2026:65534", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/errata/RHSA-2026:66016", "https://access.redhat.com/errata/RHSA-2026:66022", "https://access.redhat.com/errata/RHSA-2026:66432", "https://access.redhat.com/security/cve/CVE-2026-39821", "https://bugzilla.redhat.com/2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-37435.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://github.com/golang/go/issues/78760", "https://go.dev/cl/767220", "https://go.dev/issue/78760", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", "https://linux.oracle.com/cve/CVE-2026-39821.html", "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", "https://pkg.go.dev/vuln/GO-2026-5026", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", "https://ubuntu.com/security/notices/USN-8416-1", "https://www.cve.org/CVERecord?id=CVE-2026-39821" ], "PublishedDate": "2026-05-22T16:16:20.41Z", "LastModifiedDate": "2026-09-11T13:17:49.237Z" }, { "VulnerabilityID": "CVE-2026-39822", "VendorIDs": [ "GO-2026-4970" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:096a5fae6ae18cedd89d345f861f0eafa0c46af7a8efc076cf6e3cb941ead50d", "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", "Severity": "HIGH", "CweIDs": [ "CWE-61" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:38878", "https://access.redhat.com/security/cve/CVE-2026-39822", "https://bugzilla.redhat.com/2498152", "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", "https://errata.almalinux.org/9/ALSA-2026-38878.html", "https://errata.rockylinux.org/RLSA-2026:38878", "https://go.dev/cl/797880", "https://go.dev/issue/79005", "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", "https://linux.oracle.com/cve/CVE-2026-39822.html", "https://linux.oracle.com/errata/ELSA-2026-38995.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", "https://pkg.go.dev/vuln/GO-2026-4970", "https://www.cve.org/CVERecord?id=CVE-2026-39822" ], "PublishedDate": "2026-07-08T17:17:21.31Z", "LastModifiedDate": "2026-07-13T14:54:26.317Z" }, { "VulnerabilityID": "CVE-2026-39836", "VendorIDs": [ "GO-2026-4971" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.10, 1.26.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:fcfd0f80d772511c98e49faad20a1959e8fbfb9032322c9708d6028df332b15d", "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "bitnami": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 2, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:22121", "https://access.redhat.com/security/cve/CVE-2026-39836", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", "https://errata.rockylinux.org/RLSA-2026:22121", "https://go.dev/cl/775320", "https://go.dev/issue/79006", "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", "https://linux.oracle.com/cve/CVE-2026-39836.html", "https://linux.oracle.com/errata/ELSA-2026-22121.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", "https://pkg.go.dev/vuln/GO-2026-4971", "https://www.cve.org/CVERecord?id=CVE-2026-39836" ], "PublishedDate": "2026-05-07T20:16:43.593Z", "LastModifiedDate": "2026-06-17T10:42:40.34Z" }, { "VulnerabilityID": "CVE-2026-42499", "VendorIDs": [ "GO-2026-4977" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.10, 1.26.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:3812f89a5d6b0b5adc7ee5bfb034243adb69a3555dbc4af3dc29136f788ab678", "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", "Severity": "HIGH", "CweIDs": [ "CWE-1046" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:17713", "https://access.redhat.com/errata/RHSA-2026:17714", "https://access.redhat.com/errata/RHSA-2026:22112", "https://access.redhat.com/errata/RHSA-2026:22120", "https://access.redhat.com/errata/RHSA-2026:22121", "https://access.redhat.com/errata/RHSA-2026:33120", "https://access.redhat.com/errata/RHSA-2026:33123", "https://access.redhat.com/errata/RHSA-2026:33142", "https://access.redhat.com/errata/RHSA-2026:33150", "https://access.redhat.com/errata/RHSA-2026:33574", "https://access.redhat.com/errata/RHSA-2026:34364", "https://access.redhat.com/errata/RHSA-2026:36319", "https://access.redhat.com/errata/RHSA-2026:36625", "https://access.redhat.com/errata/RHSA-2026:36754", "https://access.redhat.com/errata/RHSA-2026:36797", "https://access.redhat.com/errata/RHSA-2026:40262", "https://access.redhat.com/errata/RHSA-2026:41031", "https://access.redhat.com/errata/RHSA-2026:41066", "https://access.redhat.com/errata/RHSA-2026:41928", "https://access.redhat.com/errata/RHSA-2026:42146", "https://access.redhat.com/errata/RHSA-2026:42644", "https://access.redhat.com/errata/RHSA-2026:42796", "https://access.redhat.com/errata/RHSA-2026:43038", "https://access.redhat.com/errata/RHSA-2026:43052", "https://access.redhat.com/errata/RHSA-2026:43692", "https://access.redhat.com/errata/RHSA-2026:47952", "https://access.redhat.com/errata/RHSA-2026:49702", "https://access.redhat.com/errata/RHSA-2026:49712", "https://access.redhat.com/errata/RHSA-2026:50300", "https://access.redhat.com/errata/RHSA-2026:50843", "https://access.redhat.com/errata/RHSA-2026:51033", "https://access.redhat.com/errata/RHSA-2026:51112", "https://access.redhat.com/errata/RHSA-2026:54274", "https://access.redhat.com/errata/RHSA-2026:54283", "https://access.redhat.com/errata/RHSA-2026:54284", "https://access.redhat.com/errata/RHSA-2026:54285", "https://access.redhat.com/errata/RHSA-2026:54286", "https://access.redhat.com/errata/RHSA-2026:54287", "https://access.redhat.com/errata/RHSA-2026:54531", "https://access.redhat.com/errata/RHSA-2026:54552", "https://access.redhat.com/errata/RHSA-2026:54555", "https://access.redhat.com/errata/RHSA-2026:54583", "https://access.redhat.com/errata/RHSA-2026:54602", "https://access.redhat.com/errata/RHSA-2026:56340", "https://access.redhat.com/errata/RHSA-2026:56785", "https://access.redhat.com/errata/RHSA-2026:56789", "https://access.redhat.com/errata/RHSA-2026:56852", "https://access.redhat.com/errata/RHSA-2026:56854", "https://access.redhat.com/errata/RHSA-2026:56910", "https://access.redhat.com/errata/RHSA-2026:56912", "https://access.redhat.com/errata/RHSA-2026:57194", "https://access.redhat.com/errata/RHSA-2026:57482", "https://access.redhat.com/errata/RHSA-2026:57487", "https://access.redhat.com/errata/RHSA-2026:57649", "https://access.redhat.com/errata/RHSA-2026:57845", "https://access.redhat.com/errata/RHSA-2026:57914", "https://access.redhat.com/errata/RHSA-2026:59467", "https://access.redhat.com/errata/RHSA-2026:59830", "https://access.redhat.com/errata/RHSA-2026:59833", "https://access.redhat.com/errata/RHSA-2026:60018", "https://access.redhat.com/errata/RHSA-2026:60023", "https://access.redhat.com/errata/RHSA-2026:60520", "https://access.redhat.com/errata/RHSA-2026:61253", "https://access.redhat.com/errata/RHSA-2026:62260", "https://access.redhat.com/errata/RHSA-2026:62406", "https://access.redhat.com/errata/RHSA-2026:62407", "https://access.redhat.com/errata/RHSA-2026:62753", "https://access.redhat.com/errata/RHSA-2026:62754", "https://access.redhat.com/errata/RHSA-2026:62803", "https://access.redhat.com/errata/RHSA-2026:63022", "https://access.redhat.com/errata/RHSA-2026:63163", "https://access.redhat.com/errata/RHSA-2026:63332", "https://access.redhat.com/errata/RHSA-2026:63636", "https://access.redhat.com/errata/RHSA-2026:64818", "https://access.redhat.com/errata/RHSA-2026:65116", "https://access.redhat.com/errata/RHSA-2026:65117", "https://access.redhat.com/errata/RHSA-2026:65153", "https://access.redhat.com/errata/RHSA-2026:65335", "https://access.redhat.com/errata/RHSA-2026:65336", "https://access.redhat.com/errata/RHSA-2026:65534", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/errata/RHSA-2026:65895", "https://access.redhat.com/errata/RHSA-2026:66022", "https://access.redhat.com/errata/RHSA-2026:66327", "https://access.redhat.com/security/cve/CVE-2026-42499", "https://bugzilla.redhat.com/2467809", "https://bugzilla.redhat.com/2467820", "https://bugzilla.redhat.com/2484204", "https://bugzilla.redhat.com/2484830", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515827", "https://bugzilla.redhat.com/2515838", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/2515840", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-65117.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/771520", "https://go.dev/issue/78987", "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", "https://linux.oracle.com/cve/CVE-2026-42499.html", "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", "https://pkg.go.dev/vuln/GO-2026-4977", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", "https://www.cve.org/CVERecord?id=CVE-2026-42499" ], "PublishedDate": "2026-05-07T20:16:44.54Z", "LastModifiedDate": "2026-09-11T13:17:59.763Z" }, { "VulnerabilityID": "CVE-2026-42504", "VendorIDs": [ "GO-2026-5038" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.11, 1.26.4", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:95e006aded6bebd459634358fd77bd04c5f917ae94d9c7852dfd5b9d9d631771", "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", "Severity": "HIGH", "CweIDs": [ "CWE-407" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:65117", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/security/cve/CVE-2026-42504", "https://bugzilla.redhat.com/2467809", "https://bugzilla.redhat.com/2467820", "https://bugzilla.redhat.com/2484204", "https://bugzilla.redhat.com/2484830", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515827", "https://bugzilla.redhat.com/2515838", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/2515840", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-65117.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/774481", "https://go.dev/issue/79217", "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", "https://linux.oracle.com/cve/CVE-2026-42504.html", "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", "https://pkg.go.dev/vuln/GO-2026-5038", "https://www.cve.org/CVERecord?id=CVE-2026-42504" ], "PublishedDate": "2026-06-02T23:16:37.927Z", "LastModifiedDate": "2026-07-22T19:10:00.12Z" }, { "VulnerabilityID": "CVE-2026-56853", "VendorIDs": [ "GO-2026-6089" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:1202c86987b2c2564cd2da971d0ded8ba567117b0ba4c25358e3c9ac0f2c5168", "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:65117", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/security/cve/CVE-2026-56853", "https://bugzilla.redhat.com/2467809", "https://bugzilla.redhat.com/2467820", "https://bugzilla.redhat.com/2484204", "https://bugzilla.redhat.com/2484830", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515827", "https://bugzilla.redhat.com/2515838", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/2515840", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-65117.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/795540", "https://go.dev/issue/80205", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://linux.oracle.com/cve/CVE-2026-56853.html", "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", "https://pkg.go.dev/vuln/GO-2026-6089", "https://www.cve.org/CVERecord?id=CVE-2026-56853" ], "PublishedDate": "2026-08-13T22:17:22.093Z", "LastModifiedDate": "2026-09-03T16:37:52.17Z" }, { "VulnerabilityID": "CVE-2026-56858", "VendorIDs": [ "GO-2026-6091" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:bc535ab86cc107c694cd6971a6b23ba96728bd03585a8d23f526abfce22ff433", "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", "Severity": "HIGH", "CweIDs": [ "CWE-79" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 2, "oracle-oval": 3, "photon": 2, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "V3Score": 6.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:65117", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/security/cve/CVE-2026-56858", "https://bugzilla.redhat.com/2467809", "https://bugzilla.redhat.com/2467820", "https://bugzilla.redhat.com/2484204", "https://bugzilla.redhat.com/2484830", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515827", "https://bugzilla.redhat.com/2515838", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/2515840", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-65117.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/807100", "https://go.dev/issue/80435", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://linux.oracle.com/cve/CVE-2026-56858.html", "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", "https://pkg.go.dev/vuln/GO-2026-6091", "https://www.cve.org/CVERecord?id=CVE-2026-56858" ], "PublishedDate": "2026-08-13T22:17:22.207Z", "LastModifiedDate": "2026-09-03T16:37:52.17Z" }, { "VulnerabilityID": "CVE-2026-56859", "VendorIDs": [ "GO-2026-6088" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:ab62dc3557cb81326d275230a92ad6d0dea55e1c3efa0b4c054834941047dfed", "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:65117", "https://access.redhat.com/errata/RHSA-2026:65886", "https://access.redhat.com/security/cve/CVE-2026-56859", "https://bugzilla.redhat.com/2467809", "https://bugzilla.redhat.com/2467820", "https://bugzilla.redhat.com/2484204", "https://bugzilla.redhat.com/2484830", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515827", "https://bugzilla.redhat.com/2515838", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/2515840", "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-65117.html", "https://errata.rockylinux.org/RLSA-2026:65886", "https://go.dev/cl/803320", "https://go.dev/issue/80481", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://linux.oracle.com/cve/CVE-2026-56859.html", "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", "https://pkg.go.dev/vuln/GO-2026-6088", "https://www.cve.org/CVERecord?id=CVE-2026-56859" ], "PublishedDate": "2026-08-13T22:17:22.32Z", "LastModifiedDate": "2026-09-03T16:37:52.17Z" }, { "VulnerabilityID": "CVE-2026-56860", "VendorIDs": [ "GO-2026-6218" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:5d4edc047f09241e4bc2ddff96c80d1d0c26a3143a6496a32bab6d3c0845da66", "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", "Severity": "HIGH", "CweIDs": [ "CWE-407" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 2, "oracle-oval": 3, "photon": 2, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:66364", "https://access.redhat.com/security/cve/CVE-2026-56860", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-66364.html", "https://errata.rockylinux.org/RLSA-2026:66364", "https://go.dev/cl/803681", "https://go.dev/issue/80494", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://linux.oracle.com/cve/CVE-2026-56860.html", "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", "https://pkg.go.dev/vuln/GO-2026-6218", "https://www.cve.org/CVERecord?id=CVE-2026-56860" ], "PublishedDate": "2026-08-13T22:17:22.44Z", "LastModifiedDate": "2026-09-03T16:37:52.17Z" }, { "VulnerabilityID": "CVE-2026-56862", "VendorIDs": [ "GO-2026-6090" ], "PkgID": "stdlib@v1.24.6", "PkgName": "stdlib", "PkgIdentifier": { "PURL": "pkg:golang/stdlib@v1.24.6", "UID": "5a9b484fa87e1a00" }, "InstalledVersion": "v1.24.6", "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", "Status": "fixed", "Layer": { "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", "DataSource": { "ID": "govulndb", "Name": "The Go Vulnerability Database", "URL": "https://pkg.go.dev/vuln/" }, "Fingerprint": "sha256:0334074ecb18a8ca06b9e645342012eb7692b13a5b9f2e86505ce36d27fb1064", "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:66364", "https://access.redhat.com/security/cve/CVE-2026-56862", "https://bugzilla.redhat.com/2515815", "https://bugzilla.redhat.com/2515820", "https://bugzilla.redhat.com/2515839", "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", "https://errata.almalinux.org/9/ALSA-2026-66364.html", "https://errata.rockylinux.org/RLSA-2026:66364", "https://go.dev/cl/804261", "https://go.dev/issue/80528", "https://groups.google.com/g/golang-announce/c/94pEornpRlI", "https://linux.oracle.com/cve/CVE-2026-56862.html", "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", "https://pkg.go.dev/vuln/GO-2026-6090", "https://www.cve.org/CVERecord?id=CVE-2026-56862" ], "PublishedDate": "2026-08-13T22:17:22.55Z", "LastModifiedDate": "2026-09-03T16:37:52.17Z" } ] } ] }