{ "SchemaVersion": 2, "Trivy": { "Version": "0.74.0" }, "ReportID": "01a0a616-bfff-795c-abf3-86ee2da79ee6", "CreatedAt": "2026-09-15T17:21:43.935616815Z", "ArtifactID": "sha256:7e2ef2cf0963a6021bbb0428d17799b7e412657661833d57eaf85269698a2bee", "ArtifactName": "dtf-production-web:validation", "ArtifactType": "container_image", "Metadata": { "Size": 63693824, "OS": { "Family": "alpine", "Name": "3.23.3" }, "ImageID": "sha256:c1ae962ff4d0551b3c1629aa702c89b2ad98497d2c1c808bfcba74d6bffb7ec2", "DiffIDs": [ "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e", "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119", "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294", "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da", "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8", "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0", "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8", "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0", "sha256:4a37d6822c6d388b4e3399cf15c5bd0878c71d6ec14862edd0f778b1e75b4b62", "sha256:860dbfb02839b3b8496aae962b9fae057fd868bd09f0e6867230e80aca08260e", "sha256:aa2935217d14946c1ebf1ccb9e1ca43fca63c86d4fe6aed723f5b3ae997762c5" ], "RepoTags": [ "dtf-production-web:validation" ], "RepoDigests": [ "dtf-production-web@sha256:c1ae962ff4d0551b3c1629aa702c89b2ad98497d2c1c808bfcba74d6bffb7ec2" ], "Reference": "dtf-production-web:validation", "ImageConfig": { "architecture": "amd64", "created": "2026-09-15T14:09:15.680375581-03:00", "history": [ { "created": "2026-01-28T01:18:04Z", "created_by": "ADD alpine-minirootfs-3.23.3-x86_64.tar.gz / # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-01-28T01:18:04Z", "created_by": "CMD [\"/bin/sh\"]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:24Z", "created_by": "LABEL maintainer=NGINX Docker Maintainers \u003cdocker-maint@nginx.com\u003e", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:24Z", "created_by": "ENV NGINX_VERSION=1.28.3", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:24Z", "created_by": "ENV PKG_RELEASE=1", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:24Z", "created_by": "ENV DYNPKG_RELEASE=1", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:24Z", "created_by": "RUN /bin/sh -c set -x \u0026\u0026 addgroup -g 101 -S nginx \u0026\u0026 adduser -S -D -H -u 101 -h /var/cache/nginx -s /sbin/nologin -G nginx -g nginx nginx \u0026\u0026 apkArch=\"$(cat /etc/apk/arch)\" \u0026\u0026 nginxPackages=\" nginx=${NGINX_VERSION}-r${PKG_RELEASE} \" \u0026\u0026 apk add --no-cache --virtual .checksum-deps openssl \u0026\u0026 case \"$apkArch\" in x86_64|aarch64) set -x \u0026\u0026 KEY_SHA512=\"e09fa32f0a0eab2b879ccbbc4d0e4fb9751486eedda75e35fac65802cc9faa266425edf83e261137a2f4d16281ce2c1a5f4502930fe75154723da014214f0655\" \u0026\u0026 wget -O /tmp/nginx_signing.rsa.pub https://nginx.org/keys/nginx_signing.rsa.pub \u0026\u0026 if echo \"$KEY_SHA512 */tmp/nginx_signing.rsa.pub\" | sha512sum -c -; then echo \"key verification succeeded!\"; mv /tmp/nginx_signing.rsa.pub /etc/apk/keys/; else echo \"key verification failed!\"; exit 1; fi \u0026\u0026 DEPS=$(apk query --summarize depends --recursive --no-cache --repository \"@nginxorg https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" ${nginxPackages/=/@nginxorg=}) \u0026\u0026 apk add --no-cache $DEPS \u0026\u0026 apk add --repositories-file /dev/null -X \"https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" --no-cache $nginxPackages ;; *) set -x \u0026\u0026 tempDir=\"$(mktemp -d)\" \u0026\u0026 chown nobody:nobody $tempDir \u0026\u0026 apk add --no-cache --virtual .build-deps gcc libc-dev make openssl-dev pcre2-dev zlib-dev linux-headers bash alpine-sdk findutils curl \u0026\u0026 su nobody -s /bin/sh -c \" export HOME=${tempDir} \u0026\u0026 cd ${tempDir} \u0026\u0026 curl -f -L -O https://github.com/nginx/pkg-oss/archive/${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 PKGOSSCHECKSUM=\\\"866d10a1091f34b6bd9e7dcae69653323fa98511a2b75104b54d97ef71416b9b96f10510149d9e85aa582b21b3cb5e43ea9c2b8d8f7cf0079452e8bea2c10db4 *${NGINX_VERSION}-${PKG_RELEASE}.tar.gz\\\" \u0026\u0026 if [ \\\"\\$(openssl sha512 -r ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz)\\\" = \\\"\\$PKGOSSCHECKSUM\\\" ]; then echo \\\"pkg-oss tarball checksum verification succeeded!\\\"; else echo \\\"pkg-oss tarball checksum verification failed!\\\"; exit 1; fi \u0026\u0026 tar xzvf ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 cd pkg-oss-${NGINX_VERSION}-${PKG_RELEASE} \u0026\u0026 cd alpine \u0026\u0026 make base \u0026\u0026 apk index --allow-untrusted -o ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz ${tempDir}/packages/alpine/${apkArch}/*.apk \u0026\u0026 abuild-sign -k ${tempDir}/.abuild/abuild-key.rsa ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz \" \u0026\u0026 cp ${tempDir}/.abuild/abuild-key.rsa.pub /etc/apk/keys/ \u0026\u0026 apk del --no-network .build-deps \u0026\u0026 DEPS=$(apk query --summarize depends --recursive --no-cache --repository \"@nginxorg ${tempDir}/packages/alpine/\" ${nginxPackages/=/@nginxorg=}) \u0026\u0026 apk add --no-cache $DEPS \u0026\u0026 apk add --repositories-file /dev/null -X ${tempDir}/packages/alpine/ --no-cache $nginxPackages ;; esac \u0026\u0026 apk del --no-network .checksum-deps \u0026\u0026 if [ -n \"$tempDir\" ]; then rm -rf \"$tempDir\"; fi \u0026\u0026 if [ -f \"/etc/apk/keys/abuild-key.rsa.pub\" ]; then rm -f /etc/apk/keys/abuild-key.rsa.pub; fi \u0026\u0026 apk add --no-cache gettext-envsubst \u0026\u0026 apk add --no-cache tzdata \u0026\u0026 ln -sf /dev/stdout /var/log/nginx/access.log \u0026\u0026 ln -sf /dev/stderr /var/log/nginx/error.log \u0026\u0026 mkdir /docker-entrypoint.d # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-03-24T22:12:25Z", "created_by": "COPY docker-entrypoint.sh / # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-03-24T22:12:25Z", "created_by": "COPY 10-listen-on-ipv6-by-default.sh /docker-entrypoint.d # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-03-24T22:12:25Z", "created_by": "COPY 15-local-resolvers.envsh /docker-entrypoint.d # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-03-24T22:12:25Z", "created_by": "COPY 20-envsubst-on-templates.sh /docker-entrypoint.d # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-03-24T22:12:25Z", "created_by": "COPY 30-tune-worker-processes.sh /docker-entrypoint.d # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-03-24T22:12:25Z", "created_by": "ENTRYPOINT [\"/docker-entrypoint.sh\"]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:25Z", "created_by": "EXPOSE map[80/tcp:{}]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:25Z", "created_by": "STOPSIGNAL SIGQUIT", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T22:12:25Z", "created_by": "CMD [\"nginx\" \"-g\" \"daemon off;\"]", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T23:11:15Z", "created_by": "ENV NJS_VERSION=0.9.6", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T23:11:15Z", "created_by": "ENV NJS_RELEASE=1", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T23:11:15Z", "created_by": "ENV ACME_VERSION=0.3.1", "comment": "buildkit.dockerfile.v0", "empty_layer": true }, { "created": "2026-03-24T23:11:15Z", "created_by": "RUN /bin/sh -c set -x \u0026\u0026 apkArch=\"$(cat /etc/apk/arch)\" \u0026\u0026 nginxPackages=\" nginx=${NGINX_VERSION}-r${PKG_RELEASE} nginx-module-xslt=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-geoip=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-image-filter=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-njs=${NGINX_VERSION}.${NJS_VERSION}-r${NJS_RELEASE} nginx-module-acme=${NGINX_VERSION}.${ACME_VERSION}-r${PKG_RELEASE} \" \u0026\u0026 apk add --no-cache --virtual .checksum-deps openssl \u0026\u0026 case \"$apkArch\" in x86_64|aarch64) apk add -X \"https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" --no-cache $nginxPackages ;; *) set -x \u0026\u0026 tempDir=\"$(mktemp -d)\" \u0026\u0026 chown nobody:nobody $tempDir \u0026\u0026 apk add --no-cache --virtual .build-deps gcc libc-dev make openssl-dev pcre2-dev zlib-dev linux-headers libxslt-dev gd-dev geoip-dev libedit-dev bash alpine-sdk findutils curl cargo clang-libclang \u0026\u0026 su nobody -s /bin/sh -c \" export HOME=${tempDir} \u0026\u0026 cd ${tempDir} \u0026\u0026 curl -f -L -O https://github.com/nginx/pkg-oss/archive/${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 PKGOSSCHECKSUM=\\\"866d10a1091f34b6bd9e7dcae69653323fa98511a2b75104b54d97ef71416b9b96f10510149d9e85aa582b21b3cb5e43ea9c2b8d8f7cf0079452e8bea2c10db4 *${NGINX_VERSION}-${PKG_RELEASE}.tar.gz\\\" \u0026\u0026 if [ \\\"\\$(openssl sha512 -r ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz)\\\" = \\\"\\$PKGOSSCHECKSUM\\\" ]; then echo \\\"pkg-oss tarball checksum verification succeeded!\\\"; else echo \\\"pkg-oss tarball checksum verification failed!\\\"; exit 1; fi \u0026\u0026 tar xzvf ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 cd pkg-oss-${NGINX_VERSION}-${PKG_RELEASE} \u0026\u0026 cd alpine \u0026\u0026 export BUILDTARGET=\\\"module-geoip module-image-filter module-njs module-xslt module-acme\\\" \u0026\u0026 if [ \\\"\\$(apk --print-arch)\\\" = \\\"armhf\\\" ]; then BUILDTARGET=\\\"\\$( echo \\$BUILDTARGET | sed 's,module-acme,,' )\\\"; fi \u0026\u0026 make \\$BUILDTARGET \u0026\u0026 apk index --allow-untrusted -o ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz ${tempDir}/packages/alpine/${apkArch}/*.apk \u0026\u0026 abuild-sign -k ${tempDir}/.abuild/abuild-key.rsa ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz \" \u0026\u0026 cp ${tempDir}/.abuild/abuild-key.rsa.pub /etc/apk/keys/ \u0026\u0026 apk del --no-network .build-deps \u0026\u0026 if [ \"$apkArch\" = \"armhf\" ]; then nginxPackages=\"$( echo $nginxPackages | sed 's,nginx-module-acme=.*,,')\"; fi \u0026\u0026 apk add -X ${tempDir}/packages/alpine/ --no-cache $nginxPackages ;; esac \u0026\u0026 apk del --no-network .checksum-deps \u0026\u0026 if [ -n \"$tempDir\" ]; then rm -rf \"$tempDir\"; fi \u0026\u0026 if [ -f \"/etc/apk/keys/abuild-key.rsa.pub\" ]; then rm -f /etc/apk/keys/abuild-key.rsa.pub; fi \u0026\u0026 apk add --no-cache curl ca-certificates # buildkit", "comment": "buildkit.dockerfile.v0" }, { "created": "2026-09-15T16:27:31Z", "created_by": "/bin/sh -c #(nop) ARG VCS_REF=unknown", "empty_layer": true }, { "created": "2026-09-15T16:27:34Z", "created_by": "/bin/sh -c #(nop) LABEL org.opencontainers.image.title=DTF Site and Kanban org.opencontainers.image.revision=local-validation org.opencontainers.image.source=DTF System repository", "empty_layer": true }, { "created": "2026-09-15T16:27:35Z", "created_by": "/bin/sh -c #(nop) ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https://invalid.example", "empty_layer": true }, { "created": "2026-09-15T16:27:37Z", "created_by": "/bin/sh -c #(nop) COPY file:20fe34ab76ccd30979b464bdd4e734819f8249f24e5498a44c5d04b3778448ad in /etc/nginx/templates/default.conf.template " }, { "created": "2026-09-15T16:27:38Z", "created_by": "/bin/sh -c #(nop) COPY file:250b223b4392e692fcbffe99098e39467952f288ef8b682d85553e0190850b97 in /usr/share/nginx/html/index.html " }, { "created": "2026-09-15T16:27:39Z", "created_by": "/bin/sh -c #(nop) COPY dir:7a567fb1a37cda0230a25ad002e176756991ed408b4b3db7deb5c2a2a0c42e1b in /usr/share/nginx/html/ " }, { "created": "2026-09-15T17:09:14Z", "created_by": "/bin/sh -c #(nop) USER 101:101", "empty_layer": true }, { "created": "2026-09-15T17:09:15Z", "created_by": "/bin/sh -c #(nop) EXPOSE 8080", "empty_layer": true } ], "os": "linux", "rootfs": { "type": "layers", "diff_ids": [ "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e", "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119", "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294", "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da", "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8", "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0", "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8", "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0", "sha256:4a37d6822c6d388b4e3399cf15c5bd0878c71d6ec14862edd0f778b1e75b4b62", "sha256:860dbfb02839b3b8496aae962b9fae057fd868bd09f0e6867230e80aca08260e", "sha256:aa2935217d14946c1ebf1ccb9e1ca43fca63c86d4fe6aed723f5b3ae997762c5" ] }, "config": { "Cmd": [ "nginx", "-g", "daemon off;" ], "Entrypoint": [ "/docker-entrypoint.sh" ], "Env": [ "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", "NGINX_VERSION=1.28.3", "PKG_RELEASE=1", "DYNPKG_RELEASE=1", "NJS_VERSION=0.9.6", "NJS_RELEASE=1", "ACME_VERSION=0.3.1", "WEB_INDEX=index.html", "PUBLIC_HOST=invalid.example", "S3_PUBLIC_ENDPOINT=https://invalid.example" ], "Labels": { "maintainer": "NGINX Docker Maintainers \u003cdocker-maint@nginx.com\u003e", "org.opencontainers.image.revision": "local-validation", "org.opencontainers.image.source": "DTF System repository", "org.opencontainers.image.title": "DTF Site and Kanban" }, "User": "101:101", "WorkingDir": "/", "ExposedPorts": { "80/tcp": {}, "8080/tcp": {} }, "StopSignal": "SIGQUIT" } }, "Layers": [ { "Size": 8724480, "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, { "Size": 4654592, "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, { "Size": 3584, "Digest": "sha256:e914c6e98e37815624beb8c5043be292f121898059d4d50c0709bc4da661f685", "DiffID": "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294" }, { "Size": 4608, "Digest": "sha256:d631a49fb4f72e5bc609d0af4ce6d3ed054498068dc16c730be6b4e37c4a7f6c", "DiffID": "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da" }, { "Size": 2560, "Digest": "sha256:8f7c784e247120771f7bdb83b2ab8e17af75af4858332b63e0ed40610f5a9b59", "DiffID": "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8" }, { "Size": 5120, "Digest": "sha256:44fa0a5a779fdf3b85972e8dfb3b2755a72a97290b682794f57212d88fa3a631", "DiffID": "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0" }, { "Size": 7168, "Digest": "sha256:98104829f3fe8d2ead9a69b1f56c1f98955fd2b5933f089301331bb1f349683b", "DiffID": "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8" }, { "Size": 50089984, "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, { "Size": 5120, "Digest": "sha256:4509de44e3385a343f9ac0f76f43c70be9f9394508d0acdc7d383511f09f91d7", "DiffID": "sha256:4a37d6822c6d388b4e3399cf15c5bd0878c71d6ec14862edd0f778b1e75b4b62" }, { "Size": 152576, "Digest": "sha256:297df280b12814cec0cbc0bad18c01b96c5774db590a64e33867e8a6e255a888", "DiffID": "sha256:860dbfb02839b3b8496aae962b9fae057fd868bd09f0e6867230e80aca08260e" }, { "Size": 44032, "Digest": "sha256:5f5be02e32912d8d4243b79a370d86e36576137c36046a82f89397cdb44cdf75", "DiffID": "sha256:aa2935217d14946c1ebf1ccb9e1ca43fca63c86d4fe6aed723f5b3ae997762c5" } ] }, "Results": [ { "Target": "dtf-production-web:validation (alpine 3.23.3)", "Class": "os-pkgs", "Type": "alpine", "Packages": [ { "ID": "alpine-baselayout@3.7.1-r8", "Name": "alpine-baselayout", "Identifier": { "PURL": "pkg:apk/alpine/alpine-baselayout@3.7.1-r8?arch=x86_64\u0026distro=3.23.3", "UID": "dc092fc47b5d9e05" }, "Version": "3.7.1-r8", "Arch": "x86_64", "SrcName": "alpine-baselayout", "SrcVersion": "3.7.1-r8", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "alpine-baselayout-data@3.7.1-r8", "busybox-binsh@1.37.0-r30" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:9a137c3c8e738bcabac13326c9fc5472fa58aaf4", "InstalledFiles": [ "etc/motd", "etc/crontabs/root", "etc/modprobe.d/aliases.conf", "etc/modprobe.d/blacklist.conf", "etc/modprobe.d/i386.conf", "etc/profile.d/20locale.sh", "etc/profile.d/README", "etc/profile.d/color_prompt.sh.disabled", "usr/lib/sysctl.d/00-alpine.conf", "var/lock", "var/run", "var/spool/mail", "var/spool/cron/crontabs" ], "AnalyzedBy": "apk" }, { "ID": "alpine-baselayout-data@3.7.1-r8", "Name": "alpine-baselayout-data", "Identifier": { "PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.1-r8?arch=x86_64\u0026distro=3.23.3", "UID": "6542463feabe92df" }, "Version": "3.7.1-r8", "Arch": "x86_64", "SrcName": "alpine-baselayout", "SrcVersion": "3.7.1-r8", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:9a60b0edb4559ab279cf004b7e685cfd78dd0c15", "InstalledFiles": [ "etc/fstab", "etc/group", "etc/hostname", "etc/hosts", "etc/inittab", "etc/modules", "etc/mtab", "etc/nsswitch.conf", "etc/passwd", "etc/profile", "etc/protocols", "etc/services", "etc/shadow", "etc/shells", "etc/sysctl.conf" ], "AnalyzedBy": "apk" }, { "ID": "alpine-keys@2.6-r0", "Name": "alpine-keys", "Identifier": { "PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.23.3", "UID": "2c7cb90de388aa7d" }, "Version": "2.6-r0", "Arch": "x86_64", "SrcName": "alpine-keys", "SrcVersion": "2.6-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:5c45a821cd6b84d543bbd7ff12a7de1855c5cd13", "InstalledFiles": [ "etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", "etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", "usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", "usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub" ], "AnalyzedBy": "apk" }, { "ID": "alpine-release@3.23.3-r0", "Name": "alpine-release", "Identifier": { "PURL": "pkg:apk/alpine/alpine-release@3.23.3-r0?arch=x86_64\u0026distro=3.23.3", "UID": "4820d6f0afb6a834" }, "Version": "3.23.3-r0", "Arch": "x86_64", "SrcName": "alpine-base", "SrcVersion": "3.23.3-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "alpine-keys@2.6-r0" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:e71144a1a35c4844507cd1a3281a7189049f3522", "InstalledFiles": [ "etc/alpine-release", "etc/issue", "etc/os-release", "etc/secfixes.d/alpine", "usr/lib/os-release" ], "AnalyzedBy": "apk" }, { "ID": "aom-libs@3.13.1-r1", "Name": "aom-libs", "Identifier": { "PURL": "pkg:apk/alpine/aom-libs@3.13.1-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8324fd8055cbd635" }, "Version": "3.13.1-r1", "Arch": "x86_64", "SrcName": "aom", "SrcVersion": "3.13.1-r1", "Licenses": [ "BSD-2-Clause", "custom" ], "Maintainer": "Oleg Titov \u003coleg.titov@gmail.com\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:97b0c2dffcef97a0253876d015ca217de10b216a", "InstalledFiles": [ "usr/lib/libaom.so.3", "usr/lib/libaom.so.3.13.1" ], "AnalyzedBy": "apk" }, { "ID": "apk-tools@3.0.3-r1", "Name": "apk-tools", "Identifier": { "PURL": "pkg:apk/alpine/apk-tools@3.0.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "135e6dc8dcafde4f" }, "Version": "3.0.3-r1", "Arch": "x86_64", "SrcName": "apk-tools", "SrcVersion": "3.0.3-r1", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "ca-certificates-bundle@20251003-r0", "libapk@3.0.3-r1", "libcrypto3@3.5.5-r0", "musl@1.2.5-r21", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:b2f877e6c9fb945c185cf36ed546064b8b374245", "InstalledFiles": [ "sbin/apk" ], "AnalyzedBy": "apk" }, { "ID": "brotli-libs@1.2.0-r0", "Name": "brotli-libs", "Identifier": { "PURL": "pkg:apk/alpine/brotli-libs@1.2.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "18708ffc8b6c1544" }, "Version": "1.2.0-r0", "Arch": "x86_64", "SrcName": "brotli", "SrcVersion": "1.2.0-r0", "Licenses": [ "MIT" ], "Maintainer": "prspkt \u003cprspkt@protonmail.com\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:0814694602f35d2741e916fdcb4c9a1e0ec50b42", "InstalledFiles": [ "usr/lib/libbrotlicommon.so.1", "usr/lib/libbrotlicommon.so.1.2.0", "usr/lib/libbrotlidec.so.1", "usr/lib/libbrotlidec.so.1.2.0", "usr/lib/libbrotlienc.so.1", "usr/lib/libbrotlienc.so.1.2.0" ], "AnalyzedBy": "apk" }, { "ID": "busybox@1.37.0-r30", "Name": "busybox", "Identifier": { "PURL": "pkg:apk/alpine/busybox@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", "UID": "1701a73d4be0e35a" }, "Version": "1.37.0-r30", "Arch": "x86_64", "SrcName": "busybox", "SrcVersion": "1.37.0-r30", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:f1347801bb96b1aa40d17f82237c3f4ff02a4725", "InstalledFiles": [ "bin/busybox", "etc/securetty", "etc/busybox-paths.d/busybox", "etc/logrotate.d/acpid", "etc/network/if-up.d/dad", "etc/udhcpc/udhcpc.conf", "usr/share/udhcpc/default.script" ], "AnalyzedBy": "apk" }, { "ID": "busybox-binsh@1.37.0-r30", "Name": "busybox-binsh", "Identifier": { "PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", "UID": "3e18d05d46a6f46f" }, "Version": "1.37.0-r30", "Arch": "x86_64", "SrcName": "busybox", "SrcVersion": "1.37.0-r30", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", "DependsOn": [ "busybox@1.37.0-r30" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:188d2d0110afa58e8a3e3e5fd424b2d996df7a09", "InstalledFiles": [ "bin/sh" ], "AnalyzedBy": "apk" }, { "ID": "c-ares@1.34.6-r0", "Name": "c-ares", "Identifier": { "PURL": "pkg:apk/alpine/c-ares@1.34.6-r0?arch=x86_64\u0026distro=3.23.3", "UID": "2fc69dd6afab16ae" }, "Version": "1.34.6-r0", "Arch": "x86_64", "SrcName": "c-ares", "SrcVersion": "1.34.6-r0", "Licenses": [ "MIT" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:e3bb3ff47a277ff9409b8c4bb825099cfe2bcbe2", "InstalledFiles": [ "usr/lib/libcares.so.2", "usr/lib/libcares.so.2.19.5" ], "AnalyzedBy": "apk" }, { "ID": "ca-certificates@20251003-r0", "Name": "ca-certificates", "Identifier": { "PURL": "pkg:apk/alpine/ca-certificates@20251003-r0?arch=x86_64\u0026distro=3.23.3", "UID": "209bcc6fdf94c4a5" }, "Version": "20251003-r0", "Arch": "x86_64", "SrcName": "ca-certificates", "SrcVersion": "20251003-r0", "Licenses": [ "MPL-2.0", "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "libcrypto3@3.5.5-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:3b10fd335b2af819c4fd3562900e76fd6ea304c5", "InstalledFiles": [ "etc/ca-certificates.conf", "etc/apk/protected_paths.d/ca-certificates.list", "etc/ca-certificates/update.d/certhash", "usr/bin/c_rehash", "usr/sbin/update-ca-certificates", "usr/share/ca-certificates/mozilla/ACCVRAIZ1.crt", "usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM.crt", "usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.crt", "usr/share/ca-certificates/mozilla/ANF_Secure_Server_Root_CA.crt", "usr/share/ca-certificates/mozilla/Actalis_Authentication_Root_CA.crt", "usr/share/ca-certificates/mozilla/AffirmTrust_Commercial.crt", "usr/share/ca-certificates/mozilla/AffirmTrust_Networking.crt", "usr/share/ca-certificates/mozilla/AffirmTrust_Premium.crt", "usr/share/ca-certificates/mozilla/AffirmTrust_Premium_ECC.crt", "usr/share/ca-certificates/mozilla/Amazon_Root_CA_1.crt", "usr/share/ca-certificates/mozilla/Amazon_Root_CA_2.crt", "usr/share/ca-certificates/mozilla/Amazon_Root_CA_3.crt", "usr/share/ca-certificates/mozilla/Amazon_Root_CA_4.crt", "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_2011.crt", "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.crt", "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.crt", "usr/share/ca-certificates/mozilla/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.crt", "usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA1.crt", "usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA2.crt", "usr/share/ca-certificates/mozilla/Buypass_Class_2_Root_CA.crt", "usr/share/ca-certificates/mozilla/Buypass_Class_3_Root_CA.crt", "usr/share/ca-certificates/mozilla/CA_Disig_Root_R2.crt", "usr/share/ca-certificates/mozilla/CFCA_EV_ROOT.crt", "usr/share/ca-certificates/mozilla/COMODO_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/COMODO_ECC_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/COMODO_RSA_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/Certainly_Root_E1.crt", "usr/share/ca-certificates/mozilla/Certainly_Root_R1.crt", "usr/share/ca-certificates/mozilla/Certigna.crt", "usr/share/ca-certificates/mozilla/Certigna_Root_CA.crt", "usr/share/ca-certificates/mozilla/Certum_EC-384_CA.crt", "usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA.crt", "usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA_2.crt", "usr/share/ca-certificates/mozilla/Certum_Trusted_Root_CA.crt", "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-01.crt", "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-02.crt", "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-01.crt", "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-02.crt", "usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_1_2020.crt", "usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_2_2023.crt", "usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_1_2020.crt", "usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_2_2023.crt", "usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt", "usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt", "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_CA.crt", "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G2.crt", "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G3.crt", "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_CA.crt", "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G2.crt", "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G3.crt", "usr/share/ca-certificates/mozilla/DigiCert_High_Assurance_EV_Root_CA.crt", "usr/share/ca-certificates/mozilla/DigiCert_TLS_ECC_P384_Root_G5.crt", "usr/share/ca-certificates/mozilla/DigiCert_TLS_RSA4096_Root_G5.crt", "usr/share/ca-certificates/mozilla/DigiCert_Trusted_Root_G4.crt", "usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_EC1.crt", "usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_G2.crt", "usr/share/ca-certificates/mozilla/FIRMAPROFESIONAL_CA_ROOT-A_WEB.crt", "usr/share/ca-certificates/mozilla/GDCA_TrustAUTH_R5_ROOT.crt", "usr/share/ca-certificates/mozilla/GLOBALTRUST_2020.crt", "usr/share/ca-certificates/mozilla/GTS_Root_R1.crt", "usr/share/ca-certificates/mozilla/GTS_Root_R2.crt", "usr/share/ca-certificates/mozilla/GTS_Root_R3.crt", "usr/share/ca-certificates/mozilla/GTS_Root_R4.crt", "usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R4.crt", "usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R5.crt", "usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R3.crt", "usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R6.crt", "usr/share/ca-certificates/mozilla/GlobalSign_Root_E46.crt", "usr/share/ca-certificates/mozilla/GlobalSign_Root_R46.crt", "usr/share/ca-certificates/mozilla/Go_Daddy_Root_Certificate_Authority_-_G2.crt", "usr/share/ca-certificates/mozilla/HARICA_TLS_ECC_Root_CA_2021.crt", "usr/share/ca-certificates/mozilla/HARICA_TLS_RSA_Root_CA_2021.crt", "usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt", "usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt", "usr/share/ca-certificates/mozilla/HiPKI_Root_CA_-_G1.crt", "usr/share/ca-certificates/mozilla/Hongkong_Post_Root_CA_3.crt", "usr/share/ca-certificates/mozilla/ISRG_Root_X1.crt", "usr/share/ca-certificates/mozilla/ISRG_Root_X2.crt", "usr/share/ca-certificates/mozilla/IdenTrust_Commercial_Root_CA_1.crt", "usr/share/ca-certificates/mozilla/IdenTrust_Public_Sector_Root_CA_1.crt", "usr/share/ca-certificates/mozilla/Izenpe.com.crt", "usr/share/ca-certificates/mozilla/Microsec_e-Szigno_Root_CA_2009.crt", "usr/share/ca-certificates/mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt", "usr/share/ca-certificates/mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt", "usr/share/ca-certificates/mozilla/NAVER_Global_Root_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt", "usr/share/ca-certificates/mozilla/OISTE_Server_Root_ECC_G1.crt", "usr/share/ca-certificates/mozilla/OISTE_Server_Root_RSA_G1.crt", "usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt", "usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt", "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_1_G3.crt", "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2.crt", "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2_G3.crt", "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3.crt", "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3_G3.crt", "usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt", "usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt", "usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt", "usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt", "usr/share/ca-certificates/mozilla/SSL.com_TLS_ECC_Root_CA_2022.crt", "usr/share/ca-certificates/mozilla/SSL.com_TLS_RSA_Root_CA_2022.crt", "usr/share/ca-certificates/mozilla/SZAFIR_ROOT_CA2.crt", "usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_E46.crt", "usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_R46.crt", "usr/share/ca-certificates/mozilla/SecureSign_Root_CA12.crt", "usr/share/ca-certificates/mozilla/SecureSign_Root_CA14.crt", "usr/share/ca-certificates/mozilla/SecureSign_Root_CA15.crt", "usr/share/ca-certificates/mozilla/SecureTrust_CA.crt", "usr/share/ca-certificates/mozilla/Secure_Global_CA.crt", "usr/share/ca-certificates/mozilla/Security_Communication_ECC_RootCA1.crt", "usr/share/ca-certificates/mozilla/Security_Communication_RootCA2.crt", "usr/share/ca-certificates/mozilla/Starfield_Root_Certificate_Authority_-_G2.crt", "usr/share/ca-certificates/mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt", "usr/share/ca-certificates/mozilla/SwissSign_Gold_CA_-_G2.crt", "usr/share/ca-certificates/mozilla/SwissSign_RSA_TLS_Root_CA_2022_-_1.crt", "usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_2.crt", "usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_3.crt", "usr/share/ca-certificates/mozilla/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.crt", "usr/share/ca-certificates/mozilla/TWCA_CYBER_Root_CA.crt", "usr/share/ca-certificates/mozilla/TWCA_Global_Root_CA.crt", "usr/share/ca-certificates/mozilla/TWCA_Root_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/Telekom_Security_TLS_ECC_Root_2020.crt", "usr/share/ca-certificates/mozilla/Telekom_Security_TLS_RSA_Root_2023.crt", "usr/share/ca-certificates/mozilla/TeliaSonera_Root_CA_v1.crt", "usr/share/ca-certificates/mozilla/Telia_Root_CA_v2.crt", "usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G3.crt", "usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G4.crt", "usr/share/ca-certificates/mozilla/TrustAsia_TLS_ECC_Root_CA.crt", "usr/share/ca-certificates/mozilla/TrustAsia_TLS_RSA_Root_CA.crt", "usr/share/ca-certificates/mozilla/Trustwave_Global_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P256_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P384_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/TunTrust_Root_CA.crt", "usr/share/ca-certificates/mozilla/UCA_Extended_Validation_Root.crt", "usr/share/ca-certificates/mozilla/UCA_Global_G2_Root.crt", "usr/share/ca-certificates/mozilla/USERTrust_ECC_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/USERTrust_RSA_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/certSIGN_ROOT_CA.crt", "usr/share/ca-certificates/mozilla/certSIGN_Root_CA_G2.crt", "usr/share/ca-certificates/mozilla/e-Szigno_Root_CA_2017.crt", "usr/share/ca-certificates/mozilla/ePKI_Root_Certification_Authority.crt", "usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_C3.crt", "usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_G3.crt", "usr/share/ca-certificates/mozilla/emSign_Root_CA_-_C1.crt", "usr/share/ca-certificates/mozilla/emSign_Root_CA_-_G1.crt", "usr/share/ca-certificates/mozilla/vTrus_ECC_Root_CA.crt", "usr/share/ca-certificates/mozilla/vTrus_Root_CA.crt" ], "AnalyzedBy": "apk" }, { "ID": "ca-certificates-bundle@20251003-r0", "Name": "ca-certificates-bundle", "Identifier": { "PURL": "pkg:apk/alpine/ca-certificates-bundle@20251003-r0?arch=x86_64\u0026distro=3.23.3", "UID": "f667a2210d1d97c1" }, "Version": "20251003-r0", "Arch": "x86_64", "SrcName": "ca-certificates", "SrcVersion": "20251003-r0", "Licenses": [ "MPL-2.0", "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:63ebe72ba79f548b6cdc8a9894e16a90d80f42b0", "InstalledFiles": [ "etc/ssl/cert.pem", "etc/ssl/certs/ca-certificates.crt", "etc/ssl1.1/cert.pem", "etc/ssl1.1/certs" ], "AnalyzedBy": "apk" }, { "ID": "curl@8.17.0-r1", "Name": "curl", "Identifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "Version": "8.17.0-r1", "Arch": "x86_64", "SrcName": "curl", "SrcVersion": "8.17.0-r1", "Licenses": [ "curl" ], "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", "DependsOn": [ "libcurl@8.17.0-r1", "musl@1.2.5-r21", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:c467d4938a8ffc55afe3b1a6223787e0ecd60036", "InstalledFiles": [ "usr/bin/curl", "usr/bin/wcurl" ], "AnalyzedBy": "apk" }, { "ID": "fontconfig@2.17.1-r0", "Name": "fontconfig", "Identifier": { "PURL": "pkg:apk/alpine/fontconfig@2.17.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "70f3d175fa20e060" }, "Version": "2.17.1-r0", "Arch": "x86_64", "SrcName": "fontconfig", "SrcVersion": "2.17.1-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "freetype@2.14.1-r0", "libexpat@2.7.5-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:8037b007516a65d246442a781a05f627073394d0", "InstalledFiles": [ "etc/fonts/fonts.conf", "etc/fonts/conf.d/10-hinting-slight.conf", "etc/fonts/conf.d/10-scale-bitmap-fonts.conf", "etc/fonts/conf.d/10-sub-pixel-none.conf", "etc/fonts/conf.d/10-yes-antialias.conf", "etc/fonts/conf.d/11-lcdfilter-default.conf", "etc/fonts/conf.d/20-unhint-small-vera.conf", "etc/fonts/conf.d/30-metric-aliases.conf", "etc/fonts/conf.d/40-nonlatin.conf", "etc/fonts/conf.d/45-generic.conf", "etc/fonts/conf.d/45-latin.conf", "etc/fonts/conf.d/48-spacing.conf", "etc/fonts/conf.d/49-sansserif.conf", "etc/fonts/conf.d/50-user.conf", "etc/fonts/conf.d/51-local.conf", "etc/fonts/conf.d/60-generic.conf", "etc/fonts/conf.d/60-latin.conf", "etc/fonts/conf.d/65-fonts-persian.conf", "etc/fonts/conf.d/65-nonlatin.conf", "etc/fonts/conf.d/69-unifont.conf", "etc/fonts/conf.d/70-no-bitmaps-except-emoji.conf", "etc/fonts/conf.d/80-delicious.conf", "etc/fonts/conf.d/90-synthetic.conf", "etc/fonts/conf.d/README", "usr/bin/fc-cache", "usr/bin/fc-cat", "usr/bin/fc-conflist", "usr/bin/fc-list", "usr/bin/fc-match", "usr/bin/fc-pattern", "usr/bin/fc-query", "usr/bin/fc-scan", "usr/bin/fc-validate", "usr/lib/libfontconfig.so.1", "usr/lib/libfontconfig.so.1.16.1", "usr/share/fontconfig/conf.avail/05-reset-dirs-sample.conf", "usr/share/fontconfig/conf.avail/09-autohint-if-no-hinting.conf", "usr/share/fontconfig/conf.avail/10-autohint.conf", "usr/share/fontconfig/conf.avail/10-hinting-full.conf", "usr/share/fontconfig/conf.avail/10-hinting-medium.conf", "usr/share/fontconfig/conf.avail/10-hinting-none.conf", "usr/share/fontconfig/conf.avail/10-hinting-slight.conf", "usr/share/fontconfig/conf.avail/10-no-antialias.conf", "usr/share/fontconfig/conf.avail/10-scale-bitmap-fonts.conf", "usr/share/fontconfig/conf.avail/10-sub-pixel-bgr.conf", "usr/share/fontconfig/conf.avail/10-sub-pixel-none.conf", "usr/share/fontconfig/conf.avail/10-sub-pixel-rgb.conf", "usr/share/fontconfig/conf.avail/10-sub-pixel-vbgr.conf", "usr/share/fontconfig/conf.avail/10-sub-pixel-vrgb.conf", "usr/share/fontconfig/conf.avail/10-unhinted.conf", "usr/share/fontconfig/conf.avail/10-yes-antialias.conf", "usr/share/fontconfig/conf.avail/11-lcdfilter-default.conf", "usr/share/fontconfig/conf.avail/11-lcdfilter-legacy.conf", "usr/share/fontconfig/conf.avail/11-lcdfilter-light.conf", "usr/share/fontconfig/conf.avail/11-lcdfilter-none.conf", "usr/share/fontconfig/conf.avail/20-unhint-small-vera.conf", "usr/share/fontconfig/conf.avail/25-unhint-nonlatin.conf", "usr/share/fontconfig/conf.avail/30-metric-aliases.conf", "usr/share/fontconfig/conf.avail/35-lang-normalize.conf", "usr/share/fontconfig/conf.avail/40-nonlatin.conf", "usr/share/fontconfig/conf.avail/45-generic.conf", "usr/share/fontconfig/conf.avail/45-latin.conf", "usr/share/fontconfig/conf.avail/48-guessfamily.conf", "usr/share/fontconfig/conf.avail/48-spacing.conf", "usr/share/fontconfig/conf.avail/49-sansserif.conf", "usr/share/fontconfig/conf.avail/50-user.conf", "usr/share/fontconfig/conf.avail/51-local.conf", "usr/share/fontconfig/conf.avail/60-generic.conf", "usr/share/fontconfig/conf.avail/60-latin.conf", "usr/share/fontconfig/conf.avail/65-fonts-persian.conf", "usr/share/fontconfig/conf.avail/65-khmer.conf", "usr/share/fontconfig/conf.avail/65-nonlatin.conf", "usr/share/fontconfig/conf.avail/69-unifont.conf", "usr/share/fontconfig/conf.avail/70-no-bitmaps-and-emoji.conf", "usr/share/fontconfig/conf.avail/70-no-bitmaps-except-emoji.conf", "usr/share/fontconfig/conf.avail/70-no-bitmaps.conf", "usr/share/fontconfig/conf.avail/70-yes-bitmaps.conf", "usr/share/fontconfig/conf.avail/80-delicious.conf", "usr/share/fontconfig/conf.avail/90-synthetic.conf", "usr/share/xml/fontconfig/fonts.dtd" ], "AnalyzedBy": "apk" }, { "ID": "freetype@2.14.1-r0", "Name": "freetype", "Identifier": { "PURL": "pkg:apk/alpine/freetype@2.14.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "21ab81867b035d6b" }, "Version": "2.14.1-r0", "Arch": "x86_64", "SrcName": "freetype", "SrcVersion": "2.14.1-r0", "Licenses": [ "FTL", "GPL-2.0-or-later" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "brotli-libs@1.2.0-r0", "libbz2@1.0.8-r6", "libpng@1.6.55-r0", "musl@1.2.5-r21", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:e227f29a00edd7ed5b1e62a050da6532183e60be", "InstalledFiles": [ "usr/lib/libfreetype.so.6", "usr/lib/libfreetype.so.6.20.4" ], "AnalyzedBy": "apk" }, { "ID": "geoip@1.6.12-r6", "Name": "geoip", "Identifier": { "PURL": "pkg:apk/alpine/geoip@1.6.12-r6?arch=x86_64\u0026distro=3.23.3", "UID": "a40f515e64af4e00" }, "Version": "1.6.12-r6", "Arch": "x86_64", "SrcName": "geoip", "SrcVersion": "1.6.12-r6", "Licenses": [ "LGPL-2.1-or-later" ], "Maintainer": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:8f2ea64ecb173949f03ec2371db4b534f142450f", "InstalledFiles": [ "usr/bin/geoiplookup", "usr/bin/geoiplookup6", "usr/lib/libGeoIP.so.1", "usr/lib/libGeoIP.so.1.6.12" ], "AnalyzedBy": "apk" }, { "ID": "gettext-envsubst@0.24.1-r1", "Name": "gettext-envsubst", "Identifier": { "PURL": "pkg:apk/alpine/gettext-envsubst@0.24.1-r1?arch=x86_64\u0026distro=3.23.3", "UID": "7fc5d88562c27ca2" }, "Version": "0.24.1-r1", "Arch": "x86_64", "SrcName": "gettext", "SrcVersion": "0.24.1-r1", "Licenses": [ "GPL-3.0-or-later", "LGPL-2.1-or-later", "MIT" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "libintl@0.24.1-r1", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "Digest": "sha1:7593f7d82a7c943f0114a5f700788c53afb8a554", "InstalledFiles": [ "usr/bin/envsubst" ], "AnalyzedBy": "apk" }, { "ID": "libapk@3.0.3-r1", "Name": "libapk", "Identifier": { "PURL": "pkg:apk/alpine/libapk@3.0.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "d8a4dac06126e84f" }, "Version": "3.0.3-r1", "Arch": "x86_64", "SrcName": "apk-tools", "SrcVersion": "3.0.3-r1", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libcrypto3@3.5.5-r0", "libssl3@3.5.5-r0", "musl@1.2.5-r21", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:17d0c18e379eb411aaa3e07392343a2dd6e098cc", "InstalledFiles": [ "usr/lib/libapk.so.3.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libavif@1.3.0-r0", "Name": "libavif", "Identifier": { "PURL": "pkg:apk/alpine/libavif@1.3.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "a92c4af89456638d" }, "Version": "1.3.0-r0", "Arch": "x86_64", "SrcName": "libavif", "SrcVersion": "1.3.0-r0", "Licenses": [ "BSD-2-Clause" ], "Maintainer": "Bart Ribbers \u003cbribbers@disroot.org\u003e", "DependsOn": [ "aom-libs@3.13.1-r1", "libdav1d@1.5.2-r0", "libyuv@0.0.1887.20251502-r1", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:6e0e61c8a9d1cb5a4a5f3faa64fb597844614f93", "InstalledFiles": [ "usr/lib/libavif.so.16", "usr/lib/libavif.so.16.3.0" ], "AnalyzedBy": "apk" }, { "ID": "libbsd@0.12.2-r0", "Name": "libbsd", "Identifier": { "PURL": "pkg:apk/alpine/libbsd@0.12.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "e8223f0f48326233" }, "Version": "0.12.2-r0", "Arch": "x86_64", "SrcName": "libbsd", "SrcVersion": "0.12.2-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libmd@1.1.0-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:33970b157edad359d05a2c3e6f3460e725549c8b", "InstalledFiles": [ "usr/lib/libbsd.so.0", "usr/lib/libbsd.so.0.12.2" ], "AnalyzedBy": "apk" }, { "ID": "libbz2@1.0.8-r6", "Name": "libbz2", "Identifier": { "PURL": "pkg:apk/alpine/libbz2@1.0.8-r6?arch=x86_64\u0026distro=3.23.3", "UID": "74d7fef128d53896" }, "Version": "1.0.8-r6", "Arch": "x86_64", "SrcName": "bzip2", "SrcVersion": "1.0.8-r6", "Licenses": [ "bzip-2-1.0.6" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:864d363da11ee24c7920e0d052d2da7f8429251e", "InstalledFiles": [ "usr/lib/libbz2.so.1", "usr/lib/libbz2.so.1.0.8" ], "AnalyzedBy": "apk" }, { "ID": "libcrypto3@3.5.5-r0", "Name": "libcrypto3", "Identifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "Version": "3.5.5-r0", "Arch": "x86_64", "SrcName": "openssl", "SrcVersion": "3.5.5-r0", "Licenses": [ "Apache-2.0" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:9ebf6995e814bacff0c04a868b0b27c3e82090f4", "InstalledFiles": [ "etc/ssl/ct_log_list.cnf", "etc/ssl/ct_log_list.cnf.dist", "etc/ssl/openssl.cnf", "etc/ssl/openssl.cnf.dist", "usr/lib/libcrypto.so.3", "usr/lib/engines-3/afalg.so", "usr/lib/engines-3/capi.so", "usr/lib/engines-3/loader_attic.so", "usr/lib/engines-3/padlock.so", "usr/lib/ossl-modules/legacy.so" ], "AnalyzedBy": "apk" }, { "ID": "libcurl@8.17.0-r1", "Name": "libcurl", "Identifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "Version": "8.17.0-r1", "Arch": "x86_64", "SrcName": "curl", "SrcVersion": "8.17.0-r1", "Licenses": [ "curl" ], "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", "DependsOn": [ "brotli-libs@1.2.0-r0", "c-ares@1.34.6-r0", "ca-certificates-bundle@20251003-r0", "libcrypto3@3.5.5-r0", "libidn2@2.3.8-r0", "libpsl@0.21.5-r3", "libssl3@3.5.5-r0", "musl@1.2.5-r21", "nghttp2-libs@1.68.0-r0", "nghttp3@1.13.1-r0", "zlib@1.3.1-r2", "zstd-libs@1.5.7-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:4018e686de80aa87659e95c1e62a3539c1d2542f", "InstalledFiles": [ "usr/lib/libcurl.so.4", "usr/lib/libcurl.so.4.8.0" ], "AnalyzedBy": "apk" }, { "ID": "libdav1d@1.5.2-r0", "Name": "libdav1d", "Identifier": { "PURL": "pkg:apk/alpine/libdav1d@1.5.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "b65a4cd7ff34a143" }, "Version": "1.5.2-r0", "Arch": "x86_64", "SrcName": "dav1d", "SrcVersion": "1.5.2-r0", "Licenses": [ "BSD-2-Clause" ], "Maintainer": "Bart Ribbers \u003cbribbers@disroot.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:62a9676453a8b99cfb42148cfd26df3b964bcc1b", "InstalledFiles": [ "usr/lib/libdav1d.so.7", "usr/lib/libdav1d.so.7.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libedit@20251016.3.1-r0", "Name": "libedit", "Identifier": { "PURL": "pkg:apk/alpine/libedit@20251016.3.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "c13fb208e3c71d28" }, "Version": "20251016.3.1-r0", "Arch": "x86_64", "SrcName": "libedit", "SrcVersion": "20251016.3.1-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Celeste \u003ccielesti@protonmail.com\u003e", "DependsOn": [ "libncursesw@6.5_p20251123-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:463f69335a3223b1ce6856ce3bef5c03fee721bf", "InstalledFiles": [ "usr/lib/libedit.so.0", "usr/lib/libedit.so.0.0.76" ], "AnalyzedBy": "apk" }, { "ID": "libexpat@2.7.5-r0", "Name": "libexpat", "Identifier": { "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "60ae354914fcce6c" }, "Version": "2.7.5-r0", "Arch": "x86_64", "SrcName": "expat", "SrcVersion": "2.7.5-r0", "Licenses": [ "MIT" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:5760d53ddd7cca8a742c672e4e00a475718eacaa", "InstalledFiles": [ "usr/lib/libexpat.so.1", "usr/lib/libexpat.so.1.11.3" ], "AnalyzedBy": "apk" }, { "ID": "libgcc@15.2.0-r2", "Name": "libgcc", "Identifier": { "PURL": "pkg:apk/alpine/libgcc@15.2.0-r2?arch=x86_64\u0026distro=3.23.3", "UID": "fe01204cb80c388d" }, "Version": "15.2.0-r2", "Arch": "x86_64", "SrcName": "gcc", "SrcVersion": "15.2.0-r2", "Licenses": [ "GPL-2.0-or-later", "LGPL-2.1-or-later" ], "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:57fccbe9eebf23f2c4f38ee2a24f8b0bdd508ff7", "InstalledFiles": [ "usr/lib/libgcc_s.so.1" ], "AnalyzedBy": "apk" }, { "ID": "libgd@2.3.3-r10", "Name": "libgd", "Identifier": { "PURL": "pkg:apk/alpine/libgd@2.3.3-r10?arch=x86_64\u0026distro=3.23.3", "UID": "65b22f80adc66176" }, "Version": "2.3.3-r10", "Arch": "x86_64", "SrcName": "gd", "SrcVersion": "2.3.3-r10", "Licenses": [ "GD" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "fontconfig@2.17.1-r0", "freetype@2.14.1-r0", "libavif@1.3.0-r0", "libjpeg-turbo@3.1.2-r0", "libpng@1.6.55-r0", "libwebp@1.6.0-r0", "libxpm@3.5.17-r0", "musl@1.2.5-r21", "tiff@4.7.1-r0", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:948454e00c660b6ddf1338a857959222f0888336", "InstalledFiles": [ "usr/lib/libgd.so.3", "usr/lib/libgd.so.3.0.11" ], "AnalyzedBy": "apk" }, { "ID": "libice@1.1.2-r0", "Name": "libice", "Identifier": { "PURL": "pkg:apk/alpine/libice@1.1.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "99c17cd82ccd171a" }, "Version": "1.1.2-r0", "Arch": "x86_64", "SrcName": "libice", "SrcVersion": "1.1.2-r0", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:997a01303f63cee0ba9773f0cd9b26b2eb5e6ace", "InstalledFiles": [ "usr/lib/libICE.so.6", "usr/lib/libICE.so.6.3.0" ], "AnalyzedBy": "apk" }, { "ID": "libidn2@2.3.8-r0", "Name": "libidn2", "Identifier": { "PURL": "pkg:apk/alpine/libidn2@2.3.8-r0?arch=x86_64\u0026distro=3.23.3", "UID": "e2fcbba2f74d78bf" }, "Version": "2.3.8-r0", "Arch": "x86_64", "SrcName": "libidn2", "SrcVersion": "2.3.8-r0", "Licenses": [ "GPL-2.0-or-later", "LGPL-3.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libunistring@1.4.1-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:b8c5bfa365da5c360a01230db4d71e65af94af3d", "InstalledFiles": [ "usr/lib/libidn2.so.0", "usr/lib/libidn2.so.0.4.0" ], "AnalyzedBy": "apk" }, { "ID": "libintl@0.24.1-r1", "Name": "libintl", "Identifier": { "PURL": "pkg:apk/alpine/libintl@0.24.1-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c90c10550691ca73" }, "Version": "0.24.1-r1", "Arch": "x86_64", "SrcName": "gettext", "SrcVersion": "0.24.1-r1", "Licenses": [ "LGPL-2.1-or-later" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "Digest": "sha1:0222324bb4dfd35e8a3ec821c86eb5afbd43a3af", "InstalledFiles": [ "usr/lib/libintl.so.8", "usr/lib/libintl.so.8.4.3" ], "AnalyzedBy": "apk" }, { "ID": "libjpeg-turbo@3.1.2-r0", "Name": "libjpeg-turbo", "Identifier": { "PURL": "pkg:apk/alpine/libjpeg-turbo@3.1.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "f80d15900d386c53" }, "Version": "3.1.2-r0", "Arch": "x86_64", "SrcName": "libjpeg-turbo", "SrcVersion": "3.1.2-r0", "Licenses": [ "BSD-3-Clause", "IJG", "Zlib" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:aa025fb7ecf9bd65ef2afe47e3740639521e09ce", "InstalledFiles": [ "usr/lib/libjpeg.so.8", "usr/lib/libjpeg.so.8.3.2" ], "AnalyzedBy": "apk" }, { "ID": "libmd@1.1.0-r0", "Name": "libmd", "Identifier": { "PURL": "pkg:apk/alpine/libmd@1.1.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "e263a6bc7bc6d7e0" }, "Version": "1.1.0-r0", "Arch": "x86_64", "SrcName": "libmd", "SrcVersion": "1.1.0-r0", "Licenses": [ "BSD-3-Clause", "BSD-2-Clause", "ISC", "Beerware", "Public", "Domain" ], "Maintainer": "omni \u003comni+alpine@hack.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:ce7c57bd1f6628da8ba0d3f2ac18f6d8c93c0346", "InstalledFiles": [ "usr/lib/libmd.so.0", "usr/lib/libmd.so.0.1.0" ], "AnalyzedBy": "apk" }, { "ID": "libncursesw@6.5_p20251123-r0", "Name": "libncursesw", "Identifier": { "PURL": "pkg:apk/alpine/libncursesw@6.5_p20251123-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6a5d130d9eac3aa5" }, "Version": "6.5_p20251123-r0", "Arch": "x86_64", "SrcName": "ncurses", "SrcVersion": "6.5_p20251123-r0", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21", "ncurses-terminfo-base@6.5_p20251123-r0" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:649d3041c52b80620fb50a98f5979d25ebbe1523", "InstalledFiles": [ "usr/lib/libncursesw.so.6", "usr/lib/libncursesw.so.6.5" ], "AnalyzedBy": "apk" }, { "ID": "libpng@1.6.55-r0", "Name": "libpng", "Identifier": { "PURL": "pkg:apk/alpine/libpng@1.6.55-r0?arch=x86_64\u0026distro=3.23.3", "UID": "9c803c58fd4ab240" }, "Version": "1.6.55-r0", "Arch": "x86_64", "SrcName": "libpng", "SrcVersion": "1.6.55-r0", "Licenses": [ "Libpng" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:03c56da9ef638f4eba0e4315bfa9b1966c26b328", "InstalledFiles": [ "usr/lib/libpng16.so.16", "usr/lib/libpng16.so.16.55.0" ], "AnalyzedBy": "apk" }, { "ID": "libpsl@0.21.5-r3", "Name": "libpsl", "Identifier": { "PURL": "pkg:apk/alpine/libpsl@0.21.5-r3?arch=x86_64\u0026distro=3.23.3", "UID": "9fb5bd2254e54a0" }, "Version": "0.21.5-r3", "Arch": "x86_64", "SrcName": "libpsl", "SrcVersion": "0.21.5-r3", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libidn2@2.3.8-r0", "libunistring@1.4.1-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:b663c00f920a93be49c825555aa1a212e4287393", "InstalledFiles": [ "usr/lib/libpsl.so.5", "usr/lib/libpsl.so.5.3.5" ], "AnalyzedBy": "apk" }, { "ID": "libsharpyuv@1.6.0-r0", "Name": "libsharpyuv", "Identifier": { "PURL": "pkg:apk/alpine/libsharpyuv@1.6.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "8d52c69285b703" }, "Version": "1.6.0-r0", "Arch": "x86_64", "SrcName": "libwebp", "SrcVersion": "1.6.0-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:9bbf3958ac62e163084cde753276246e56ff298b", "InstalledFiles": [ "usr/lib/libsharpyuv.so.0", "usr/lib/libsharpyuv.so.0.1.2" ], "AnalyzedBy": "apk" }, { "ID": "libsm@1.2.6-r0", "Name": "libsm", "Identifier": { "PURL": "pkg:apk/alpine/libsm@1.2.6-r0?arch=x86_64\u0026distro=3.23.3", "UID": "927edab0a11162d6" }, "Version": "1.2.6-r0", "Arch": "x86_64", "SrcName": "libsm", "SrcVersion": "1.2.6-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libice@1.1.2-r0", "libuuid@2.41.2-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:244b3b3e68f3c6c11c6202320109d460a2498e76", "InstalledFiles": [ "usr/lib/libSM.so.6", "usr/lib/libSM.so.6.0.1" ], "AnalyzedBy": "apk" }, { "ID": "libssl3@3.5.5-r0", "Name": "libssl3", "Identifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "Version": "3.5.5-r0", "Arch": "x86_64", "SrcName": "openssl", "SrcVersion": "3.5.5-r0", "Licenses": [ "Apache-2.0" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libcrypto3@3.5.5-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:12234895b6577cddcbe3450406f357600e8a6951", "InstalledFiles": [ "usr/lib/libssl.so.3" ], "AnalyzedBy": "apk" }, { "ID": "libstdc++@15.2.0-r2", "Name": "libstdc++", "Identifier": { "PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r2?arch=x86_64\u0026distro=3.23.3", "UID": "45c1717355985287" }, "Version": "15.2.0-r2", "Arch": "x86_64", "SrcName": "gcc", "SrcVersion": "15.2.0-r2", "Licenses": [ "GPL-2.0-or-later", "LGPL-2.1-or-later" ], "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", "DependsOn": [ "libgcc@15.2.0-r2", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:528d77417a16706468af852f2859ad00f176e266", "InstalledFiles": [ "usr/lib/libstdc++.so.6", "usr/lib/libstdc++.so.6.0.34" ], "AnalyzedBy": "apk" }, { "ID": "libunistring@1.4.1-r0", "Name": "libunistring", "Identifier": { "PURL": "pkg:apk/alpine/libunistring@1.4.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "4e0ee8fa7d9a5823" }, "Version": "1.4.1-r0", "Arch": "x86_64", "SrcName": "libunistring", "SrcVersion": "1.4.1-r0", "Licenses": [ "GPL-2.0-or-later", "LGPL-3.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:6e56562bde456bee5971787d3d95c34e84ced797", "InstalledFiles": [ "usr/lib/libunistring.so.5", "usr/lib/libunistring.so.5.2.1" ], "AnalyzedBy": "apk" }, { "ID": "libuuid@2.41.2-r0", "Name": "libuuid", "Identifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "Version": "2.41.2-r0", "Arch": "x86_64", "SrcName": "util-linux", "SrcVersion": "2.41.2-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:0050e9a7637cd71596beab9996afd0e335489016", "InstalledFiles": [ "usr/lib/libuuid.so.1", "usr/lib/libuuid.so.1.3.0" ], "AnalyzedBy": "apk" }, { "ID": "libwebp@1.6.0-r0", "Name": "libwebp", "Identifier": { "PURL": "pkg:apk/alpine/libwebp@1.6.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "3a5205b94800cfd5" }, "Version": "1.6.0-r0", "Arch": "x86_64", "SrcName": "libwebp", "SrcVersion": "1.6.0-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libsharpyuv@1.6.0-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:46f79fe406ce611058a6c0ce995ebe85f7b73c7a", "InstalledFiles": [ "usr/lib/libwebp.so.7", "usr/lib/libwebp.so.7.2.0" ], "AnalyzedBy": "apk" }, { "ID": "libx11@1.8.12-r1", "Name": "libx11", "Identifier": { "PURL": "pkg:apk/alpine/libx11@1.8.12-r1?arch=x86_64\u0026distro=3.23.3", "UID": "a425120d26ddc2d8" }, "Version": "1.8.12-r1", "Arch": "x86_64", "SrcName": "libx11", "SrcVersion": "1.8.12-r1", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libxcb@1.17.0-r1", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:689b36ec47d6c9abb9cbd0c7067ba4636568dbd5", "InstalledFiles": [ "usr/lib/libX11-xcb.so.1", "usr/lib/libX11-xcb.so.1.0.0", "usr/lib/libX11.so.6", "usr/lib/libX11.so.6.4.0", "usr/share/X11/XErrorDB", "usr/share/X11/Xcms.txt", "usr/share/X11/locale/compose.dir", "usr/share/X11/locale/locale.alias", "usr/share/X11/locale/locale.dir", "usr/share/X11/locale/C/Compose", "usr/share/X11/locale/C/XI18N_OBJS", "usr/share/X11/locale/C/XLC_LOCALE", "usr/share/X11/locale/am_ET.UTF-8/Compose", "usr/share/X11/locale/am_ET.UTF-8/XI18N_OBJS", "usr/share/X11/locale/am_ET.UTF-8/XLC_LOCALE", "usr/share/X11/locale/armscii-8/Compose", "usr/share/X11/locale/armscii-8/XI18N_OBJS", "usr/share/X11/locale/armscii-8/XLC_LOCALE", "usr/share/X11/locale/cs_CZ.UTF-8/Compose", "usr/share/X11/locale/cs_CZ.UTF-8/XI18N_OBJS", "usr/share/X11/locale/cs_CZ.UTF-8/XLC_LOCALE", "usr/share/X11/locale/el_GR.UTF-8/Compose", "usr/share/X11/locale/el_GR.UTF-8/XI18N_OBJS", "usr/share/X11/locale/el_GR.UTF-8/XLC_LOCALE", "usr/share/X11/locale/en_US.UTF-8/Compose", "usr/share/X11/locale/en_US.UTF-8/XI18N_OBJS", "usr/share/X11/locale/en_US.UTF-8/XLC_LOCALE", "usr/share/X11/locale/fi_FI.UTF-8/Compose", "usr/share/X11/locale/fi_FI.UTF-8/XI18N_OBJS", "usr/share/X11/locale/fi_FI.UTF-8/XLC_LOCALE", "usr/share/X11/locale/georgian-academy/Compose", "usr/share/X11/locale/georgian-academy/XI18N_OBJS", "usr/share/X11/locale/georgian-academy/XLC_LOCALE", "usr/share/X11/locale/georgian-ps/Compose", "usr/share/X11/locale/georgian-ps/XI18N_OBJS", "usr/share/X11/locale/georgian-ps/XLC_LOCALE", "usr/share/X11/locale/ibm-cp1133/Compose", "usr/share/X11/locale/ibm-cp1133/XI18N_OBJS", "usr/share/X11/locale/ibm-cp1133/XLC_LOCALE", "usr/share/X11/locale/iscii-dev/Compose", "usr/share/X11/locale/iscii-dev/XI18N_OBJS", "usr/share/X11/locale/iscii-dev/XLC_LOCALE", "usr/share/X11/locale/isiri-3342/Compose", "usr/share/X11/locale/isiri-3342/XI18N_OBJS", "usr/share/X11/locale/isiri-3342/XLC_LOCALE", "usr/share/X11/locale/iso8859-1/Compose", "usr/share/X11/locale/iso8859-1/XI18N_OBJS", "usr/share/X11/locale/iso8859-1/XLC_LOCALE", "usr/share/X11/locale/iso8859-10/Compose", "usr/share/X11/locale/iso8859-10/XI18N_OBJS", "usr/share/X11/locale/iso8859-10/XLC_LOCALE", "usr/share/X11/locale/iso8859-11/Compose", "usr/share/X11/locale/iso8859-11/XI18N_OBJS", "usr/share/X11/locale/iso8859-11/XLC_LOCALE", "usr/share/X11/locale/iso8859-13/Compose", "usr/share/X11/locale/iso8859-13/XI18N_OBJS", "usr/share/X11/locale/iso8859-13/XLC_LOCALE", "usr/share/X11/locale/iso8859-14/Compose", "usr/share/X11/locale/iso8859-14/XI18N_OBJS", "usr/share/X11/locale/iso8859-14/XLC_LOCALE", "usr/share/X11/locale/iso8859-15/Compose", "usr/share/X11/locale/iso8859-15/XI18N_OBJS", "usr/share/X11/locale/iso8859-15/XLC_LOCALE", "usr/share/X11/locale/iso8859-2/Compose", "usr/share/X11/locale/iso8859-2/XI18N_OBJS", "usr/share/X11/locale/iso8859-2/XLC_LOCALE", "usr/share/X11/locale/iso8859-3/Compose", "usr/share/X11/locale/iso8859-3/XI18N_OBJS", "usr/share/X11/locale/iso8859-3/XLC_LOCALE", "usr/share/X11/locale/iso8859-4/Compose", "usr/share/X11/locale/iso8859-4/XI18N_OBJS", "usr/share/X11/locale/iso8859-4/XLC_LOCALE", "usr/share/X11/locale/iso8859-5/Compose", "usr/share/X11/locale/iso8859-5/XI18N_OBJS", "usr/share/X11/locale/iso8859-5/XLC_LOCALE", "usr/share/X11/locale/iso8859-6/Compose", "usr/share/X11/locale/iso8859-6/XI18N_OBJS", "usr/share/X11/locale/iso8859-6/XLC_LOCALE", "usr/share/X11/locale/iso8859-7/Compose", "usr/share/X11/locale/iso8859-7/XI18N_OBJS", "usr/share/X11/locale/iso8859-7/XLC_LOCALE", "usr/share/X11/locale/iso8859-8/Compose", "usr/share/X11/locale/iso8859-8/XI18N_OBJS", "usr/share/X11/locale/iso8859-8/XLC_LOCALE", "usr/share/X11/locale/iso8859-9/Compose", "usr/share/X11/locale/iso8859-9/XI18N_OBJS", "usr/share/X11/locale/iso8859-9/XLC_LOCALE", "usr/share/X11/locale/iso8859-9e/Compose", "usr/share/X11/locale/iso8859-9e/XI18N_OBJS", "usr/share/X11/locale/iso8859-9e/XLC_LOCALE", "usr/share/X11/locale/ja/Compose", "usr/share/X11/locale/ja/XI18N_OBJS", "usr/share/X11/locale/ja/XLC_LOCALE", "usr/share/X11/locale/ja.JIS/Compose", "usr/share/X11/locale/ja.JIS/XI18N_OBJS", "usr/share/X11/locale/ja.JIS/XLC_LOCALE", "usr/share/X11/locale/ja.SJIS/Compose", "usr/share/X11/locale/ja.SJIS/XI18N_OBJS", "usr/share/X11/locale/ja.SJIS/XLC_LOCALE", "usr/share/X11/locale/ja_JP.UTF-8/Compose", "usr/share/X11/locale/ja_JP.UTF-8/XI18N_OBJS", "usr/share/X11/locale/ja_JP.UTF-8/XLC_LOCALE", "usr/share/X11/locale/km_KH.UTF-8/Compose", "usr/share/X11/locale/km_KH.UTF-8/XI18N_OBJS", "usr/share/X11/locale/km_KH.UTF-8/XLC_LOCALE", "usr/share/X11/locale/ko/Compose", "usr/share/X11/locale/ko/XI18N_OBJS", "usr/share/X11/locale/ko/XLC_LOCALE", "usr/share/X11/locale/ko_KR.UTF-8/Compose", "usr/share/X11/locale/ko_KR.UTF-8/XI18N_OBJS", "usr/share/X11/locale/ko_KR.UTF-8/XLC_LOCALE", "usr/share/X11/locale/koi8-c/Compose", "usr/share/X11/locale/koi8-c/XI18N_OBJS", "usr/share/X11/locale/koi8-c/XLC_LOCALE", "usr/share/X11/locale/koi8-r/Compose", "usr/share/X11/locale/koi8-r/XI18N_OBJS", "usr/share/X11/locale/koi8-r/XLC_LOCALE", "usr/share/X11/locale/koi8-u/Compose", "usr/share/X11/locale/koi8-u/XI18N_OBJS", "usr/share/X11/locale/koi8-u/XLC_LOCALE", "usr/share/X11/locale/microsoft-cp1251/Compose", "usr/share/X11/locale/microsoft-cp1251/XI18N_OBJS", "usr/share/X11/locale/microsoft-cp1251/XLC_LOCALE", "usr/share/X11/locale/microsoft-cp1255/Compose", "usr/share/X11/locale/microsoft-cp1255/XI18N_OBJS", "usr/share/X11/locale/microsoft-cp1255/XLC_LOCALE", "usr/share/X11/locale/microsoft-cp1256/Compose", "usr/share/X11/locale/microsoft-cp1256/XI18N_OBJS", "usr/share/X11/locale/microsoft-cp1256/XLC_LOCALE", "usr/share/X11/locale/mulelao-1/Compose", "usr/share/X11/locale/mulelao-1/XI18N_OBJS", "usr/share/X11/locale/mulelao-1/XLC_LOCALE", "usr/share/X11/locale/nokhchi-1/Compose", "usr/share/X11/locale/nokhchi-1/XI18N_OBJS", "usr/share/X11/locale/nokhchi-1/XLC_LOCALE", "usr/share/X11/locale/pt_BR.UTF-8/Compose", "usr/share/X11/locale/pt_BR.UTF-8/XI18N_OBJS", "usr/share/X11/locale/pt_BR.UTF-8/XLC_LOCALE", "usr/share/X11/locale/pt_PT.UTF-8/Compose", "usr/share/X11/locale/pt_PT.UTF-8/XI18N_OBJS", "usr/share/X11/locale/pt_PT.UTF-8/XLC_LOCALE", "usr/share/X11/locale/ru_RU.UTF-8/Compose", "usr/share/X11/locale/ru_RU.UTF-8/XI18N_OBJS", "usr/share/X11/locale/ru_RU.UTF-8/XLC_LOCALE", "usr/share/X11/locale/sr_RS.UTF-8/Compose", "usr/share/X11/locale/sr_RS.UTF-8/XI18N_OBJS", "usr/share/X11/locale/sr_RS.UTF-8/XLC_LOCALE", "usr/share/X11/locale/tatar-cyr/Compose", "usr/share/X11/locale/tatar-cyr/XI18N_OBJS", "usr/share/X11/locale/tatar-cyr/XLC_LOCALE", "usr/share/X11/locale/th_TH/Compose", "usr/share/X11/locale/th_TH/XI18N_OBJS", "usr/share/X11/locale/th_TH/XLC_LOCALE", "usr/share/X11/locale/th_TH.UTF-8/Compose", "usr/share/X11/locale/th_TH.UTF-8/XI18N_OBJS", "usr/share/X11/locale/th_TH.UTF-8/XLC_LOCALE", "usr/share/X11/locale/tscii-0/Compose", "usr/share/X11/locale/tscii-0/XI18N_OBJS", "usr/share/X11/locale/tscii-0/XLC_LOCALE", "usr/share/X11/locale/vi_VN.tcvn/Compose", "usr/share/X11/locale/vi_VN.tcvn/XI18N_OBJS", "usr/share/X11/locale/vi_VN.tcvn/XLC_LOCALE", "usr/share/X11/locale/vi_VN.viscii/Compose", "usr/share/X11/locale/vi_VN.viscii/XI18N_OBJS", "usr/share/X11/locale/vi_VN.viscii/XLC_LOCALE", "usr/share/X11/locale/zh_CN/Compose", "usr/share/X11/locale/zh_CN/XI18N_OBJS", "usr/share/X11/locale/zh_CN/XLC_LOCALE", "usr/share/X11/locale/zh_CN.UTF-8/Compose", "usr/share/X11/locale/zh_CN.UTF-8/XI18N_OBJS", "usr/share/X11/locale/zh_CN.UTF-8/XLC_LOCALE", "usr/share/X11/locale/zh_CN.gb18030/Compose", "usr/share/X11/locale/zh_CN.gb18030/XI18N_OBJS", "usr/share/X11/locale/zh_CN.gb18030/XLC_LOCALE", "usr/share/X11/locale/zh_CN.gbk/Compose", "usr/share/X11/locale/zh_CN.gbk/XI18N_OBJS", "usr/share/X11/locale/zh_CN.gbk/XLC_LOCALE", "usr/share/X11/locale/zh_HK.UTF-8/Compose", "usr/share/X11/locale/zh_HK.UTF-8/XI18N_OBJS", "usr/share/X11/locale/zh_HK.UTF-8/XLC_LOCALE", "usr/share/X11/locale/zh_HK.big5/Compose", "usr/share/X11/locale/zh_HK.big5/XI18N_OBJS", "usr/share/X11/locale/zh_HK.big5/XLC_LOCALE", "usr/share/X11/locale/zh_HK.big5hkscs/Compose", "usr/share/X11/locale/zh_HK.big5hkscs/XI18N_OBJS", "usr/share/X11/locale/zh_HK.big5hkscs/XLC_LOCALE", "usr/share/X11/locale/zh_TW/Compose", "usr/share/X11/locale/zh_TW/XI18N_OBJS", "usr/share/X11/locale/zh_TW/XLC_LOCALE", "usr/share/X11/locale/zh_TW.UTF-8/Compose", "usr/share/X11/locale/zh_TW.UTF-8/XI18N_OBJS", "usr/share/X11/locale/zh_TW.UTF-8/XLC_LOCALE", "usr/share/X11/locale/zh_TW.big5/Compose", "usr/share/X11/locale/zh_TW.big5/XI18N_OBJS", "usr/share/X11/locale/zh_TW.big5/XLC_LOCALE" ], "AnalyzedBy": "apk" }, { "ID": "libxau@1.0.12-r0", "Name": "libxau", "Identifier": { "PURL": "pkg:apk/alpine/libxau@1.0.12-r0?arch=x86_64\u0026distro=3.23.3", "UID": "aa0bb8a98c218213" }, "Version": "1.0.12-r0", "Arch": "x86_64", "SrcName": "libxau", "SrcVersion": "1.0.12-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:89d2bc9daae3cb0e2ae095db6866357b7653f341", "InstalledFiles": [ "usr/lib/libXau.so.6", "usr/lib/libXau.so.6.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libxcb@1.17.0-r1", "Name": "libxcb", "Identifier": { "PURL": "pkg:apk/alpine/libxcb@1.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "6f6901ad7b331681" }, "Version": "1.17.0-r1", "Arch": "x86_64", "SrcName": "libxcb", "SrcVersion": "1.17.0-r1", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libxau@1.0.12-r0", "libxdmcp@1.1.5-r1", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:61b06f883e8f8d2d8ee360e4dac04ac037fcca13", "InstalledFiles": [ "usr/lib/libxcb-composite.so.0", "usr/lib/libxcb-composite.so.0.0.0", "usr/lib/libxcb-damage.so.0", "usr/lib/libxcb-damage.so.0.0.0", "usr/lib/libxcb-dbe.so.0", "usr/lib/libxcb-dbe.so.0.0.0", "usr/lib/libxcb-dpms.so.0", "usr/lib/libxcb-dpms.so.0.0.0", "usr/lib/libxcb-dri2.so.0", "usr/lib/libxcb-dri2.so.0.0.0", "usr/lib/libxcb-dri3.so.0", "usr/lib/libxcb-dri3.so.0.1.0", "usr/lib/libxcb-glx.so.0", "usr/lib/libxcb-glx.so.0.0.0", "usr/lib/libxcb-present.so.0", "usr/lib/libxcb-present.so.0.0.0", "usr/lib/libxcb-randr.so.0", "usr/lib/libxcb-randr.so.0.1.0", "usr/lib/libxcb-record.so.0", "usr/lib/libxcb-record.so.0.0.0", "usr/lib/libxcb-render.so.0", "usr/lib/libxcb-render.so.0.0.0", "usr/lib/libxcb-res.so.0", "usr/lib/libxcb-res.so.0.0.0", "usr/lib/libxcb-screensaver.so.0", "usr/lib/libxcb-screensaver.so.0.0.0", "usr/lib/libxcb-shape.so.0", "usr/lib/libxcb-shape.so.0.0.0", "usr/lib/libxcb-shm.so.0", "usr/lib/libxcb-shm.so.0.0.0", "usr/lib/libxcb-sync.so.1", "usr/lib/libxcb-sync.so.1.0.0", "usr/lib/libxcb-xf86dri.so.0", "usr/lib/libxcb-xf86dri.so.0.0.0", "usr/lib/libxcb-xfixes.so.0", "usr/lib/libxcb-xfixes.so.0.0.0", "usr/lib/libxcb-xinerama.so.0", "usr/lib/libxcb-xinerama.so.0.0.0", "usr/lib/libxcb-xinput.so.0", "usr/lib/libxcb-xinput.so.0.1.0", "usr/lib/libxcb-xkb.so.1", "usr/lib/libxcb-xkb.so.1.0.0", "usr/lib/libxcb-xtest.so.0", "usr/lib/libxcb-xtest.so.0.0.0", "usr/lib/libxcb-xv.so.0", "usr/lib/libxcb-xv.so.0.0.0", "usr/lib/libxcb-xvmc.so.0", "usr/lib/libxcb-xvmc.so.0.0.0", "usr/lib/libxcb.so.1", "usr/lib/libxcb.so.1.1.0" ], "AnalyzedBy": "apk" }, { "ID": "libxdmcp@1.1.5-r1", "Name": "libxdmcp", "Identifier": { "PURL": "pkg:apk/alpine/libxdmcp@1.1.5-r1?arch=x86_64\u0026distro=3.23.3", "UID": "4fca0d7ff08ca578" }, "Version": "1.1.5-r1", "Arch": "x86_64", "SrcName": "libxdmcp", "SrcVersion": "1.1.5-r1", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libbsd@0.12.2-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:99a24c0fa12282b5ef89a6e732a8d494b7696d9d", "InstalledFiles": [ "usr/lib/libXdmcp.so.6", "usr/lib/libXdmcp.so.6.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libxext@1.3.6-r2", "Name": "libxext", "Identifier": { "PURL": "pkg:apk/alpine/libxext@1.3.6-r2?arch=x86_64\u0026distro=3.23.3", "UID": "57ff00875e99d22c" }, "Version": "1.3.6-r2", "Arch": "x86_64", "SrcName": "libxext", "SrcVersion": "1.3.6-r2", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libx11@1.8.12-r1", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:92fb4f12c2170403d6a48c7485ecaee40c84bee2", "InstalledFiles": [ "usr/lib/libXext.so.6", "usr/lib/libXext.so.6.4.0" ], "AnalyzedBy": "apk" }, { "ID": "libxml2@2.13.9-r0", "Name": "libxml2", "Identifier": { "PURL": "pkg:apk/alpine/libxml2@2.13.9-r0?arch=x86_64\u0026distro=3.23.3", "UID": "ce9ff006e72f7256" }, "Version": "2.13.9-r0", "Arch": "x86_64", "SrcName": "libxml2", "SrcVersion": "2.13.9-r0", "Licenses": [ "MIT" ], "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21", "xz-libs@5.8.2-r0", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:9fb56eb6e62b7b6658a8abe14cded8d87a47ebc7", "InstalledFiles": [ "usr/lib/libxml2.so.2", "usr/lib/libxml2.so.2.13.9" ], "AnalyzedBy": "apk" }, { "ID": "libxpm@3.5.17-r0", "Name": "libxpm", "Identifier": { "PURL": "pkg:apk/alpine/libxpm@3.5.17-r0?arch=x86_64\u0026distro=3.23.3", "UID": "eb108d14a7e73e9c" }, "Version": "3.5.17-r0", "Arch": "x86_64", "SrcName": "libxpm", "SrcVersion": "3.5.17-r0", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libx11@1.8.12-r1", "libxext@1.3.6-r2", "libxt@1.3.1-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:50af3a739664e6d3dc92b94be46d3b96c0b11da8", "InstalledFiles": [ "usr/bin/cxpm", "usr/bin/sxpm", "usr/lib/libXpm.so.4", "usr/lib/libXpm.so.4.11.0" ], "AnalyzedBy": "apk" }, { "ID": "libxslt@1.1.43-r3", "Name": "libxslt", "Identifier": { "PURL": "pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64\u0026distro=3.23.3", "UID": "3a1c588b7ca6e66a" }, "Version": "1.1.43-r3", "Arch": "x86_64", "SrcName": "libxslt", "SrcVersion": "1.1.43-r3", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libxml2@2.13.9-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:7d73182371fbf2141e137329e5432b94551bdd1b", "InstalledFiles": [ "usr/bin/xsltproc", "usr/lib/libexslt.so.0", "usr/lib/libexslt.so.0.8.24", "usr/lib/libxslt.so.1", "usr/lib/libxslt.so.1.1.43" ], "AnalyzedBy": "apk" }, { "ID": "libxt@1.3.1-r0", "Name": "libxt", "Identifier": { "PURL": "pkg:apk/alpine/libxt@1.3.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "d94c77e6d9f596b4" }, "Version": "1.3.1-r0", "Arch": "x86_64", "SrcName": "libxt", "SrcVersion": "1.3.1-r0", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "libice@1.1.2-r0", "libsm@1.2.6-r0", "libx11@1.8.12-r1", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:1cffd892c392dcaac9ad017c999f9e268b5f8ee1", "InstalledFiles": [ "usr/lib/libXt.so.6", "usr/lib/libXt.so.6.0.0" ], "AnalyzedBy": "apk" }, { "ID": "libyuv@0.0.1887.20251502-r1", "Name": "libyuv", "Identifier": { "PURL": "pkg:apk/alpine/libyuv@0.0.1887.20251502-r1?arch=x86_64\u0026distro=3.23.3", "UID": "7fa232d8c24a770f" }, "Version": "0.0.1887.20251502-r1", "Arch": "x86_64", "SrcName": "libyuv", "SrcVersion": "0.0.1887.20251502-r1", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Andy Postnikov \u003capostnikov@gmail.com\u003e", "DependsOn": [ "libgcc@15.2.0-r2", "libjpeg-turbo@3.1.2-r0", "libstdc++@15.2.0-r2", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:8335fd57f5a479534322e6ac74968fdc7564d8d0", "InstalledFiles": [ "usr/bin/yuvconvert", "usr/lib/libyuv.so" ], "AnalyzedBy": "apk" }, { "ID": "musl@1.2.5-r21", "Name": "musl", "Identifier": { "PURL": "pkg:apk/alpine/musl@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", "UID": "750ab06f52f2bfe9" }, "Version": "1.2.5-r21", "Arch": "x86_64", "SrcName": "musl", "SrcVersion": "1.2.5-r21", "Licenses": [ "MIT" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:d05a75ec13e1a7a8bab56ce7cd3dc79bd727e698", "InstalledFiles": [ "lib/ld-musl-x86_64.so.1", "lib/libc.musl-x86_64.so.1" ], "AnalyzedBy": "apk" }, { "ID": "musl-utils@1.2.5-r21", "Name": "musl-utils", "Identifier": { "PURL": "pkg:apk/alpine/musl-utils@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", "UID": "9dadd6d4093981ad" }, "Version": "1.2.5-r21", "Arch": "x86_64", "SrcName": "musl", "SrcVersion": "1.2.5-r21", "Licenses": [ "MIT", "BSD-2-Clause", "GPL-2.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21", "scanelf@1.3.8-r2" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:daa79528d2cf877f6d656207a818d43c8dea9a30", "InstalledFiles": [ "sbin/ldconfig", "usr/bin/getconf", "usr/bin/getent", "usr/bin/iconv", "usr/bin/ldd" ], "AnalyzedBy": "apk" }, { "ID": "ncurses-terminfo-base@6.5_p20251123-r0", "Name": "ncurses-terminfo-base", "Identifier": { "PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.5_p20251123-r0?arch=x86_64\u0026distro=3.23.3", "UID": "5acf10991828fa7a" }, "Version": "6.5_p20251123-r0", "Arch": "x86_64", "SrcName": "ncurses", "SrcVersion": "6.5_p20251123-r0", "Licenses": [ "X-11" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:57bd1d8124ec957eefea2314bdf45b0ed1068cee", "InstalledFiles": [ "etc/terminfo/a/alacritty", "etc/terminfo/a/ansi", "etc/terminfo/d/dumb", "etc/terminfo/g/gnome", "etc/terminfo/g/gnome-256color", "etc/terminfo/k/konsole", "etc/terminfo/k/konsole-256color", "etc/terminfo/k/konsole-linux", "etc/terminfo/l/linux", "etc/terminfo/p/putty", "etc/terminfo/p/putty-256color", "etc/terminfo/r/rxvt", "etc/terminfo/r/rxvt-256color", "etc/terminfo/s/screen", "etc/terminfo/s/screen-256color", "etc/terminfo/s/st-0.6", "etc/terminfo/s/st-0.7", "etc/terminfo/s/st-0.8", "etc/terminfo/s/st-0.8.5", "etc/terminfo/s/st-16color", "etc/terminfo/s/st-256color", "etc/terminfo/s/st-direct", "etc/terminfo/s/sun", "etc/terminfo/t/terminator", "etc/terminfo/t/terminology", "etc/terminfo/t/terminology-0.6.1", "etc/terminfo/t/terminology-1.0.0", "etc/terminfo/t/terminology-1.8.1", "etc/terminfo/t/tmux", "etc/terminfo/t/tmux-256color", "etc/terminfo/v/vt100", "etc/terminfo/v/vt102", "etc/terminfo/v/vt200", "etc/terminfo/v/vt220", "etc/terminfo/v/vt52", "etc/terminfo/v/vte", "etc/terminfo/v/vte-256color", "etc/terminfo/x/xterm", "etc/terminfo/x/xterm-256color", "etc/terminfo/x/xterm-color", "etc/terminfo/x/xterm-xfree86" ], "AnalyzedBy": "apk" }, { "ID": "nghttp2-libs@1.68.0-r0", "Name": "nghttp2-libs", "Identifier": { "PURL": "pkg:apk/alpine/nghttp2-libs@1.68.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "802c936f9e7891b2" }, "Version": "1.68.0-r0", "Arch": "x86_64", "SrcName": "nghttp2", "SrcVersion": "1.68.0-r0", "Licenses": [ "MIT" ], "Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:584b6a1b0aed58a3f543bfd77729b0d8a8b1745b", "InstalledFiles": [ "usr/lib/libnghttp2.so.14", "usr/lib/libnghttp2.so.14.29.2" ], "AnalyzedBy": "apk" }, { "ID": "nghttp3@1.13.1-r0", "Name": "nghttp3", "Identifier": { "PURL": "pkg:apk/alpine/nghttp3@1.13.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "7999d360d1276f40" }, "Version": "1.13.1-r0", "Arch": "x86_64", "SrcName": "nghttp3", "SrcVersion": "1.13.1-r0", "Licenses": [ "MIT" ], "Maintainer": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:e48fcb3e81f7e46a42e3926d8513c83b7798774b", "InstalledFiles": [ "usr/lib/libnghttp3.so.9", "usr/lib/libnghttp3.so.9.5.1" ], "AnalyzedBy": "apk" }, { "ID": "nginx@1.28.3-r1", "Name": "nginx", "Identifier": { "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8bdce2a9d53051b3" }, "Version": "1.28.3-r1", "Arch": "x86_64", "SrcName": "nginx", "SrcVersion": "1.28.3-r1", "Licenses": [ "2-clause", "BSD-3-Clause", "license" ], "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "libcrypto3@3.5.5-r0", "libssl3@3.5.5-r0", "musl@1.2.5-r21", "pcre2@10.47-r0", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "Digest": "sha1:dea6a746d0881ec71c3ec7bd2e9e57640da2235f", "InstalledFiles": [ "etc/init.d/nginx", "etc/init.d/nginx-debug", "etc/logrotate.d/nginx", "etc/nginx/fastcgi.conf", "etc/nginx/fastcgi_params", "etc/nginx/mime.types", "etc/nginx/modules", "etc/nginx/nginx.conf", "etc/nginx/scgi_params", "etc/nginx/uwsgi_params", "etc/nginx/conf.d/default.conf", "usr/sbin/nginx", "usr/sbin/nginx-debug", "usr/share/licenses/nginx/COPYRIGHT", "usr/share/man/man8/nginx.8.gz", "usr/share/nginx/html/50x.html", "usr/share/nginx/html/index.html" ], "AnalyzedBy": "apk" }, { "ID": "nginx-module-acme@1.28.3.0.3.1-r1", "Name": "nginx-module-acme", "Identifier": { "PURL": "pkg:apk/alpine/nginx-module-acme@1.28.3.0.3.1-r1?arch=x86_64\u0026distro=3.23.3", "UID": "bb37055f6eef4ca8" }, "Version": "1.28.3.0.3.1-r1", "Arch": "x86_64", "SrcName": "nginx-module-acme", "SrcVersion": "1.28.3.0.3.1-r1", "Licenses": [ "2-clause", "BSD-3-Clause", "license" ], "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "libgcc@15.2.0-r2", "musl@1.2.5-r21", "nginx@1.28.3-r1" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:b108c1a13c4b8b83c6a784405dbbad1f91c757c2", "InstalledFiles": [ "usr/lib/nginx/modules/ngx_http_acme_module-debug.so", "usr/lib/nginx/modules/ngx_http_acme_module.so", "usr/share/licenses/nginx-module-acme/COPYRIGHT" ], "AnalyzedBy": "apk" }, { "ID": "nginx-module-geoip@1.28.3-r1", "Name": "nginx-module-geoip", "Identifier": { "PURL": "pkg:apk/alpine/nginx-module-geoip@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "db1b1d0252bc58df" }, "Version": "1.28.3-r1", "Arch": "x86_64", "SrcName": "nginx-module-geoip", "SrcVersion": "1.28.3-r1", "Licenses": [ "2-clause", "BSD-3-Clause", "license" ], "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "geoip@1.6.12-r6", "musl@1.2.5-r21", "nginx@1.28.3-r1" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:bacb3265dfe077670e913138a0c21da9fb929d90", "InstalledFiles": [ "usr/lib/nginx/modules/ngx_http_geoip_module-debug.so", "usr/lib/nginx/modules/ngx_http_geoip_module.so", "usr/lib/nginx/modules/ngx_stream_geoip_module-debug.so", "usr/lib/nginx/modules/ngx_stream_geoip_module.so", "usr/share/licenses/nginx-module-geoip/COPYRIGHT" ], "AnalyzedBy": "apk" }, { "ID": "nginx-module-image-filter@1.28.3-r1", "Name": "nginx-module-image-filter", "Identifier": { "PURL": "pkg:apk/alpine/nginx-module-image-filter@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "d51155adfd3ac0fa" }, "Version": "1.28.3-r1", "Arch": "x86_64", "SrcName": "nginx-module-image-filter", "SrcVersion": "1.28.3-r1", "Licenses": [ "2-clause", "BSD-3-Clause", "license" ], "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "libgd@2.3.3-r10", "musl@1.2.5-r21", "nginx@1.28.3-r1" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:60b0b0c575765646982023c66f7bb95ad4670307", "InstalledFiles": [ "usr/lib/nginx/modules/ngx_http_image_filter_module-debug.so", "usr/lib/nginx/modules/ngx_http_image_filter_module.so", "usr/share/licenses/nginx-module-image-filter/COPYRIGHT" ], "AnalyzedBy": "apk" }, { "ID": "nginx-module-njs@1.28.3.0.9.6-r1", "Name": "nginx-module-njs", "Identifier": { "PURL": "pkg:apk/alpine/nginx-module-njs@1.28.3.0.9.6-r1?arch=x86_64\u0026distro=3.23.3", "UID": "f336ec3ee9c2ec8f" }, "Version": "1.28.3.0.9.6-r1", "Arch": "x86_64", "SrcName": "nginx-module-njs", "SrcVersion": "1.28.3.0.9.6-r1", "Licenses": [ "2-clause", "BSD-3-Clause", "license" ], "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "libcrypto3@3.5.5-r0", "libedit@20251016.3.1-r0", "libxml2@2.13.9-r0", "musl@1.2.5-r21", "nginx@1.28.3-r1", "pcre2@10.47-r0", "zlib@1.3.1-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:a24eaada9c23702c483244875e7336738bc5a815", "InstalledFiles": [ "usr/bin/njs", "usr/lib/nginx/modules/ngx_http_js_module-debug.so", "usr/lib/nginx/modules/ngx_http_js_module.so", "usr/lib/nginx/modules/ngx_stream_js_module-debug.so", "usr/lib/nginx/modules/ngx_stream_js_module.so", "usr/share/doc/nginx-module-njs/CHANGES", "usr/share/licenses/nginx-module-njs/COPYRIGHT" ], "AnalyzedBy": "apk" }, { "ID": "nginx-module-xslt@1.28.3-r1", "Name": "nginx-module-xslt", "Identifier": { "PURL": "pkg:apk/alpine/nginx-module-xslt@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "4c6b1502eaa20cef" }, "Version": "1.28.3-r1", "Arch": "x86_64", "SrcName": "nginx-module-xslt", "SrcVersion": "1.28.3-r1", "Licenses": [ "2-clause", "BSD-3-Clause", "license" ], "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", "DependsOn": [ "busybox-binsh@1.37.0-r30", "libxml2@2.13.9-r0", "libxslt@1.1.43-r3", "musl@1.2.5-r21", "nginx@1.28.3-r1" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:0e3a923995439eea4163e4d6b8f80a5748ef2bdb", "InstalledFiles": [ "usr/lib/nginx/modules/ngx_http_xslt_filter_module-debug.so", "usr/lib/nginx/modules/ngx_http_xslt_filter_module.so", "usr/share/licenses/nginx-module-xslt/COPYRIGHT" ], "AnalyzedBy": "apk" }, { "ID": "pcre2@10.47-r0", "Name": "pcre2", "Identifier": { "PURL": "pkg:apk/alpine/pcre2@10.47-r0?arch=x86_64\u0026distro=3.23.3", "UID": "84da847bec967f4e" }, "Version": "10.47-r0", "Arch": "x86_64", "SrcName": "pcre2", "SrcVersion": "10.47-r0", "Licenses": [ "BSD-3-Clause" ], "Maintainer": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "Digest": "sha1:549059958151627bb0f5469bded945988b1bc24b", "InstalledFiles": [ "usr/lib/libpcre2-8.so.0", "usr/lib/libpcre2-8.so.0.15.0", "usr/lib/libpcre2-posix.so.3", "usr/lib/libpcre2-posix.so.3.0.7" ], "AnalyzedBy": "apk" }, { "ID": "scanelf@1.3.8-r2", "Name": "scanelf", "Identifier": { "PURL": "pkg:apk/alpine/scanelf@1.3.8-r2?arch=x86_64\u0026distro=3.23.3", "UID": "948b35f6525ae462" }, "Version": "1.3.8-r2", "Arch": "x86_64", "SrcName": "pax-utils", "SrcVersion": "1.3.8-r2", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:6ea36dd44ef9f6364f0cdfabe09ea15d2fdbe229", "InstalledFiles": [ "usr/bin/scanelf" ], "AnalyzedBy": "apk" }, { "ID": "ssl_client@1.37.0-r30", "Name": "ssl_client", "Identifier": { "PURL": "pkg:apk/alpine/ssl_client@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", "UID": "260f15056a81cadb" }, "Version": "1.37.0-r30", "Arch": "x86_64", "SrcName": "busybox", "SrcVersion": "1.37.0-r30", "Licenses": [ "GPL-2.0-only" ], "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", "DependsOn": [ "libcrypto3@3.5.5-r0", "libssl3@3.5.5-r0", "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:5b6ec0939cfc9be47d9677a3152c547cc18b5edd", "InstalledFiles": [ "usr/bin/ssl_client" ], "AnalyzedBy": "apk" }, { "ID": "tiff@4.7.1-r0", "Name": "tiff", "Identifier": { "PURL": "pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64\u0026distro=3.23.3", "UID": "2726c1d2741c571e" }, "Version": "4.7.1-r0", "Arch": "x86_64", "SrcName": "tiff", "SrcVersion": "4.7.1-r0", "Licenses": [ "libtiff" ], "Maintainer": "Michael Mason \u003cms13sp@gmail.com\u003e", "DependsOn": [ "libjpeg-turbo@3.1.2-r0", "libwebp@1.6.0-r0", "musl@1.2.5-r21", "zlib@1.3.1-r2", "zstd-libs@1.5.7-r2" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:b92c3394d281f51345a9375da14f347b6c1619a6", "InstalledFiles": [ "usr/lib/libtiff.so.6", "usr/lib/libtiff.so.6.2.0" ], "AnalyzedBy": "apk" }, { "ID": "tzdata@2026a-r0", "Name": "tzdata", "Identifier": { "PURL": "pkg:apk/alpine/tzdata@2026a-r0?arch=x86_64\u0026distro=3.23.3", "UID": "a7ad329b0644c5d6" }, "Version": "2026a-r0", "Arch": "x86_64", "SrcName": "tzdata", "SrcVersion": "2026a-r0", "Licenses": [ "Public-Domain" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "Digest": "sha1:82f6ca3f827e313572fc0cd15bed4a040f7d515c", "InstalledFiles": [ "usr/share/zoneinfo/CET", "usr/share/zoneinfo/CST6CDT", "usr/share/zoneinfo/Cuba", "usr/share/zoneinfo/EET", "usr/share/zoneinfo/EST", "usr/share/zoneinfo/EST5EDT", "usr/share/zoneinfo/Egypt", "usr/share/zoneinfo/Eire", "usr/share/zoneinfo/Factory", "usr/share/zoneinfo/GB", "usr/share/zoneinfo/GB-Eire", "usr/share/zoneinfo/GMT", "usr/share/zoneinfo/GMT+0", "usr/share/zoneinfo/GMT-0", "usr/share/zoneinfo/GMT0", "usr/share/zoneinfo/Greenwich", "usr/share/zoneinfo/HST", "usr/share/zoneinfo/Hongkong", "usr/share/zoneinfo/Iceland", "usr/share/zoneinfo/Iran", "usr/share/zoneinfo/Israel", "usr/share/zoneinfo/Jamaica", "usr/share/zoneinfo/Japan", "usr/share/zoneinfo/Kwajalein", "usr/share/zoneinfo/Libya", "usr/share/zoneinfo/MET", "usr/share/zoneinfo/MST", "usr/share/zoneinfo/MST7MDT", "usr/share/zoneinfo/NZ", "usr/share/zoneinfo/NZ-CHAT", "usr/share/zoneinfo/Navajo", "usr/share/zoneinfo/PRC", "usr/share/zoneinfo/PST8PDT", "usr/share/zoneinfo/Poland", "usr/share/zoneinfo/Portugal", "usr/share/zoneinfo/ROC", "usr/share/zoneinfo/ROK", "usr/share/zoneinfo/Singapore", "usr/share/zoneinfo/Turkey", "usr/share/zoneinfo/UCT", "usr/share/zoneinfo/UTC", "usr/share/zoneinfo/Universal", "usr/share/zoneinfo/W-SU", "usr/share/zoneinfo/WET", "usr/share/zoneinfo/Zulu", "usr/share/zoneinfo/iso3166.tab", "usr/share/zoneinfo/leap-seconds.list", "usr/share/zoneinfo/posixrules", "usr/share/zoneinfo/zone.tab", "usr/share/zoneinfo/zone1970.tab", "usr/share/zoneinfo/Africa/Abidjan", "usr/share/zoneinfo/Africa/Accra", "usr/share/zoneinfo/Africa/Addis_Ababa", "usr/share/zoneinfo/Africa/Algiers", "usr/share/zoneinfo/Africa/Asmara", "usr/share/zoneinfo/Africa/Asmera", "usr/share/zoneinfo/Africa/Bamako", "usr/share/zoneinfo/Africa/Bangui", "usr/share/zoneinfo/Africa/Banjul", "usr/share/zoneinfo/Africa/Bissau", "usr/share/zoneinfo/Africa/Blantyre", "usr/share/zoneinfo/Africa/Brazzaville", "usr/share/zoneinfo/Africa/Bujumbura", "usr/share/zoneinfo/Africa/Cairo", "usr/share/zoneinfo/Africa/Casablanca", "usr/share/zoneinfo/Africa/Ceuta", "usr/share/zoneinfo/Africa/Conakry", "usr/share/zoneinfo/Africa/Dakar", "usr/share/zoneinfo/Africa/Dar_es_Salaam", "usr/share/zoneinfo/Africa/Djibouti", "usr/share/zoneinfo/Africa/Douala", "usr/share/zoneinfo/Africa/El_Aaiun", "usr/share/zoneinfo/Africa/Freetown", "usr/share/zoneinfo/Africa/Gaborone", "usr/share/zoneinfo/Africa/Harare", "usr/share/zoneinfo/Africa/Johannesburg", "usr/share/zoneinfo/Africa/Juba", "usr/share/zoneinfo/Africa/Kampala", "usr/share/zoneinfo/Africa/Khartoum", "usr/share/zoneinfo/Africa/Kigali", "usr/share/zoneinfo/Africa/Kinshasa", "usr/share/zoneinfo/Africa/Lagos", "usr/share/zoneinfo/Africa/Libreville", "usr/share/zoneinfo/Africa/Lome", "usr/share/zoneinfo/Africa/Luanda", "usr/share/zoneinfo/Africa/Lubumbashi", "usr/share/zoneinfo/Africa/Lusaka", "usr/share/zoneinfo/Africa/Malabo", "usr/share/zoneinfo/Africa/Maputo", "usr/share/zoneinfo/Africa/Maseru", "usr/share/zoneinfo/Africa/Mbabane", "usr/share/zoneinfo/Africa/Mogadishu", "usr/share/zoneinfo/Africa/Monrovia", "usr/share/zoneinfo/Africa/Nairobi", "usr/share/zoneinfo/Africa/Ndjamena", "usr/share/zoneinfo/Africa/Niamey", "usr/share/zoneinfo/Africa/Nouakchott", "usr/share/zoneinfo/Africa/Ouagadougou", "usr/share/zoneinfo/Africa/Porto-Novo", "usr/share/zoneinfo/Africa/Sao_Tome", "usr/share/zoneinfo/Africa/Timbuktu", "usr/share/zoneinfo/Africa/Tripoli", "usr/share/zoneinfo/Africa/Tunis", "usr/share/zoneinfo/Africa/Windhoek", "usr/share/zoneinfo/America/Adak", "usr/share/zoneinfo/America/Anchorage", "usr/share/zoneinfo/America/Anguilla", "usr/share/zoneinfo/America/Antigua", "usr/share/zoneinfo/America/Araguaina", "usr/share/zoneinfo/America/Aruba", "usr/share/zoneinfo/America/Asuncion", "usr/share/zoneinfo/America/Atikokan", "usr/share/zoneinfo/America/Atka", "usr/share/zoneinfo/America/Bahia", "usr/share/zoneinfo/America/Bahia_Banderas", "usr/share/zoneinfo/America/Barbados", "usr/share/zoneinfo/America/Belem", "usr/share/zoneinfo/America/Belize", "usr/share/zoneinfo/America/Blanc-Sablon", "usr/share/zoneinfo/America/Boa_Vista", "usr/share/zoneinfo/America/Bogota", "usr/share/zoneinfo/America/Boise", "usr/share/zoneinfo/America/Buenos_Aires", "usr/share/zoneinfo/America/Cambridge_Bay", "usr/share/zoneinfo/America/Campo_Grande", "usr/share/zoneinfo/America/Cancun", "usr/share/zoneinfo/America/Caracas", "usr/share/zoneinfo/America/Catamarca", "usr/share/zoneinfo/America/Cayenne", "usr/share/zoneinfo/America/Cayman", "usr/share/zoneinfo/America/Chicago", "usr/share/zoneinfo/America/Chihuahua", "usr/share/zoneinfo/America/Ciudad_Juarez", "usr/share/zoneinfo/America/Coral_Harbour", "usr/share/zoneinfo/America/Cordoba", "usr/share/zoneinfo/America/Costa_Rica", "usr/share/zoneinfo/America/Coyhaique", "usr/share/zoneinfo/America/Creston", "usr/share/zoneinfo/America/Cuiaba", "usr/share/zoneinfo/America/Curacao", "usr/share/zoneinfo/America/Danmarkshavn", "usr/share/zoneinfo/America/Dawson", "usr/share/zoneinfo/America/Dawson_Creek", "usr/share/zoneinfo/America/Denver", "usr/share/zoneinfo/America/Detroit", "usr/share/zoneinfo/America/Dominica", "usr/share/zoneinfo/America/Edmonton", "usr/share/zoneinfo/America/Eirunepe", "usr/share/zoneinfo/America/El_Salvador", "usr/share/zoneinfo/America/Ensenada", "usr/share/zoneinfo/America/Fort_Nelson", "usr/share/zoneinfo/America/Fort_Wayne", "usr/share/zoneinfo/America/Fortaleza", "usr/share/zoneinfo/America/Glace_Bay", "usr/share/zoneinfo/America/Godthab", "usr/share/zoneinfo/America/Goose_Bay", "usr/share/zoneinfo/America/Grand_Turk", "usr/share/zoneinfo/America/Grenada", "usr/share/zoneinfo/America/Guadeloupe", "usr/share/zoneinfo/America/Guatemala", "usr/share/zoneinfo/America/Guayaquil", "usr/share/zoneinfo/America/Guyana", "usr/share/zoneinfo/America/Halifax", "usr/share/zoneinfo/America/Havana", "usr/share/zoneinfo/America/Hermosillo", "usr/share/zoneinfo/America/Indianapolis", "usr/share/zoneinfo/America/Inuvik", "usr/share/zoneinfo/America/Iqaluit", "usr/share/zoneinfo/America/Jamaica", "usr/share/zoneinfo/America/Jujuy", "usr/share/zoneinfo/America/Juneau", "usr/share/zoneinfo/America/Knox_IN", "usr/share/zoneinfo/America/Kralendijk", "usr/share/zoneinfo/America/La_Paz", "usr/share/zoneinfo/America/Lima", "usr/share/zoneinfo/America/Los_Angeles", "usr/share/zoneinfo/America/Louisville", "usr/share/zoneinfo/America/Lower_Princes", "usr/share/zoneinfo/America/Maceio", "usr/share/zoneinfo/America/Managua", "usr/share/zoneinfo/America/Manaus", "usr/share/zoneinfo/America/Marigot", "usr/share/zoneinfo/America/Martinique", "usr/share/zoneinfo/America/Matamoros", "usr/share/zoneinfo/America/Mazatlan", "usr/share/zoneinfo/America/Mendoza", "usr/share/zoneinfo/America/Menominee", "usr/share/zoneinfo/America/Merida", "usr/share/zoneinfo/America/Metlakatla", "usr/share/zoneinfo/America/Mexico_City", "usr/share/zoneinfo/America/Miquelon", "usr/share/zoneinfo/America/Moncton", "usr/share/zoneinfo/America/Monterrey", "usr/share/zoneinfo/America/Montevideo", "usr/share/zoneinfo/America/Montreal", "usr/share/zoneinfo/America/Montserrat", "usr/share/zoneinfo/America/Nassau", "usr/share/zoneinfo/America/New_York", "usr/share/zoneinfo/America/Nipigon", "usr/share/zoneinfo/America/Nome", "usr/share/zoneinfo/America/Noronha", "usr/share/zoneinfo/America/Nuuk", "usr/share/zoneinfo/America/Ojinaga", "usr/share/zoneinfo/America/Panama", "usr/share/zoneinfo/America/Pangnirtung", "usr/share/zoneinfo/America/Paramaribo", "usr/share/zoneinfo/America/Phoenix", "usr/share/zoneinfo/America/Port-au-Prince", "usr/share/zoneinfo/America/Port_of_Spain", "usr/share/zoneinfo/America/Porto_Acre", "usr/share/zoneinfo/America/Porto_Velho", "usr/share/zoneinfo/America/Puerto_Rico", "usr/share/zoneinfo/America/Punta_Arenas", "usr/share/zoneinfo/America/Rainy_River", "usr/share/zoneinfo/America/Rankin_Inlet", "usr/share/zoneinfo/America/Recife", "usr/share/zoneinfo/America/Regina", "usr/share/zoneinfo/America/Resolute", "usr/share/zoneinfo/America/Rio_Branco", "usr/share/zoneinfo/America/Rosario", "usr/share/zoneinfo/America/Santa_Isabel", "usr/share/zoneinfo/America/Santarem", "usr/share/zoneinfo/America/Santiago", "usr/share/zoneinfo/America/Santo_Domingo", "usr/share/zoneinfo/America/Sao_Paulo", "usr/share/zoneinfo/America/Scoresbysund", "usr/share/zoneinfo/America/Shiprock", "usr/share/zoneinfo/America/Sitka", "usr/share/zoneinfo/America/St_Barthelemy", "usr/share/zoneinfo/America/St_Johns", "usr/share/zoneinfo/America/St_Kitts", "usr/share/zoneinfo/America/St_Lucia", "usr/share/zoneinfo/America/St_Thomas", "usr/share/zoneinfo/America/St_Vincent", "usr/share/zoneinfo/America/Swift_Current", "usr/share/zoneinfo/America/Tegucigalpa", "usr/share/zoneinfo/America/Thule", "usr/share/zoneinfo/America/Thunder_Bay", "usr/share/zoneinfo/America/Tijuana", "usr/share/zoneinfo/America/Toronto", "usr/share/zoneinfo/America/Tortola", "usr/share/zoneinfo/America/Vancouver", "usr/share/zoneinfo/America/Virgin", "usr/share/zoneinfo/America/Whitehorse", "usr/share/zoneinfo/America/Winnipeg", "usr/share/zoneinfo/America/Yakutat", "usr/share/zoneinfo/America/Yellowknife", "usr/share/zoneinfo/America/Argentina/Buenos_Aires", "usr/share/zoneinfo/America/Argentina/Catamarca", "usr/share/zoneinfo/America/Argentina/ComodRivadavia", "usr/share/zoneinfo/America/Argentina/Cordoba", "usr/share/zoneinfo/America/Argentina/Jujuy", "usr/share/zoneinfo/America/Argentina/La_Rioja", "usr/share/zoneinfo/America/Argentina/Mendoza", "usr/share/zoneinfo/America/Argentina/Rio_Gallegos", "usr/share/zoneinfo/America/Argentina/Salta", "usr/share/zoneinfo/America/Argentina/San_Juan", "usr/share/zoneinfo/America/Argentina/San_Luis", "usr/share/zoneinfo/America/Argentina/Tucuman", "usr/share/zoneinfo/America/Argentina/Ushuaia", "usr/share/zoneinfo/America/Indiana/Indianapolis", "usr/share/zoneinfo/America/Indiana/Knox", "usr/share/zoneinfo/America/Indiana/Marengo", "usr/share/zoneinfo/America/Indiana/Petersburg", "usr/share/zoneinfo/America/Indiana/Tell_City", "usr/share/zoneinfo/America/Indiana/Vevay", "usr/share/zoneinfo/America/Indiana/Vincennes", "usr/share/zoneinfo/America/Indiana/Winamac", "usr/share/zoneinfo/America/Kentucky/Louisville", "usr/share/zoneinfo/America/Kentucky/Monticello", "usr/share/zoneinfo/America/North_Dakota/Beulah", "usr/share/zoneinfo/America/North_Dakota/Center", "usr/share/zoneinfo/America/North_Dakota/New_Salem", "usr/share/zoneinfo/Antarctica/Casey", "usr/share/zoneinfo/Antarctica/Davis", "usr/share/zoneinfo/Antarctica/DumontDUrville", "usr/share/zoneinfo/Antarctica/Macquarie", "usr/share/zoneinfo/Antarctica/Mawson", "usr/share/zoneinfo/Antarctica/McMurdo", "usr/share/zoneinfo/Antarctica/Palmer", "usr/share/zoneinfo/Antarctica/Rothera", "usr/share/zoneinfo/Antarctica/South_Pole", "usr/share/zoneinfo/Antarctica/Syowa", "usr/share/zoneinfo/Antarctica/Troll", "usr/share/zoneinfo/Antarctica/Vostok", "usr/share/zoneinfo/Arctic/Longyearbyen", "usr/share/zoneinfo/Asia/Aden", "usr/share/zoneinfo/Asia/Almaty", "usr/share/zoneinfo/Asia/Amman", "usr/share/zoneinfo/Asia/Anadyr", "usr/share/zoneinfo/Asia/Aqtau", "usr/share/zoneinfo/Asia/Aqtobe", "usr/share/zoneinfo/Asia/Ashgabat", "usr/share/zoneinfo/Asia/Ashkhabad", "usr/share/zoneinfo/Asia/Atyrau", "usr/share/zoneinfo/Asia/Baghdad", "usr/share/zoneinfo/Asia/Bahrain", "usr/share/zoneinfo/Asia/Baku", "usr/share/zoneinfo/Asia/Bangkok", "usr/share/zoneinfo/Asia/Barnaul", "usr/share/zoneinfo/Asia/Beirut", "usr/share/zoneinfo/Asia/Bishkek", "usr/share/zoneinfo/Asia/Brunei", "usr/share/zoneinfo/Asia/Calcutta", "usr/share/zoneinfo/Asia/Chita", "usr/share/zoneinfo/Asia/Choibalsan", "usr/share/zoneinfo/Asia/Chongqing", "usr/share/zoneinfo/Asia/Chungking", "usr/share/zoneinfo/Asia/Colombo", "usr/share/zoneinfo/Asia/Dacca", "usr/share/zoneinfo/Asia/Damascus", "usr/share/zoneinfo/Asia/Dhaka", "usr/share/zoneinfo/Asia/Dili", "usr/share/zoneinfo/Asia/Dubai", "usr/share/zoneinfo/Asia/Dushanbe", "usr/share/zoneinfo/Asia/Famagusta", "usr/share/zoneinfo/Asia/Gaza", "usr/share/zoneinfo/Asia/Harbin", "usr/share/zoneinfo/Asia/Hebron", "usr/share/zoneinfo/Asia/Ho_Chi_Minh", "usr/share/zoneinfo/Asia/Hong_Kong", "usr/share/zoneinfo/Asia/Hovd", "usr/share/zoneinfo/Asia/Irkutsk", "usr/share/zoneinfo/Asia/Istanbul", "usr/share/zoneinfo/Asia/Jakarta", "usr/share/zoneinfo/Asia/Jayapura", "usr/share/zoneinfo/Asia/Jerusalem", "usr/share/zoneinfo/Asia/Kabul", "usr/share/zoneinfo/Asia/Kamchatka", "usr/share/zoneinfo/Asia/Karachi", "usr/share/zoneinfo/Asia/Kashgar", "usr/share/zoneinfo/Asia/Kathmandu", "usr/share/zoneinfo/Asia/Katmandu", "usr/share/zoneinfo/Asia/Khandyga", "usr/share/zoneinfo/Asia/Kolkata", "usr/share/zoneinfo/Asia/Krasnoyarsk", "usr/share/zoneinfo/Asia/Kuala_Lumpur", "usr/share/zoneinfo/Asia/Kuching", "usr/share/zoneinfo/Asia/Kuwait", "usr/share/zoneinfo/Asia/Macao", "usr/share/zoneinfo/Asia/Macau", "usr/share/zoneinfo/Asia/Magadan", "usr/share/zoneinfo/Asia/Makassar", "usr/share/zoneinfo/Asia/Manila", "usr/share/zoneinfo/Asia/Muscat", "usr/share/zoneinfo/Asia/Nicosia", "usr/share/zoneinfo/Asia/Novokuznetsk", "usr/share/zoneinfo/Asia/Novosibirsk", "usr/share/zoneinfo/Asia/Omsk", "usr/share/zoneinfo/Asia/Oral", "usr/share/zoneinfo/Asia/Phnom_Penh", "usr/share/zoneinfo/Asia/Pontianak", "usr/share/zoneinfo/Asia/Pyongyang", "usr/share/zoneinfo/Asia/Qatar", "usr/share/zoneinfo/Asia/Qostanay", "usr/share/zoneinfo/Asia/Qyzylorda", "usr/share/zoneinfo/Asia/Rangoon", "usr/share/zoneinfo/Asia/Riyadh", "usr/share/zoneinfo/Asia/Saigon", "usr/share/zoneinfo/Asia/Sakhalin", "usr/share/zoneinfo/Asia/Samarkand", "usr/share/zoneinfo/Asia/Seoul", "usr/share/zoneinfo/Asia/Shanghai", "usr/share/zoneinfo/Asia/Singapore", "usr/share/zoneinfo/Asia/Srednekolymsk", "usr/share/zoneinfo/Asia/Taipei", "usr/share/zoneinfo/Asia/Tashkent", "usr/share/zoneinfo/Asia/Tbilisi", "usr/share/zoneinfo/Asia/Tehran", "usr/share/zoneinfo/Asia/Tel_Aviv", "usr/share/zoneinfo/Asia/Thimbu", "usr/share/zoneinfo/Asia/Thimphu", "usr/share/zoneinfo/Asia/Tokyo", "usr/share/zoneinfo/Asia/Tomsk", "usr/share/zoneinfo/Asia/Ujung_Pandang", "usr/share/zoneinfo/Asia/Ulaanbaatar", "usr/share/zoneinfo/Asia/Ulan_Bator", "usr/share/zoneinfo/Asia/Urumqi", "usr/share/zoneinfo/Asia/Ust-Nera", "usr/share/zoneinfo/Asia/Vientiane", "usr/share/zoneinfo/Asia/Vladivostok", "usr/share/zoneinfo/Asia/Yakutsk", "usr/share/zoneinfo/Asia/Yangon", "usr/share/zoneinfo/Asia/Yekaterinburg", "usr/share/zoneinfo/Asia/Yerevan", "usr/share/zoneinfo/Atlantic/Azores", "usr/share/zoneinfo/Atlantic/Bermuda", "usr/share/zoneinfo/Atlantic/Canary", "usr/share/zoneinfo/Atlantic/Cape_Verde", "usr/share/zoneinfo/Atlantic/Faeroe", "usr/share/zoneinfo/Atlantic/Faroe", "usr/share/zoneinfo/Atlantic/Jan_Mayen", "usr/share/zoneinfo/Atlantic/Madeira", "usr/share/zoneinfo/Atlantic/Reykjavik", "usr/share/zoneinfo/Atlantic/South_Georgia", "usr/share/zoneinfo/Atlantic/St_Helena", "usr/share/zoneinfo/Atlantic/Stanley", "usr/share/zoneinfo/Australia/ACT", "usr/share/zoneinfo/Australia/Adelaide", "usr/share/zoneinfo/Australia/Brisbane", "usr/share/zoneinfo/Australia/Broken_Hill", "usr/share/zoneinfo/Australia/Canberra", "usr/share/zoneinfo/Australia/Currie", "usr/share/zoneinfo/Australia/Darwin", "usr/share/zoneinfo/Australia/Eucla", "usr/share/zoneinfo/Australia/Hobart", "usr/share/zoneinfo/Australia/LHI", "usr/share/zoneinfo/Australia/Lindeman", "usr/share/zoneinfo/Australia/Lord_Howe", "usr/share/zoneinfo/Australia/Melbourne", "usr/share/zoneinfo/Australia/NSW", "usr/share/zoneinfo/Australia/North", "usr/share/zoneinfo/Australia/Perth", "usr/share/zoneinfo/Australia/Queensland", "usr/share/zoneinfo/Australia/South", "usr/share/zoneinfo/Australia/Sydney", "usr/share/zoneinfo/Australia/Tasmania", "usr/share/zoneinfo/Australia/Victoria", "usr/share/zoneinfo/Australia/West", "usr/share/zoneinfo/Australia/Yancowinna", "usr/share/zoneinfo/Brazil/Acre", "usr/share/zoneinfo/Brazil/DeNoronha", "usr/share/zoneinfo/Brazil/East", "usr/share/zoneinfo/Brazil/West", "usr/share/zoneinfo/Canada/Atlantic", "usr/share/zoneinfo/Canada/Central", "usr/share/zoneinfo/Canada/Eastern", "usr/share/zoneinfo/Canada/Mountain", "usr/share/zoneinfo/Canada/Newfoundland", "usr/share/zoneinfo/Canada/Pacific", "usr/share/zoneinfo/Canada/Saskatchewan", "usr/share/zoneinfo/Canada/Yukon", "usr/share/zoneinfo/Chile/Continental", "usr/share/zoneinfo/Chile/EasterIsland", "usr/share/zoneinfo/Etc/GMT", "usr/share/zoneinfo/Etc/GMT+0", "usr/share/zoneinfo/Etc/GMT+1", "usr/share/zoneinfo/Etc/GMT+10", "usr/share/zoneinfo/Etc/GMT+11", "usr/share/zoneinfo/Etc/GMT+12", "usr/share/zoneinfo/Etc/GMT+2", "usr/share/zoneinfo/Etc/GMT+3", "usr/share/zoneinfo/Etc/GMT+4", "usr/share/zoneinfo/Etc/GMT+5", "usr/share/zoneinfo/Etc/GMT+6", "usr/share/zoneinfo/Etc/GMT+7", "usr/share/zoneinfo/Etc/GMT+8", "usr/share/zoneinfo/Etc/GMT+9", "usr/share/zoneinfo/Etc/GMT-0", "usr/share/zoneinfo/Etc/GMT-1", "usr/share/zoneinfo/Etc/GMT-10", "usr/share/zoneinfo/Etc/GMT-11", "usr/share/zoneinfo/Etc/GMT-12", "usr/share/zoneinfo/Etc/GMT-13", "usr/share/zoneinfo/Etc/GMT-14", "usr/share/zoneinfo/Etc/GMT-2", "usr/share/zoneinfo/Etc/GMT-3", "usr/share/zoneinfo/Etc/GMT-4", "usr/share/zoneinfo/Etc/GMT-5", "usr/share/zoneinfo/Etc/GMT-6", "usr/share/zoneinfo/Etc/GMT-7", "usr/share/zoneinfo/Etc/GMT-8", "usr/share/zoneinfo/Etc/GMT-9", "usr/share/zoneinfo/Etc/GMT0", "usr/share/zoneinfo/Etc/Greenwich", "usr/share/zoneinfo/Etc/UCT", "usr/share/zoneinfo/Etc/UTC", "usr/share/zoneinfo/Etc/Universal", "usr/share/zoneinfo/Etc/Zulu", "usr/share/zoneinfo/Europe/Amsterdam", "usr/share/zoneinfo/Europe/Andorra", "usr/share/zoneinfo/Europe/Astrakhan", "usr/share/zoneinfo/Europe/Athens", "usr/share/zoneinfo/Europe/Belfast", "usr/share/zoneinfo/Europe/Belgrade", "usr/share/zoneinfo/Europe/Berlin", "usr/share/zoneinfo/Europe/Bratislava", "usr/share/zoneinfo/Europe/Brussels", "usr/share/zoneinfo/Europe/Bucharest", "usr/share/zoneinfo/Europe/Budapest", "usr/share/zoneinfo/Europe/Busingen", "usr/share/zoneinfo/Europe/Chisinau", "usr/share/zoneinfo/Europe/Copenhagen", "usr/share/zoneinfo/Europe/Dublin", "usr/share/zoneinfo/Europe/Gibraltar", "usr/share/zoneinfo/Europe/Guernsey", "usr/share/zoneinfo/Europe/Helsinki", "usr/share/zoneinfo/Europe/Isle_of_Man", "usr/share/zoneinfo/Europe/Istanbul", "usr/share/zoneinfo/Europe/Jersey", "usr/share/zoneinfo/Europe/Kaliningrad", "usr/share/zoneinfo/Europe/Kiev", "usr/share/zoneinfo/Europe/Kirov", "usr/share/zoneinfo/Europe/Kyiv", "usr/share/zoneinfo/Europe/Lisbon", "usr/share/zoneinfo/Europe/Ljubljana", "usr/share/zoneinfo/Europe/London", "usr/share/zoneinfo/Europe/Luxembourg", "usr/share/zoneinfo/Europe/Madrid", "usr/share/zoneinfo/Europe/Malta", "usr/share/zoneinfo/Europe/Mariehamn", "usr/share/zoneinfo/Europe/Minsk", "usr/share/zoneinfo/Europe/Monaco", "usr/share/zoneinfo/Europe/Moscow", "usr/share/zoneinfo/Europe/Nicosia", "usr/share/zoneinfo/Europe/Oslo", "usr/share/zoneinfo/Europe/Paris", "usr/share/zoneinfo/Europe/Podgorica", "usr/share/zoneinfo/Europe/Prague", "usr/share/zoneinfo/Europe/Riga", "usr/share/zoneinfo/Europe/Rome", "usr/share/zoneinfo/Europe/Samara", "usr/share/zoneinfo/Europe/San_Marino", "usr/share/zoneinfo/Europe/Sarajevo", "usr/share/zoneinfo/Europe/Saratov", "usr/share/zoneinfo/Europe/Simferopol", "usr/share/zoneinfo/Europe/Skopje", "usr/share/zoneinfo/Europe/Sofia", "usr/share/zoneinfo/Europe/Stockholm", "usr/share/zoneinfo/Europe/Tallinn", "usr/share/zoneinfo/Europe/Tirane", "usr/share/zoneinfo/Europe/Tiraspol", "usr/share/zoneinfo/Europe/Ulyanovsk", "usr/share/zoneinfo/Europe/Uzhgorod", "usr/share/zoneinfo/Europe/Vaduz", "usr/share/zoneinfo/Europe/Vatican", "usr/share/zoneinfo/Europe/Vienna", "usr/share/zoneinfo/Europe/Vilnius", "usr/share/zoneinfo/Europe/Volgograd", "usr/share/zoneinfo/Europe/Warsaw", "usr/share/zoneinfo/Europe/Zagreb", "usr/share/zoneinfo/Europe/Zaporozhye", "usr/share/zoneinfo/Europe/Zurich", "usr/share/zoneinfo/Indian/Antananarivo", "usr/share/zoneinfo/Indian/Chagos", "usr/share/zoneinfo/Indian/Christmas", "usr/share/zoneinfo/Indian/Cocos", "usr/share/zoneinfo/Indian/Comoro", "usr/share/zoneinfo/Indian/Kerguelen", "usr/share/zoneinfo/Indian/Mahe", "usr/share/zoneinfo/Indian/Maldives", "usr/share/zoneinfo/Indian/Mauritius", "usr/share/zoneinfo/Indian/Mayotte", "usr/share/zoneinfo/Indian/Reunion", "usr/share/zoneinfo/Mexico/BajaNorte", "usr/share/zoneinfo/Mexico/BajaSur", "usr/share/zoneinfo/Mexico/General", "usr/share/zoneinfo/Pacific/Apia", "usr/share/zoneinfo/Pacific/Auckland", "usr/share/zoneinfo/Pacific/Bougainville", "usr/share/zoneinfo/Pacific/Chatham", "usr/share/zoneinfo/Pacific/Chuuk", "usr/share/zoneinfo/Pacific/Easter", "usr/share/zoneinfo/Pacific/Efate", "usr/share/zoneinfo/Pacific/Enderbury", "usr/share/zoneinfo/Pacific/Fakaofo", "usr/share/zoneinfo/Pacific/Fiji", "usr/share/zoneinfo/Pacific/Funafuti", "usr/share/zoneinfo/Pacific/Galapagos", "usr/share/zoneinfo/Pacific/Gambier", "usr/share/zoneinfo/Pacific/Guadalcanal", "usr/share/zoneinfo/Pacific/Guam", "usr/share/zoneinfo/Pacific/Honolulu", "usr/share/zoneinfo/Pacific/Johnston", "usr/share/zoneinfo/Pacific/Kanton", "usr/share/zoneinfo/Pacific/Kiritimati", "usr/share/zoneinfo/Pacific/Kosrae", "usr/share/zoneinfo/Pacific/Kwajalein", "usr/share/zoneinfo/Pacific/Majuro", "usr/share/zoneinfo/Pacific/Marquesas", "usr/share/zoneinfo/Pacific/Midway", "usr/share/zoneinfo/Pacific/Nauru", "usr/share/zoneinfo/Pacific/Niue", "usr/share/zoneinfo/Pacific/Norfolk", "usr/share/zoneinfo/Pacific/Noumea", "usr/share/zoneinfo/Pacific/Pago_Pago", "usr/share/zoneinfo/Pacific/Palau", "usr/share/zoneinfo/Pacific/Pitcairn", "usr/share/zoneinfo/Pacific/Pohnpei", "usr/share/zoneinfo/Pacific/Ponape", "usr/share/zoneinfo/Pacific/Port_Moresby", "usr/share/zoneinfo/Pacific/Rarotonga", "usr/share/zoneinfo/Pacific/Saipan", "usr/share/zoneinfo/Pacific/Samoa", "usr/share/zoneinfo/Pacific/Tahiti", "usr/share/zoneinfo/Pacific/Tarawa", "usr/share/zoneinfo/Pacific/Tongatapu", "usr/share/zoneinfo/Pacific/Truk", "usr/share/zoneinfo/Pacific/Wake", "usr/share/zoneinfo/Pacific/Wallis", "usr/share/zoneinfo/Pacific/Yap", "usr/share/zoneinfo/US/Alaska", "usr/share/zoneinfo/US/Aleutian", "usr/share/zoneinfo/US/Arizona", "usr/share/zoneinfo/US/Central", "usr/share/zoneinfo/US/East-Indiana", "usr/share/zoneinfo/US/Eastern", "usr/share/zoneinfo/US/Hawaii", "usr/share/zoneinfo/US/Indiana-Starke", "usr/share/zoneinfo/US/Michigan", "usr/share/zoneinfo/US/Mountain", "usr/share/zoneinfo/US/Pacific", "usr/share/zoneinfo/US/Samoa" ], "AnalyzedBy": "apk" }, { "ID": "xz-libs@5.8.2-r0", "Name": "xz-libs", "Identifier": { "PURL": "pkg:apk/alpine/xz-libs@5.8.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "3c1589b6a5aafd51" }, "Version": "5.8.2-r0", "Arch": "x86_64", "SrcName": "xz", "SrcVersion": "5.8.2-r0", "Licenses": [ "GPL-2.0-or-later", "0BSD", "Public-Domain", "LGPL-2.1-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:d3eb4807f74650a151b4463266ecd1b507f3c49f", "InstalledFiles": [ "usr/lib/liblzma.so.5", "usr/lib/liblzma.so.5.8.2" ], "AnalyzedBy": "apk" }, { "ID": "zlib@1.3.1-r2", "Name": "zlib", "Identifier": { "PURL": "pkg:apk/alpine/zlib@1.3.1-r2?arch=x86_64\u0026distro=3.23.3", "UID": "792cdc69bc59d880" }, "Version": "1.3.1-r2", "Arch": "x86_64", "SrcName": "zlib", "SrcVersion": "1.3.1-r2", "Licenses": [ "Zlib" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "Digest": "sha1:3e8e8e76dfefb4efd27658ada6d792e66ba2775e", "InstalledFiles": [ "usr/lib/libz.so.1", "usr/lib/libz.so.1.3.1" ], "AnalyzedBy": "apk" }, { "ID": "zstd-libs@1.5.7-r2", "Name": "zstd-libs", "Identifier": { "PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.23.3", "UID": "8146f1dd71a6e601" }, "Version": "1.5.7-r2", "Arch": "x86_64", "SrcName": "zstd", "SrcVersion": "1.5.7-r2", "Licenses": [ "BSD-3-Clause", "GPL-2.0-or-later" ], "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", "DependsOn": [ "musl@1.2.5-r21" ], "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "Digest": "sha1:d507b8ac3c4335a40405ac20e49bac9d43642be6", "InstalledFiles": [ "usr/lib/libzstd.so.1", "usr/lib/libzstd.so.1.5.7" ], "AnalyzedBy": "apk" } ], "Vulnerabilities": [ { "VulnerabilityID": "CVE-2026-33630", "PkgID": "c-ares@1.34.6-r0", "PkgName": "c-ares", "PkgIdentifier": { "PURL": "pkg:apk/alpine/c-ares@1.34.6-r0?arch=x86_64\u0026distro=3.23.3", "UID": "2fc69dd6afab16ae" }, "InstalledVersion": "1.34.6-r0", "FixedVersion": "1.34.8-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33630", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:d9285fd73f7e1ba4205068c1a17a3c88a2207aa83fe9dc1a5ee265912dd88d0b", "Title": "c-ares: c-ares: Use-after-free / double-free in query-completion handling", "Description": "c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.", "Severity": "HIGH", "CweIDs": [ "CWE-415", "CWE-416" ], "VendorSeverity": { "alma": 3, "amazon": 3, "oracle-oval": 3, "redhat": 3, "rocky": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:42096", "https://access.redhat.com/security/cve/CVE-2026-33630", "https://bugzilla.redhat.com/2497686", "https://bugzilla.redhat.com/show_bug.cgi?id=2497686", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33630", "https://errata.almalinux.org/10/ALSA-2026-42096.html", "https://errata.rockylinux.org/RLSA-2026:42096", "https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc", "https://github.com/c-ares/c-ares/commit/d823199b688052dcdc1646f2ab4cb8c16b1c644a", "https://github.com/c-ares/c-ares/pull/1237", "https://github.com/c-ares/c-ares/releases/tag/v1.34.7", "https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542", "https://linux.oracle.com/cve/CVE-2026-33630.html", "https://linux.oracle.com/errata/ELSA-2026-42096.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-33630", "https://www.cve.org/CVERecord?id=CVE-2026-33630" ], "PublishedDate": "2026-09-03T19:17:27.42Z", "LastModifiedDate": "2026-09-09T21:09:13.08Z" }, { "VulnerabilityID": "CVE-2026-11352", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11352", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:c5a7996455e5abe2f73f0bc9cfd31708f763449a7ca938a4958bca6ab1b659ec", "Title": "curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability", "Description": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.", "Severity": "HIGH", "CweIDs": [ "CWE-835" ], "VendorSeverity": { "julia": 3, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-11352", "https://curl.se/L7HzKXisfJ/CVE-2026-11352.md", "https://curl.se/docs/CVE-2026-11352.html", "https://curl.se/docs/CVE-2026-11352.json", "https://github.com/advisories/GHSA-qxwx-hr5v-h5q4", "https://hackerone.com/reports/3783438", "https://nvd.nist.gov/vuln/detail/CVE-2026-11352", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-11352" ], "PublishedDate": "2026-07-03T07:16:23.693Z", "LastModifiedDate": "2026-09-15T07:16:25.353Z" }, { "VulnerabilityID": "CVE-2026-11586", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11586", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:bc7b43b547a2565b4607dc3593d90e2a9bc8360f6b27b3286ac7b4d7b20c68c3", "Title": "curl: curl: Denial of Service via WebSocket PING flood", "Description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "amazon": 2, "julia": 3, "photon": 3, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-11586", "https://curl.se/L7HzKXisfJ/CVE-2026-11586.md", "https://curl.se/docs/CVE-2026-11586.html", "https://curl.se/docs/CVE-2026-11586.json", "https://github.com/advisories/GHSA-c68q-h477-5646", "https://hackerone.com/reports/3788931", "https://nvd.nist.gov/vuln/detail/CVE-2026-11586", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-11586" ], "PublishedDate": "2026-07-03T07:16:23.883Z", "LastModifiedDate": "2026-09-15T07:16:25.7Z" }, { "VulnerabilityID": "CVE-2026-12064", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-12064", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:793bbbf4ce77ae94363cb62edd580c9591a91f15bfb0e26fbd87e4075bbf47e7", "Title": "curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP", "Description": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.", "Severity": "HIGH", "CweIDs": [ "CWE-297", "CWE-295" ], "VendorSeverity": { "amazon": 2, "azure": 3, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-12064", "https://curl.se/L7HzKXisfJ/CVE-2026-12064.md", "https://curl.se/docs/CVE-2026-12064.html", "https://curl.se/docs/CVE-2026-12064.json", "https://github.com/advisories/GHSA-jm94-9f7h-36pr", "https://hackerone.com/reports/3797526", "https://linux.oracle.com/cve/CVE-2026-12064.html", "https://linux.oracle.com/errata/ELSA-2026-55450.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-12064", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-12064" ], "PublishedDate": "2026-07-03T07:16:24.217Z", "LastModifiedDate": "2026-09-15T07:16:26.15Z" }, { "VulnerabilityID": "CVE-2026-5773", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.20.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-5773", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:1acc9c31ac9ea826f308e75b534e8333b6fb5a4e5cd6aae6a71c691b06a79924", "Title": "curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse", "Description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.", "Severity": "HIGH", "CweIDs": [ "CWE-488", "CWE-918" ], "VendorSeverity": { "julia": 3, "nvd": 3, "photon": 3, "redhat": 2, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "V3Score": 6.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/04/29/9", "https://access.redhat.com/security/cve/CVE-2026-5773", "https://curl.se/docs/CVE-2026-5773.html", "https://curl.se/docs/CVE-2026-5773.json", "https://github.com/advisories/GHSA-rp9q-8q5w-ch44", "https://hackerone.com/reports/3650689", "https://nvd.nist.gov/vuln/detail/CVE-2026-5773", "https://ubuntu.com/security/notices/USN-8227-1", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-5773" ], "PublishedDate": "2026-05-13T13:01:56.307Z", "LastModifiedDate": "2026-09-15T07:16:28.82Z" }, { "VulnerabilityID": "CVE-2026-6276", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.20.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-6276", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:bb1da73213b0678dacf9c6d1fbb816aacac82d9b2c5d0fdbcf8c84e6d1cee38d", "Title": "curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers", "Description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.", "Severity": "HIGH", "CweIDs": [ "CWE-346", "CWE-319" ], "VendorSeverity": { "azure": 2, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "V3Score": 3.7 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/04/29/13", "https://access.redhat.com/security/cve/CVE-2026-6276", "https://curl.se/docs/CVE-2026-6276.html", "https://curl.se/docs/CVE-2026-6276.json", "https://github.com/advisories/GHSA-2jc6-hc33-hv48", "https://hackerone.com/reports/3671818", "https://nvd.nist.gov/vuln/detail/CVE-2026-6276", "https://ubuntu.com/security/notices/USN-8227-1", "https://www.cve.org/CVERecord?id=CVE-2026-6276" ], "PublishedDate": "2026-05-13T13:01:56.8Z", "LastModifiedDate": "2026-09-15T07:16:29.343Z" }, { "VulnerabilityID": "CVE-2026-8286", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8286", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:6441208109db6f17f86e53be7856b8f45aecbef9792b49f40fff0f9dc980d5c5", "Title": "curl: curl: Insecure connection establishment due to TLS configuration mismatch", "Description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.", "Severity": "HIGH", "CweIDs": [ "CWE-295" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 3, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "V3Score": 8.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:55439", "https://access.redhat.com/errata/RHSA-2026:57462", "https://access.redhat.com/security/cve/CVE-2026-8286", "https://bugzilla.redhat.com/2496763", "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", "https://creativecommons.org/licenses/by/4.0/", "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md", "https://curl.se/docs/CVE-2026-8286.html", "https://curl.se/docs/CVE-2026-8286.json", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", "https://errata.almalinux.org/8/ALSA-2026-57462.html", "https://errata.rockylinux.org/RLSA-2026:55439", "https://github.com/advisories/GHSA-32xh-3x3c-6g6h", "https://hackerone.com/reports/3718195", "https://linux.oracle.com/cve/CVE-2026-8286.html", "https://linux.oracle.com/errata/ELSA-2026-57462.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-8286", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8286" ], "PublishedDate": "2026-07-03T07:16:24.453Z", "LastModifiedDate": "2026-09-15T07:16:31.617Z" }, { "VulnerabilityID": "CVE-2026-8458", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8458", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:de0928ee55bf721148ed577b0e2e717084dcd109e80d479e2248f2a8ccabbaab", "Title": "curl: libcurl: Unauthorized connection reuse due to a logical error", "Description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.", "Severity": "HIGH", "CweIDs": [ "CWE-488" ], "VendorSeverity": { "amazon": 2, "azure": 2, "julia": 2, "photon": 2, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "V3Score": 6.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-8458", "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md", "https://curl.se/docs/CVE-2026-8458.html", "https://curl.se/docs/CVE-2026-8458.json", "https://github.com/advisories/GHSA-88c6-6jfq-mm4q", "https://hackerone.com/reports/3721183", "https://nvd.nist.gov/vuln/detail/CVE-2026-8458", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8458" ], "PublishedDate": "2026-07-03T07:16:24.63Z", "LastModifiedDate": "2026-09-15T07:16:32.327Z" }, { "VulnerabilityID": "CVE-2026-8925", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8925", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:908932d0c505f02e788f0f48b293fb356087e87e1e0015ef5a5c06b6d60f1730", "Title": "curl: curl: Double-free vulnerability in SASL authentication", "Description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.", "Severity": "HIGH", "CweIDs": [ "CWE-415" ], "VendorSeverity": { "amazon": 2, "julia": 4, "photon": 4, "redhat": 3, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 9.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-8925", "https://curl.se/L7HzKXisfJ/CVE-2026-8925.md", "https://curl.se/docs/CVE-2026-8925.html", "https://curl.se/docs/CVE-2026-8925.json", "https://github.com/advisories/GHSA-p8x5-c6c9-8cwx", "https://hackerone.com/reports/3735193", "https://nvd.nist.gov/vuln/detail/CVE-2026-8925", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8925" ], "PublishedDate": "2026-07-03T07:16:24.95Z", "LastModifiedDate": "2026-09-15T07:16:32.8Z" }, { "VulnerabilityID": "CVE-2026-8927", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8927", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:b158f4cf7def44df3301af1431f24ec3c72e83ce08484944a0fceccf30937d10", "Title": "curl: Information disclosure due to uncleared proxy authentication state", "Description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.", "Severity": "HIGH", "CweIDs": [ "CWE-294" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 2, "julia": 4, "oracle-oval": 3, "photon": 4, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 9.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:55432", "https://access.redhat.com/security/cve/CVE-2026-8927", "https://bugzilla.redhat.com/2496769", "https://bugzilla.redhat.com/show_bug.cgi?id=2496769", "https://creativecommons.org/licenses/by/4.0/", "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md", "https://curl.se/docs/CVE-2026-8927.html", "https://curl.se/docs/CVE-2026-8927.json", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927", "https://errata.almalinux.org/10/ALSA-2026-55432.html", "https://errata.rockylinux.org/RLSA-2026:55432", "https://github.com/advisories/GHSA-jr4f-4564-w3mr", "https://hackerone.com/reports/3744543", "https://linux.oracle.com/cve/CVE-2026-8927.html", "https://linux.oracle.com/errata/ELSA-2026-55432.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-8927", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8927" ], "PublishedDate": "2026-07-03T07:16:25.123Z", "LastModifiedDate": "2026-09-15T07:16:33.157Z" }, { "VulnerabilityID": "CVE-2026-9547", "PkgID": "curl@8.17.0-r1", "PkgName": "curl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "c4e4a99c2363a971" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9547", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:1cafe58ac3ef9667652d91660e01a5fed38fba86ecdc8954932bd47f8092230c", "Title": "curl: curl: Man-in-the-middle attack via SSH host key bypass", "Description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.", "Severity": "HIGH", "CweIDs": [ "CWE-297" ], "VendorSeverity": { "alma": 3, "amazon": 2, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 7.4 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 7.4 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:55439", "https://access.redhat.com/security/cve/CVE-2026-9547", "https://bugzilla.redhat.com/2446448", "https://bugzilla.redhat.com/2446450", "https://bugzilla.redhat.com/2496758", "https://bugzilla.redhat.com/2496763", "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", "https://creativecommons.org/licenses/by/4.0/", "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md", "https://curl.se/docs/CVE-2026-9547.html", "https://curl.se/docs/CVE-2026-9547.json", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", "https://errata.almalinux.org/9/ALSA-2026-55439.html", "https://errata.rockylinux.org/RLSA-2026:55439", "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6", "https://hackerone.com/reports/3751712", "https://linux.oracle.com/cve/CVE-2026-9547.html", "https://linux.oracle.com/errata/ELSA-2026-55450.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-9547", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-9547" ], "PublishedDate": "2026-07-03T07:16:25.99Z", "LastModifiedDate": "2026-09-15T07:16:35.31Z" }, { "VulnerabilityID": "CVE-2026-31789", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31789", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:7bf2c442a9419b41bc691833b980d4fa12130e8b82d1207c4ae76f2f8be6e8f4", "Title": "openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing", "Description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "CRITICAL", "CweIDs": [ "CWE-787" ], "VendorSeverity": { "azure": 2, "julia": 4, "nvd": 4, "photon": 4, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 9.8 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 9.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", "V3Score": 5.8 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-31789", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://github.com/advisories/GHSA-j79m-9jxq-788r", "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde", "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf", "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49", "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9", "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521", "https://nvd.nist.gov/vuln/detail/CVE-2026-31789", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://www.cve.org/CVERecord?id=CVE-2026-31789", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:21.617Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-14456", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.8-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:8507d921256f647a5b9079077494639909fd9e3b51749200c7f9400293e2d105", "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "amazon": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/08/13/4", "https://access.redhat.com/security/cve/CVE-2026-14456", "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", "https://linux.oracle.com/cve/CVE-2026-14456.html", "https://linux.oracle.com/errata/ELSA-2026-67165-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", "https://openssl-library.org/news/secadv/20260813.txt", "https://ubuntu.com/security/notices/USN-8678-1", "https://www.cve.org/CVERecord?id=CVE-2026-14456" ], "PublishedDate": "2026-08-13T15:19:31.82Z", "LastModifiedDate": "2026-08-28T19:46:29.323Z" }, { "VulnerabilityID": "CVE-2026-28387", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28387", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:b0190ab2642810a6089f1ff172803c0e42d45e8efc211805b891e5d7e36abcd2", "Title": "openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication", "Description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages. These SMTP (or other similar) clients are not vulnerable\nto this issue. Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-416" ], "VendorSeverity": { "amazon": 3, "azure": 1, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "V3Score": 3.7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-28387", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b", "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe", "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3", "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7", "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177", "https://nvd.nist.gov/vuln/detail/CVE-2026-28387", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28387", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:20.7Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-28388", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28388", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:a645fcf6ec5bc8a2ef3da2e32ac68d75ea181be65a5f4f5e15bb7bfe8ca93365", "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing", "Description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "amazon": 3, "azure": 2, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-28388", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e", "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139", "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3", "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8", "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726", "https://nvd.nist.gov/vuln/detail/CVE-2026-28388", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28388", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:20.863Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-28389", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28389", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:496ad76e8296a02bab42c4a14de6182a3630367e087d8a9f8ccadccb29fffc54", "Title": "openssl: OpenSSL: Denial of Service vulnerability in CMS processing", "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "amazon": 3, "azure": 2, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-28389", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://github.com/advisories/GHSA-7x88-9hgc-69gf", "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5", "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616", "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f", "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a", "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686", "https://nvd.nist.gov/vuln/detail/CVE-2026-28389", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28389", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:21.03Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-28390", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28390", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:70c833c28a24a3236952fc029c28e1723c2ef84fd1df3e2ea5664be91e746d48", "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing", "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "alma": 2, "amazon": 3, "azure": 2, "julia": 3, "nvd": 3, "oracle-oval": 2, "photon": 3, "redhat": 2, "rocky": 2, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:22312", "https://access.redhat.com/errata/RHSA-2026:38503", "https://access.redhat.com/security/cve/CVE-2026-28390", "https://bugzilla.redhat.com/2456314", "https://bugzilla.redhat.com/show_bug.cgi?id=2456314", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28390", "https://errata.almalinux.org/8/ALSA-2026-38503.html", "https://errata.rockylinux.org/RLSA-2026:22312", "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc", "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6", "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4", "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788", "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75", "https://linux.oracle.com/cve/CVE-2026-28390.html", "https://linux.oracle.com/errata/ELSA-2026-50345.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-28390", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28390", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:21.19Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-45447", "PkgID": "libcrypto3@3.5.5-r0", "PkgName": "libcrypto3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "6778a588f2cebd48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.7-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45447", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:1fac74a0b529ec2ff72d7655c158c79f473b9ad9cda7c663eaf580f5d269bf01", "Title": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()", "Description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-416", "CWE-825" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "julia": 3, "oracle-oval": 2, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 3 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:25237", "https://access.redhat.com/errata/RHSA-2026:25239", "https://access.redhat.com/errata/RHSA-2026:26275", "https://access.redhat.com/errata/RHSA-2026:26319", "https://access.redhat.com/errata/RHSA-2026:29197", "https://access.redhat.com/errata/RHSA-2026:34102", "https://access.redhat.com/errata/RHSA-2026:35869", "https://access.redhat.com/errata/RHSA-2026:36215", "https://access.redhat.com/errata/RHSA-2026:36217", "https://access.redhat.com/errata/RHSA-2026:39009", "https://access.redhat.com/errata/RHSA-2026:39012", "https://access.redhat.com/errata/RHSA-2026:39981", "https://access.redhat.com/errata/RHSA-2026:44438", "https://access.redhat.com/errata/RHSA-2026:47735", "https://access.redhat.com/errata/RHSA-2026:47737", "https://access.redhat.com/errata/RHSA-2026:58563", "https://access.redhat.com/errata/RHSA-2026:58981", "https://access.redhat.com/errata/RHSA-2026:59831", "https://access.redhat.com/errata/RHSA-2026:66524", "https://access.redhat.com/security/cve/CVE-2026-45447", "https://bugzilla.redhat.com/2481898", "https://bugzilla.redhat.com/show_bug.cgi?id=2481879", "https://bugzilla.redhat.com/show_bug.cgi?id=2481880", "https://bugzilla.redhat.com/show_bug.cgi?id=2481881", "https://bugzilla.redhat.com/show_bug.cgi?id=2481882", "https://bugzilla.redhat.com/show_bug.cgi?id=2481884", "https://bugzilla.redhat.com/show_bug.cgi?id=2481885", "https://bugzilla.redhat.com/show_bug.cgi?id=2481887", "https://bugzilla.redhat.com/show_bug.cgi?id=2481890", "https://bugzilla.redhat.com/show_bug.cgi?id=2481891", "https://bugzilla.redhat.com/show_bug.cgi?id=2481892", "https://bugzilla.redhat.com/show_bug.cgi?id=2481893", "https://bugzilla.redhat.com/show_bug.cgi?id=2481894", "https://bugzilla.redhat.com/show_bug.cgi?id=2481896", "https://bugzilla.redhat.com/show_bug.cgi?id=2481897", "https://bugzilla.redhat.com/show_bug.cgi?id=2481898", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076", "https://errata.almalinux.org/8/ALSA-2026-36215.html", "https://errata.rockylinux.org/RLSA-2026:25239", "https://github.com/advisories/GHSA-f684-cpcq-j565", "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", "https://github.com/openssl/security/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", "https://github.com/openssl/security/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", "https://github.com/openssl/security/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", "https://github.com/openssl/security/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", "https://github.com/openssl/security/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", "https://linux.oracle.com/cve/CVE-2026-45447.html", "https://linux.oracle.com/errata/ELSA-2026-50379.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-45447", "https://openssl-library.org/news/secadv/20260609.txt", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json", "https://ubuntu.com/security/notices/USN-8414-1", "https://ubuntu.com/security/notices/USN-8414-2", "https://www.cve.org/CVERecord?id=CVE-2026-45447" ], "PublishedDate": "2026-06-09T17:17:19.277Z", "LastModifiedDate": "2026-09-11T13:18:10.853Z" }, { "VulnerabilityID": "CVE-2026-11352", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11352", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:6f80d7483e4bd52959711d0c7172c0ed75361987e1606fc001619a48e5615ad0", "Title": "curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability", "Description": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.", "Severity": "HIGH", "CweIDs": [ "CWE-835" ], "VendorSeverity": { "julia": 3, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-11352", "https://curl.se/L7HzKXisfJ/CVE-2026-11352.md", "https://curl.se/docs/CVE-2026-11352.html", "https://curl.se/docs/CVE-2026-11352.json", "https://github.com/advisories/GHSA-qxwx-hr5v-h5q4", "https://hackerone.com/reports/3783438", "https://nvd.nist.gov/vuln/detail/CVE-2026-11352", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-11352" ], "PublishedDate": "2026-07-03T07:16:23.693Z", "LastModifiedDate": "2026-09-15T07:16:25.353Z" }, { "VulnerabilityID": "CVE-2026-11586", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11586", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:9adc54fad5fcbe0cb3f68ad1a8b876d9a29d938c9d3ca8318458114a5d4aceb5", "Title": "curl: curl: Denial of Service via WebSocket PING flood", "Description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "amazon": 2, "julia": 3, "photon": 3, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-11586", "https://curl.se/L7HzKXisfJ/CVE-2026-11586.md", "https://curl.se/docs/CVE-2026-11586.html", "https://curl.se/docs/CVE-2026-11586.json", "https://github.com/advisories/GHSA-c68q-h477-5646", "https://hackerone.com/reports/3788931", "https://nvd.nist.gov/vuln/detail/CVE-2026-11586", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-11586" ], "PublishedDate": "2026-07-03T07:16:23.883Z", "LastModifiedDate": "2026-09-15T07:16:25.7Z" }, { "VulnerabilityID": "CVE-2026-12064", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-12064", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:c75e1d44bf742f10d17a692714a5cac51f4729b0e8179b0513d7706cb9f85435", "Title": "curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP", "Description": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.", "Severity": "HIGH", "CweIDs": [ "CWE-297", "CWE-295" ], "VendorSeverity": { "amazon": 2, "azure": 3, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-12064", "https://curl.se/L7HzKXisfJ/CVE-2026-12064.md", "https://curl.se/docs/CVE-2026-12064.html", "https://curl.se/docs/CVE-2026-12064.json", "https://github.com/advisories/GHSA-jm94-9f7h-36pr", "https://hackerone.com/reports/3797526", "https://linux.oracle.com/cve/CVE-2026-12064.html", "https://linux.oracle.com/errata/ELSA-2026-55450.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-12064", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-12064" ], "PublishedDate": "2026-07-03T07:16:24.217Z", "LastModifiedDate": "2026-09-15T07:16:26.15Z" }, { "VulnerabilityID": "CVE-2026-5773", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.20.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-5773", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:f5c61c3807f257cf19fe2f0154c9a646e0a599113d1770fc2c582808bf383c07", "Title": "curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse", "Description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.", "Severity": "HIGH", "CweIDs": [ "CWE-488", "CWE-918" ], "VendorSeverity": { "julia": 3, "nvd": 3, "photon": 3, "redhat": 2, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "V3Score": 6.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/04/29/9", "https://access.redhat.com/security/cve/CVE-2026-5773", "https://curl.se/docs/CVE-2026-5773.html", "https://curl.se/docs/CVE-2026-5773.json", "https://github.com/advisories/GHSA-rp9q-8q5w-ch44", "https://hackerone.com/reports/3650689", "https://nvd.nist.gov/vuln/detail/CVE-2026-5773", "https://ubuntu.com/security/notices/USN-8227-1", "https://ubuntu.com/security/notices/USN-8525-1", "https://www.cve.org/CVERecord?id=CVE-2026-5773" ], "PublishedDate": "2026-05-13T13:01:56.307Z", "LastModifiedDate": "2026-09-15T07:16:28.82Z" }, { "VulnerabilityID": "CVE-2026-6276", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.20.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-6276", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:3f46c72f692ad56b69bebd81875a83a7406c5b1503cd90fe336d15904aa01168", "Title": "curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers", "Description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.", "Severity": "HIGH", "CweIDs": [ "CWE-346", "CWE-319" ], "VendorSeverity": { "azure": 2, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "V3Score": 3.7 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/04/29/13", "https://access.redhat.com/security/cve/CVE-2026-6276", "https://curl.se/docs/CVE-2026-6276.html", "https://curl.se/docs/CVE-2026-6276.json", "https://github.com/advisories/GHSA-2jc6-hc33-hv48", "https://hackerone.com/reports/3671818", "https://nvd.nist.gov/vuln/detail/CVE-2026-6276", "https://ubuntu.com/security/notices/USN-8227-1", "https://www.cve.org/CVERecord?id=CVE-2026-6276" ], "PublishedDate": "2026-05-13T13:01:56.8Z", "LastModifiedDate": "2026-09-15T07:16:29.343Z" }, { "VulnerabilityID": "CVE-2026-8286", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8286", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:121a41985c9da40cb5aba7e2ddb430ec1266d853cbfcea27598c67f2e00fdc36", "Title": "curl: curl: Insecure connection establishment due to TLS configuration mismatch", "Description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.", "Severity": "HIGH", "CweIDs": [ "CWE-295" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 3, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "V3Score": 8.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:55439", "https://access.redhat.com/errata/RHSA-2026:57462", "https://access.redhat.com/security/cve/CVE-2026-8286", "https://bugzilla.redhat.com/2496763", "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", "https://creativecommons.org/licenses/by/4.0/", "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md", "https://curl.se/docs/CVE-2026-8286.html", "https://curl.se/docs/CVE-2026-8286.json", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", "https://errata.almalinux.org/8/ALSA-2026-57462.html", "https://errata.rockylinux.org/RLSA-2026:55439", "https://github.com/advisories/GHSA-32xh-3x3c-6g6h", "https://hackerone.com/reports/3718195", "https://linux.oracle.com/cve/CVE-2026-8286.html", "https://linux.oracle.com/errata/ELSA-2026-57462.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-8286", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8286" ], "PublishedDate": "2026-07-03T07:16:24.453Z", "LastModifiedDate": "2026-09-15T07:16:31.617Z" }, { "VulnerabilityID": "CVE-2026-8458", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8458", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:fcd8b8c3b654561673146fd1225760e31042d59052cb3453a62dd648146652cc", "Title": "curl: libcurl: Unauthorized connection reuse due to a logical error", "Description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.", "Severity": "HIGH", "CweIDs": [ "CWE-488" ], "VendorSeverity": { "amazon": 2, "azure": 2, "julia": 2, "photon": 2, "redhat": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "V3Score": 6.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-8458", "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md", "https://curl.se/docs/CVE-2026-8458.html", "https://curl.se/docs/CVE-2026-8458.json", "https://github.com/advisories/GHSA-88c6-6jfq-mm4q", "https://hackerone.com/reports/3721183", "https://nvd.nist.gov/vuln/detail/CVE-2026-8458", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8458" ], "PublishedDate": "2026-07-03T07:16:24.63Z", "LastModifiedDate": "2026-09-15T07:16:32.327Z" }, { "VulnerabilityID": "CVE-2026-8925", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8925", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:c590f69f57cd74439affbdb3326fa5bc10ae4435f37c33555f3e6834eaa55603", "Title": "curl: curl: Double-free vulnerability in SASL authentication", "Description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.", "Severity": "HIGH", "CweIDs": [ "CWE-415" ], "VendorSeverity": { "amazon": 2, "julia": 4, "photon": 4, "redhat": 3, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 9.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-8925", "https://curl.se/L7HzKXisfJ/CVE-2026-8925.md", "https://curl.se/docs/CVE-2026-8925.html", "https://curl.se/docs/CVE-2026-8925.json", "https://github.com/advisories/GHSA-p8x5-c6c9-8cwx", "https://hackerone.com/reports/3735193", "https://nvd.nist.gov/vuln/detail/CVE-2026-8925", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8925" ], "PublishedDate": "2026-07-03T07:16:24.95Z", "LastModifiedDate": "2026-09-15T07:16:32.8Z" }, { "VulnerabilityID": "CVE-2026-8927", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8927", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:a5d7961b9014e46fd3e2fe9fbb3bc180e6552fcb770627f0868212993ae97c42", "Title": "curl: Information disclosure due to uncleared proxy authentication state", "Description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.", "Severity": "HIGH", "CweIDs": [ "CWE-294" ], "VendorSeverity": { "alma": 3, "amazon": 2, "azure": 2, "julia": 4, "oracle-oval": 3, "photon": 4, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 9.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:55432", "https://access.redhat.com/security/cve/CVE-2026-8927", "https://bugzilla.redhat.com/2496769", "https://bugzilla.redhat.com/show_bug.cgi?id=2496769", "https://creativecommons.org/licenses/by/4.0/", "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md", "https://curl.se/docs/CVE-2026-8927.html", "https://curl.se/docs/CVE-2026-8927.json", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927", "https://errata.almalinux.org/10/ALSA-2026-55432.html", "https://errata.rockylinux.org/RLSA-2026:55432", "https://github.com/advisories/GHSA-jr4f-4564-w3mr", "https://hackerone.com/reports/3744543", "https://linux.oracle.com/cve/CVE-2026-8927.html", "https://linux.oracle.com/errata/ELSA-2026-55432.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-8927", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-8927" ], "PublishedDate": "2026-07-03T07:16:25.123Z", "LastModifiedDate": "2026-09-15T07:16:33.157Z" }, { "VulnerabilityID": "CVE-2026-9547", "PkgID": "libcurl@8.17.0-r1", "PkgName": "libcurl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", "UID": "85c7760f5617ed48" }, "InstalledVersion": "8.17.0-r1", "FixedVersion": "8.22.0-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9547", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:68f2b1b38e685a494a50efdcabf044195303599e5636b3dbbda5c9b9b5568dde", "Title": "curl: curl: Man-in-the-middle attack via SSH host key bypass", "Description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.", "Severity": "HIGH", "CweIDs": [ "CWE-297" ], "VendorSeverity": { "alma": 3, "amazon": 2, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 7.4 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "V3Score": 7.4 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:55439", "https://access.redhat.com/security/cve/CVE-2026-9547", "https://bugzilla.redhat.com/2446448", "https://bugzilla.redhat.com/2446450", "https://bugzilla.redhat.com/2496758", "https://bugzilla.redhat.com/2496763", "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", "https://creativecommons.org/licenses/by/4.0/", "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md", "https://curl.se/docs/CVE-2026-9547.html", "https://curl.se/docs/CVE-2026-9547.json", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", "https://errata.almalinux.org/9/ALSA-2026-55439.html", "https://errata.rockylinux.org/RLSA-2026:55439", "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6", "https://hackerone.com/reports/3751712", "https://linux.oracle.com/cve/CVE-2026-9547.html", "https://linux.oracle.com/errata/ELSA-2026-55450.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-9547", "https://ubuntu.com/security/notices/USN-8487-1", "https://www.cve.org/CVERecord?id=CVE-2026-9547" ], "PublishedDate": "2026-07-03T07:16:25.99Z", "LastModifiedDate": "2026-09-15T07:16:35.31Z" }, { "VulnerabilityID": "CVE-2026-45186", "PkgID": "libexpat@2.7.5-r0", "PkgName": "libexpat", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "60ae354914fcce6c" }, "InstalledVersion": "2.7.5-r0", "FixedVersion": "2.8.1-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45186", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:0d8a86967d8fa15637f654b06c8497d3f4f6bc48eb5cffb16a308a085413c924", "Title": "libexpat: denial of service via crafted XML input", "Description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.", "Severity": "HIGH", "CweIDs": [ "CWE-407" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 1, "julia": 3, "nvd": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/05/11/16", "https://access.redhat.com/errata/RHSA-2026:22715", "https://access.redhat.com/errata/RHSA-2026:22721", "https://access.redhat.com/errata/RHSA-2026:23230", "https://access.redhat.com/errata/RHSA-2026:26319", "https://access.redhat.com/errata/RHSA-2026:27201", "https://access.redhat.com/errata/RHSA-2026:29197", "https://access.redhat.com/errata/RHSA-2026:58981", "https://access.redhat.com/security/cve/CVE-2026-45186", "https://bugzilla.redhat.com/2468575", "https://bugzilla.redhat.com/show_bug.cgi?id=2468575", "https://cert-portal.siemens.com/productcert/html/ssa-082556.html", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45186", "https://errata.almalinux.org/8/ALSA-2026-22721.html", "https://errata.rockylinux.org/RLSA-2026:23230", "https://github.com/libexpat/libexpat/pull/1216", "https://linux.oracle.com/cve/CVE-2026-45186.html", "https://linux.oracle.com/errata/ELSA-2026-23230.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-45186", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json", "https://www.cve.org/CVERecord?id=CVE-2026-45186" ], "PublishedDate": "2026-05-10T07:16:07.883Z", "LastModifiedDate": "2026-08-25T13:19:12.733Z" }, { "VulnerabilityID": "CVE-2026-76956", "PkgID": "libexpat@2.7.5-r0", "PkgName": "libexpat", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "60ae354914fcce6c" }, "InstalledVersion": "2.7.5-r0", "FixedVersion": "2.8.4-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76956", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:643f929dd150a9f84e0f8f90df116ae6ed41ac3517b73329f9b4ae6137322fee", "Title": "libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML", "Description": "In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.", "Severity": "HIGH", "CweIDs": [ "CWE-394" ], "VendorSeverity": { "azure": 2, "nvd": 3, "redhat": 2 }, "CVSS": { "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-76956", "https://github.com/libexpat/libexpat/pull/1326", "https://github.com/libexpat/libexpat/pull/1329", "https://nvd.nist.gov/vuln/detail/CVE-2026-76956", "https://www.cve.org/CVERecord?id=CVE-2026-76956" ], "PublishedDate": "2026-08-20T05:16:29.61Z", "LastModifiedDate": "2026-09-08T21:08:20.697Z" }, { "VulnerabilityID": "CVE-2026-76957", "PkgID": "libexpat@2.7.5-r0", "PkgName": "libexpat", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "60ae354914fcce6c" }, "InstalledVersion": "2.7.5-r0", "FixedVersion": "2.8.4-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76957", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:81d7c0687cae5b008df63250a49df443831c48fd7532df7889fd28adcd84e646", "Title": "libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service", "Description": "libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.", "Severity": "HIGH", "CweIDs": [ "CWE-416" ], "VendorSeverity": { "amazon": 3, "azure": 2, "nvd": 3, "redhat": 2, "ubuntu": 2 }, "CVSS": { "nvd": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "V3Score": 4.9 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-76957", "https://github.com/libexpat/libexpat/pull/1322", "https://github.com/libexpat/libexpat/pull/1329", "https://nvd.nist.gov/vuln/detail/CVE-2026-76957", "https://www.cve.org/CVERecord?id=CVE-2026-76957" ], "PublishedDate": "2026-08-20T05:16:29.747Z", "LastModifiedDate": "2026-09-08T20:56:31.86Z" }, { "VulnerabilityID": "CVE-2026-31789", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31789", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:1ed7188257cd36ad2de434165f52910df869991d0efa7d88f0869ea1e74f85d5", "Title": "openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing", "Description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "CRITICAL", "CweIDs": [ "CWE-787" ], "VendorSeverity": { "azure": 2, "julia": 4, "nvd": 4, "photon": 4, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 9.8 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 9.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", "V3Score": 5.8 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-31789", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://github.com/advisories/GHSA-j79m-9jxq-788r", "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde", "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf", "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49", "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9", "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521", "https://nvd.nist.gov/vuln/detail/CVE-2026-31789", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://www.cve.org/CVERecord?id=CVE-2026-31789", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:21.617Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-14456", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.8-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:788f2b3335228ab2fb9361761262ebb89c47f5b5eb385ca3766d79e010bbfc26", "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-770" ], "VendorSeverity": { "amazon": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/08/13/4", "https://access.redhat.com/security/cve/CVE-2026-14456", "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", "https://linux.oracle.com/cve/CVE-2026-14456.html", "https://linux.oracle.com/errata/ELSA-2026-67165-0.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", "https://openssl-library.org/news/secadv/20260813.txt", "https://ubuntu.com/security/notices/USN-8678-1", "https://www.cve.org/CVERecord?id=CVE-2026-14456" ], "PublishedDate": "2026-08-13T15:19:31.82Z", "LastModifiedDate": "2026-08-28T19:46:29.323Z" }, { "VulnerabilityID": "CVE-2026-28387", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28387", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:34c25f043d8bec73580478120cea20d30f407dea733211611d0035b96159fbda", "Title": "openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication", "Description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages. These SMTP (or other similar) clients are not vulnerable\nto this issue. Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-416" ], "VendorSeverity": { "amazon": 3, "azure": 1, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "V3Score": 3.7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-28387", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b", "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe", "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3", "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7", "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177", "https://nvd.nist.gov/vuln/detail/CVE-2026-28387", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28387", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:20.7Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-28388", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28388", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:0b9e8688d3d089e44f6afa0038e3d461d4df29095381f896d59a0f80ee73e265", "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing", "Description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "amazon": 3, "azure": 2, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-28388", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e", "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139", "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3", "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8", "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726", "https://nvd.nist.gov/vuln/detail/CVE-2026-28388", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28388", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:20.863Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-28389", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28389", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:ca77ec59988da1821209c669e656b0097d03fa827294cd33475b020c0e96f8a1", "Title": "openssl: OpenSSL: Denial of Service vulnerability in CMS processing", "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "amazon": 3, "azure": 2, "julia": 3, "nvd": 3, "photon": 3, "redhat": 1, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 5.9 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-28389", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://github.com/advisories/GHSA-7x88-9hgc-69gf", "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5", "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616", "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f", "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a", "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686", "https://nvd.nist.gov/vuln/detail/CVE-2026-28389", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28389", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:21.03Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-28390", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28390", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:ad39877058ae8a1d4104b7f4ba55e2cd0c746173b2f65a819625b03b8d142115", "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing", "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-476" ], "VendorSeverity": { "alma": 2, "amazon": 3, "azure": 2, "julia": 3, "nvd": 3, "oracle-oval": 2, "photon": 3, "redhat": 2, "rocky": 2, "ubuntu": 1 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:22312", "https://access.redhat.com/errata/RHSA-2026:38503", "https://access.redhat.com/security/cve/CVE-2026-28390", "https://bugzilla.redhat.com/2456314", "https://bugzilla.redhat.com/show_bug.cgi?id=2456314", "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28390", "https://errata.almalinux.org/8/ALSA-2026-38503.html", "https://errata.rockylinux.org/RLSA-2026:22312", "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc", "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6", "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4", "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788", "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75", "https://linux.oracle.com/cve/CVE-2026-28390.html", "https://linux.oracle.com/errata/ELSA-2026-50345.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-28390", "https://openssl-library.org/news/secadv/20260407.txt", "https://ubuntu.com/security/notices/USN-8155-1", "https://ubuntu.com/security/notices/USN-8155-2", "https://www.cve.org/CVERecord?id=CVE-2026-28390", "https://www.openwall.com/lists/oss-security/2026/04/07/11" ], "PublishedDate": "2026-04-07T22:16:21.19Z", "LastModifiedDate": "2026-07-24T23:10:00.563Z" }, { "VulnerabilityID": "CVE-2026-45447", "PkgID": "libssl3@3.5.5-r0", "PkgName": "libssl3", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", "UID": "bca2260902e2ef48" }, "InstalledVersion": "3.5.5-r0", "FixedVersion": "3.5.7-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45447", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:65b8831d28e97cb2ad71066d8a5510cc57b87e45dcd390a81cf4b5345bad2e25", "Title": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()", "Description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", "Severity": "HIGH", "CweIDs": [ "CWE-416", "CWE-825" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "julia": 3, "oracle-oval": 2, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 3 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:25237", "https://access.redhat.com/errata/RHSA-2026:25239", "https://access.redhat.com/errata/RHSA-2026:26275", "https://access.redhat.com/errata/RHSA-2026:26319", "https://access.redhat.com/errata/RHSA-2026:29197", "https://access.redhat.com/errata/RHSA-2026:34102", "https://access.redhat.com/errata/RHSA-2026:35869", "https://access.redhat.com/errata/RHSA-2026:36215", "https://access.redhat.com/errata/RHSA-2026:36217", "https://access.redhat.com/errata/RHSA-2026:39009", "https://access.redhat.com/errata/RHSA-2026:39012", "https://access.redhat.com/errata/RHSA-2026:39981", "https://access.redhat.com/errata/RHSA-2026:44438", "https://access.redhat.com/errata/RHSA-2026:47735", "https://access.redhat.com/errata/RHSA-2026:47737", "https://access.redhat.com/errata/RHSA-2026:58563", "https://access.redhat.com/errata/RHSA-2026:58981", "https://access.redhat.com/errata/RHSA-2026:59831", "https://access.redhat.com/errata/RHSA-2026:66524", "https://access.redhat.com/security/cve/CVE-2026-45447", "https://bugzilla.redhat.com/2481898", "https://bugzilla.redhat.com/show_bug.cgi?id=2481879", "https://bugzilla.redhat.com/show_bug.cgi?id=2481880", "https://bugzilla.redhat.com/show_bug.cgi?id=2481881", "https://bugzilla.redhat.com/show_bug.cgi?id=2481882", "https://bugzilla.redhat.com/show_bug.cgi?id=2481884", "https://bugzilla.redhat.com/show_bug.cgi?id=2481885", "https://bugzilla.redhat.com/show_bug.cgi?id=2481887", "https://bugzilla.redhat.com/show_bug.cgi?id=2481890", "https://bugzilla.redhat.com/show_bug.cgi?id=2481891", "https://bugzilla.redhat.com/show_bug.cgi?id=2481892", "https://bugzilla.redhat.com/show_bug.cgi?id=2481893", "https://bugzilla.redhat.com/show_bug.cgi?id=2481894", "https://bugzilla.redhat.com/show_bug.cgi?id=2481896", "https://bugzilla.redhat.com/show_bug.cgi?id=2481897", "https://bugzilla.redhat.com/show_bug.cgi?id=2481898", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076", "https://errata.almalinux.org/8/ALSA-2026-36215.html", "https://errata.rockylinux.org/RLSA-2026:25239", "https://github.com/advisories/GHSA-f684-cpcq-j565", "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", "https://github.com/openssl/security/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", "https://github.com/openssl/security/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", "https://github.com/openssl/security/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", "https://github.com/openssl/security/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", "https://github.com/openssl/security/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", "https://linux.oracle.com/cve/CVE-2026-45447.html", "https://linux.oracle.com/errata/ELSA-2026-50379.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-45447", "https://openssl-library.org/news/secadv/20260609.txt", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json", "https://ubuntu.com/security/notices/USN-8414-1", "https://ubuntu.com/security/notices/USN-8414-2", "https://www.cve.org/CVERecord?id=CVE-2026-45447" ], "PublishedDate": "2026-06-09T17:17:19.277Z", "LastModifiedDate": "2026-09-11T13:18:10.853Z" }, { "VulnerabilityID": "CVE-2026-53612", "PkgID": "libuuid@2.41.2-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "InstalledVersion": "2.41.2-r0", "FixedVersion": "2.41.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53612", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:66e0c191ce5607dcc196942aba290c9b467bc46156fdb0b3f5c55c415060b094", "Title": "util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes", "Description": "A flaw was found in util-linux. When an /etc/fstab entry uses the user option together with X-mount.owner, X-mount.group, or X-mount.mode, mount(8) changes ownership or permissions on the mount target after mounting without re-verifying the path. A local unprivileged user can exploit this Time-of-Check-Time-of-Use (TOCTOU) window by swapping the target directory, redirecting the ownership/permission change to an arbitrary file and potentially escalating privileges to root.", "Severity": "HIGH", "VendorSeverity": { "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-53612", "https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh", "https://nvd.nist.gov/vuln/detail/CVE-2026-53612", "https://ubuntu.com/security/notices/USN-8702-1", "https://www.cve.org/CVERecord?id=CVE-2026-53612" ] }, { "VulnerabilityID": "CVE-2026-53613", "PkgID": "libuuid@2.41.2-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "InstalledVersion": "2.41.2-r0", "FixedVersion": "2.41.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53613", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:cb1ca22b1a0c6ab3c5692eb2ec1833f0970646f1e5a13be1de1eff43aab0ec4a", "Title": "util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path", "Description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.", "Severity": "HIGH", "VendorSeverity": { "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-53613", "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g", "https://nvd.nist.gov/vuln/detail/CVE-2026-53613", "https://ubuntu.com/security/notices/USN-8702-1", "https://www.cve.org/CVERecord?id=CVE-2026-53613" ] }, { "VulnerabilityID": "CVE-2026-53614", "PkgID": "libuuid@2.41.2-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "InstalledVersion": "2.41.2-r0", "FixedVersion": "2.41.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53614", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:e558ead5205cca32ae1243f8df104ee7e9129f0f79d1359a95e6fdda9ea2f852", "Title": "util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2", "Description": "A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root.", "Severity": "HIGH", "VendorSeverity": { "redhat": 3, "ubuntu": 2 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-53614", "https://github.com/util-linux/util-linux/security/advisories/GHSA-67r7-8m5w-22wx", "https://nvd.nist.gov/vuln/detail/CVE-2026-53614", "https://ubuntu.com/security/notices/USN-8702-1", "https://www.cve.org/CVERecord?id=CVE-2026-53614" ] }, { "VulnerabilityID": "CVE-2026-76642", "PkgID": "libuuid@2.41.2-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "InstalledVersion": "2.41.2-r0", "FixedVersion": "2.41.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:a7207f52f6bc2c43c87c21fd16a856b2b3e8ee94b8a18ec7c9c7124c47617b23", "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", "Severity": "HIGH", "CweIDs": [ "CWE-390" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-76642", "https://github.com/util-linux/util-linux", "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", "https://www.cve.org/CVERecord?id=CVE-2026-76642", "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" ], "PublishedDate": "2026-09-03T13:06:08.44Z", "LastModifiedDate": "2026-09-03T15:17:33.49Z" }, { "VulnerabilityID": "CVE-2026-78408", "PkgID": "libuuid@2.41.2-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "InstalledVersion": "2.41.2-r0", "FixedVersion": "2.41.6-r1", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:49a185af463fd19e31d6cb4c71b19fdb6b04e1a8db216ff3eb68fc76bc2893d6", "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", "Severity": "HIGH", "CweIDs": [ "CWE-775" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", "V3Score": 7.9 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/09/05/2", "https://access.redhat.com/errata/RHSA-2026:63162", "https://access.redhat.com/security/cve/CVE-2026-78408", "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", "https://www.cve.org/CVERecord?id=CVE-2026-78408" ], "PublishedDate": "2026-09-02T16:17:23.687Z", "LastModifiedDate": "2026-09-05T14:17:23.727Z" }, { "VulnerabilityID": "CVE-2026-78410", "PkgID": "libuuid@2.41.2-r0", "PkgName": "libuuid", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", "UID": "509022c493029e03" }, "InstalledVersion": "2.41.2-r0", "FixedVersion": "2.41.6-r0", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:754f422d26b7ff55fd2436be9fc93b9e81857e3c6995e0e202e9c970f2f8165e", "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", "Severity": "HIGH", "CweIDs": [ "CWE-367" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:63162", "https://access.redhat.com/security/cve/CVE-2026-78410", "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", "https://www.cve.org/CVERecord?id=CVE-2026-78410" ], "PublishedDate": "2026-09-02T16:17:23.983Z", "LastModifiedDate": "2026-09-04T19:17:27.567Z" }, { "VulnerabilityID": "CVE-2026-6732", "PkgID": "libxml2@2.13.9-r0", "PkgName": "libxml2", "PkgIdentifier": { "PURL": "pkg:apk/alpine/libxml2@2.13.9-r0?arch=x86_64\u0026distro=3.23.3", "UID": "ce9ff006e72f7256" }, "InstalledVersion": "2.13.9-r0", "FixedVersion": "2.13.9-r1", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-6732", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:cd01b1e873db5f860089e03849367417ca8307d68879438d902abc1d56cbaec4", "Title": "libxml2: libxml2: Denial of Service via crafted XSD-validated document", "Description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.", "Severity": "HIGH", "CweIDs": [ "CWE-843" ], "VendorSeverity": { "julia": 3, "nvd": 3, "photon": 3, "redhat": 2, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "nvd": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 6.5 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:11503", "https://access.redhat.com/security/cve/CVE-2026-6732", "https://bugzilla.redhat.com/show_bug.cgi?id=2461300", "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097", "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411", "https://nvd.nist.gov/vuln/detail/CVE-2026-6732", "https://ubuntu.com/security/notices/USN-8460-1", "https://www.cve.org/CVERecord?id=CVE-2026-6732" ], "PublishedDate": "2026-04-23T23:16:16.443Z", "LastModifiedDate": "2026-08-31T12:17:56.307Z" }, { "VulnerabilityID": "CVE-2026-40200", "PkgID": "musl@1.2.5-r21", "PkgName": "musl", "PkgIdentifier": { "PURL": "pkg:apk/alpine/musl@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", "UID": "750ab06f52f2bfe9" }, "InstalledVersion": "1.2.5-r21", "FixedVersion": "1.2.5-r23", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40200", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:9b867e6735969cfb16b8c627270d67cca6bb6530a716721259dbada8e5564aad", "Title": "musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort", "Description": "An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).", "Severity": "HIGH", "CweIDs": [ "CWE-670" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/04/10/13", "https://access.redhat.com/security/cve/CVE-2026-40200", "https://musl.libc.org/releases.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-40200", "https://www.cve.org/CVERecord?id=CVE-2026-40200", "https://www.openwall.com/lists/oss-security/2026/04/10/13" ], "PublishedDate": "2026-04-10T17:17:14.107Z", "LastModifiedDate": "2026-06-17T10:44:51.887Z" }, { "VulnerabilityID": "CVE-2026-40200", "PkgID": "musl-utils@1.2.5-r21", "PkgName": "musl-utils", "PkgIdentifier": { "PURL": "pkg:apk/alpine/musl-utils@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", "UID": "9dadd6d4093981ad" }, "InstalledVersion": "1.2.5-r21", "FixedVersion": "1.2.5-r23", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40200", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:2baaca9b049c4e9a17b9bc14dbfcc7e3710b270c7f25b326818bb881c547cfef", "Title": "musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort", "Description": "An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).", "Severity": "HIGH", "CweIDs": [ "CWE-670" ], "VendorSeverity": { "redhat": 3 }, "CVSS": { "redhat": { "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H", "V3Score": 7.8 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/04/10/13", "https://access.redhat.com/security/cve/CVE-2026-40200", "https://musl.libc.org/releases.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-40200", "https://www.cve.org/CVERecord?id=CVE-2026-40200", "https://www.openwall.com/lists/oss-security/2026/04/10/13" ], "PublishedDate": "2026-04-10T17:17:14.107Z", "LastModifiedDate": "2026-06-17T10:44:51.887Z" }, { "VulnerabilityID": "CVE-2026-27135", "PkgID": "nghttp2-libs@1.68.0-r0", "PkgName": "nghttp2-libs", "PkgIdentifier": { "PURL": "pkg:apk/alpine/nghttp2-libs@1.68.0-r0?arch=x86_64\u0026distro=3.23.3", "UID": "802c936f9e7891b2" }, "InstalledVersion": "1.68.0-r0", "FixedVersion": "1.68.1", "Status": "fixed", "Layer": { "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27135", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:14217fd5f5725adca855befd93725d4d3a4495c388f539f8e4386b48fe007647", "Title": "nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination", "Description": "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.", "Severity": "HIGH", "CweIDs": [ "CWE-617" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "cbl-mariner": 3, "julia": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "julia": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/03/20/3", "https://access.redhat.com/errata/RHSA-2026:10065", "https://access.redhat.com/errata/RHSA-2026:11768", "https://access.redhat.com/errata/RHSA-2026:13812", "https://access.redhat.com/errata/RHSA-2026:14773", "https://access.redhat.com/errata/RHSA-2026:14937", "https://access.redhat.com/errata/RHSA-2026:15087", "https://access.redhat.com/errata/RHSA-2026:16008", "https://access.redhat.com/errata/RHSA-2026:16009", "https://access.redhat.com/errata/RHSA-2026:16030", "https://access.redhat.com/errata/RHSA-2026:16174", "https://access.redhat.com/errata/RHSA-2026:17596", "https://access.redhat.com/errata/RHSA-2026:19724", "https://access.redhat.com/errata/RHSA-2026:19725", "https://access.redhat.com/errata/RHSA-2026:20040", "https://access.redhat.com/errata/RHSA-2026:20087", "https://access.redhat.com/errata/RHSA-2026:21656", "https://access.redhat.com/errata/RHSA-2026:21690", "https://access.redhat.com/errata/RHSA-2026:21695", "https://access.redhat.com/errata/RHSA-2026:25096", "https://access.redhat.com/errata/RHSA-2026:27200", "https://access.redhat.com/errata/RHSA-2026:27201", "https://access.redhat.com/errata/RHSA-2026:6190", "https://access.redhat.com/errata/RHSA-2026:7080", "https://access.redhat.com/errata/RHSA-2026:7123", "https://access.redhat.com/errata/RHSA-2026:7302", "https://access.redhat.com/errata/RHSA-2026:7310", "https://access.redhat.com/errata/RHSA-2026:7350", "https://access.redhat.com/errata/RHSA-2026:7666", "https://access.redhat.com/errata/RHSA-2026:7667", "https://access.redhat.com/errata/RHSA-2026:7668", "https://access.redhat.com/errata/RHSA-2026:7670", "https://access.redhat.com/errata/RHSA-2026:7675", "https://access.redhat.com/errata/RHSA-2026:7896", "https://access.redhat.com/errata/RHSA-2026:7983", "https://access.redhat.com/errata/RHSA-2026:8339", "https://access.redhat.com/errata/RHSA-2026:8538", "https://access.redhat.com/errata/RHSA-2026:8539", "https://access.redhat.com/errata/RHSA-2026:8540", "https://access.redhat.com/errata/RHSA-2026:8541", "https://access.redhat.com/errata/RHSA-2026:8545", "https://access.redhat.com/errata/RHSA-2026:8546", "https://access.redhat.com/errata/RHSA-2026:8547", "https://access.redhat.com/errata/RHSA-2026:8548", "https://access.redhat.com/errata/RHSA-2026:8868", "https://access.redhat.com/errata/RHSA-2026:9711", "https://access.redhat.com/errata/RHSA-2026:9832", "https://access.redhat.com/errata/RHSA-2026:9874", "https://access.redhat.com/security/cve/CVE-2026-27135", "https://bugzilla.redhat.com/2441268", "https://bugzilla.redhat.com/2442922", "https://bugzilla.redhat.com/2448754", "https://bugzilla.redhat.com/2453151", "https://bugzilla.redhat.com/show_bug.cgi?id=2448754", "https://cert-portal.siemens.com/productcert/html/ssa-019113.html", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27135", "https://errata.almalinux.org/8/ALSA-2026-8339.html", "https://errata.rockylinux.org/RLSA-2026:7668", "https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1", "https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6", "https://linux.oracle.com/cve/CVE-2026-27135.html", "https://linux.oracle.com/errata/ELSA-2026-8339.html", "https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-27135", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json", "https://ubuntu.com/security/notices/USN-8233-1", "https://ubuntu.com/security/notices/USN-8233-2", "https://www.cve.org/CVERecord?id=CVE-2026-27135" ], "PublishedDate": "2026-03-18T18:16:26.723Z", "LastModifiedDate": "2026-07-15T02:19:03.367Z" }, { "VulnerabilityID": "CVE-2026-42055", "PkgID": "nginx@1.28.3-r1", "PkgName": "nginx", "PkgIdentifier": { "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8bdce2a9d53051b3" }, "InstalledVersion": "1.28.3-r1", "FixedVersion": "1.28.3-r4", "Status": "fixed", "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42055", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:cf24340681d84f61ec55cba943ff98b324600671ea8e30214601fccbb1da0b03", "Title": "nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers", "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "Severity": "HIGH", "CweIDs": [ "CWE-122", "CWE-787", "CWE-131" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "bitnami": 4, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "V40Score": 9.2 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:27197", "https://access.redhat.com/errata/RHSA-2026:36331", "https://access.redhat.com/errata/RHSA-2026:36364", "https://access.redhat.com/errata/RHSA-2026:36618", "https://access.redhat.com/errata/RHSA-2026:36639", "https://access.redhat.com/errata/RHSA-2026:38847", "https://access.redhat.com/errata/RHSA-2026:44481", "https://access.redhat.com/errata/RHSA-2026:46836", "https://access.redhat.com/errata/RHSA-2026:58981", "https://access.redhat.com/security/cve/CVE-2026-42055", "https://bugzilla.redhat.com/2489866", "https://bugzilla.redhat.com/show_bug.cgi?id=2489866", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42055", "https://errata.almalinux.org/8/ALSA-2026-38847.html", "https://errata.rockylinux.org/RLSA-2026:36639", "https://linux.oracle.com/cve/CVE-2026-42055.html", "https://linux.oracle.com/errata/ELSA-2026-38847.html", "https://my.f5.com/manage/s/article/K000161584", "https://nvd.nist.gov/vuln/detail/CVE-2026-42055", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json", "https://ubuntu.com/security/notices/USN-8458-1", "https://www.cve.org/CVERecord?id=CVE-2026-42055" ], "PublishedDate": "2026-06-17T15:16:50.353Z", "LastModifiedDate": "2026-09-14T13:18:34.69Z" }, { "VulnerabilityID": "CVE-2026-42533", "PkgID": "nginx@1.28.3-r1", "PkgName": "nginx", "PkgIdentifier": { "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8bdce2a9d53051b3" }, "InstalledVersion": "1.28.3-r1", "FixedVersion": "1.28.3-r6", "Status": "fixed", "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42533", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:15a804ee01ab6b8edeb9cf66a74400174ccbb23556bfb9084042d656a99b6e38", "Title": "nginx: NGINX: Arbitrary code execution via crafted HTTP requests", "Description": "A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "Severity": "HIGH", "CweIDs": [ "CWE-122" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 4, "bitnami": 4, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "V40Score": 9.2 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", "V3Score": 7 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:66542", "https://access.redhat.com/security/cve/CVE-2026-42533", "https://bugzilla.redhat.com/2500967", "https://bugzilla.redhat.com/show_bug.cgi?id=2500967", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42533", "https://cyberstan.co.uk/nginx-rce/", "https://errata.almalinux.org/9/ALSA-2026-66542.html", "https://errata.rockylinux.org/RLSA-2026:66542", "https://github.com/imbas007/cve-2026-42533", "https://linux.oracle.com/cve/CVE-2026-42533.html", "https://linux.oracle.com/errata/ELSA-2026-66542-0.html", "https://my.f5.com/manage/s/article/K000162097", "https://nvd.nist.gov/vuln/detail/CVE-2026-42533", "https://ubuntu.com/security/notices/USN-8563-1", "https://ubuntu.com/security/notices/USN-8563-2", "https://ubuntu.com/security/notices/USN-8563-3", "https://ubuntu.com/security/notices/USN-8563-4", "https://ubuntu.com/security/notices/USN-8563-5", "https://www.cve.org/CVERecord?id=CVE-2026-42533" ], "PublishedDate": "2026-07-15T15:16:33.48Z", "LastModifiedDate": "2026-08-10T15:28:01.94Z" }, { "VulnerabilityID": "CVE-2026-49975", "PkgID": "nginx@1.28.3-r1", "PkgName": "nginx", "PkgIdentifier": { "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8bdce2a9d53051b3" }, "InstalledVersion": "1.28.3-r1", "FixedVersion": "1.28.3-r3", "Status": "fixed", "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49975", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:86b0fce9ba1ec6603a72210fde7aedd3fc4e0ed042e7d25b1649797cf86c05b5", "Title": "httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack", "Description": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\n\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.", "Severity": "HIGH", "CweIDs": [ "CWE-789", "CWE-409" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "V3Score": 7.5 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/06/03/3", "http://www.openwall.com/lists/oss-security/2026/06/08/16", "https://access.redhat.com/errata/RHSA-2026:25042", "https://access.redhat.com/errata/RHSA-2026:25057", "https://access.redhat.com/errata/RHSA-2026:25090", "https://access.redhat.com/errata/RHSA-2026:25225", "https://access.redhat.com/errata/RHSA-2026:27114", "https://access.redhat.com/errata/RHSA-2026:27200", "https://access.redhat.com/errata/RHSA-2026:27201", "https://access.redhat.com/errata/RHSA-2026:36373", "https://access.redhat.com/errata/RHSA-2026:36831", "https://access.redhat.com/errata/RHSA-2026:36846", "https://access.redhat.com/errata/RHSA-2026:50538", "https://access.redhat.com/errata/RHSA-2026:50572", "https://access.redhat.com/errata/RHSA-2026:55930", "https://access.redhat.com/errata/RHSA-2026:55992", "https://access.redhat.com/security/cve/CVE-2026-49975", "https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb", "https://bugzilla.redhat.com/2485371", "https://bugzilla.redhat.com/show_bug.cgi?id=2485371", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49975", "https://errata.almalinux.org/8/ALSA-2026-25090.html", "https://errata.rockylinux.org/RLSA-2026:25057", "https://github.com/EQSTLab/CVE-2026-49975", "https://github.com/icing/mod_h2/pull/324", "https://httpd.apache.org/security/vulnerabilities_24.html", "https://linux.oracle.com/cve/CVE-2026-49975.html", "https://linux.oracle.com/errata/ELSA-2026-25225.html", "https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html", "https://nvd.nist.gov/vuln/detail/CVE-2026-49975", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49975.json", "https://ubuntu.com/security/notices/USN-8384-1", "https://ubuntu.com/security/notices/USN-8398-1", "https://ubuntu.com/security/notices/USN-8398-2", "https://ubuntu.com/security/notices/USN-8398-3", "https://ubuntu.com/security/notices/USN-8398-4", "https://ubuntu.com/security/notices/USN-8571-1", "https://www.cve.org/CVERecord?id=CVE-2026-49975" ], "PublishedDate": "2026-06-08T16:16:44.223Z", "LastModifiedDate": "2026-08-19T12:18:28.65Z" }, { "VulnerabilityID": "CVE-2026-60005", "PkgID": "nginx@1.28.3-r1", "PkgName": "nginx", "PkgIdentifier": { "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8bdce2a9d53051b3" }, "InstalledVersion": "1.28.3-r1", "FixedVersion": "1.28.3-r6", "Status": "fixed", "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-60005", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:d56fb689e95df1ae318f0dc04af52c804243e06a168776bb9576c0a4f5d152dd", "Title": "nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module", "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "Severity": "HIGH", "CweIDs": [ "CWE-908" ], "VendorSeverity": { "alma": 3, "amazon": 3, "bitnami": 3, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N", "V40Score": 8.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "V3Score": 8.2 } }, "References": [ "https://access.redhat.com/errata/RHSA-2026:59216", "https://access.redhat.com/errata/RHSA-2026:59496", "https://access.redhat.com/security/cve/CVE-2026-60005", "https://bugzilla.redhat.com/2500960", "https://bugzilla.redhat.com/2500992", "https://bugzilla.redhat.com/show_bug.cgi?id=2500960", "https://bugzilla.redhat.com/show_bug.cgi?id=2500992", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56434", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-60005", "https://errata.almalinux.org/8/ALSA-2026-59216.html", "https://errata.rockylinux.org/RLSA-2026:59496", "https://linux.oracle.com/cve/CVE-2026-60005.html", "https://linux.oracle.com/errata/ELSA-2026-59496.html", "https://my.f5.com/manage/s/article/K000162100", "https://nvd.nist.gov/vuln/detail/CVE-2026-60005", "https://ubuntu.com/security/notices/USN-8563-1", "https://www.cve.org/CVERecord?id=CVE-2026-60005" ], "PublishedDate": "2026-07-15T16:16:49.82Z", "LastModifiedDate": "2026-08-11T15:09:03.683Z" }, { "VulnerabilityID": "CVE-2026-9256", "PkgID": "nginx@1.28.3-r1", "PkgName": "nginx", "PkgIdentifier": { "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", "UID": "8bdce2a9d53051b3" }, "InstalledVersion": "1.28.3-r1", "FixedVersion": "1.28.3-r2", "Status": "fixed", "Layer": { "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" }, "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9256", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:b58ba119794ad177b9d4f3dc55b60ca326d73b9fd8336dc260c84c9c4fd3029e", "Title": "nginx: ngx_http_rewrite_module: code execution and denial of service", "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "Severity": "HIGH", "CweIDs": [ "CWE-122" ], "VendorSeverity": { "alma": 3, "amazon": 3, "azure": 3, "bitnami": 4, "oracle-oval": 3, "photon": 3, "redhat": 3, "rocky": 3, "ubuntu": 2 }, "CVSS": { "bitnami": { "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "V40Score": 9.2 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "V3Score": 8.1 } }, "References": [ "http://www.openwall.com/lists/oss-security/2026/05/22/14", "https://access.redhat.com/errata/RHSA-2026:20351", "https://access.redhat.com/errata/RHSA-2026:28212", "https://access.redhat.com/errata/RHSA-2026:28921", "https://access.redhat.com/errata/RHSA-2026:28973", "https://access.redhat.com/errata/RHSA-2026:29151", "https://access.redhat.com/errata/RHSA-2026:29874", "https://access.redhat.com/errata/RHSA-2026:33313", "https://access.redhat.com/errata/RHSA-2026:44481", "https://access.redhat.com/errata/RHSA-2026:58981", "https://access.redhat.com/security/cve/CVE-2026-9256", "https://bugzilla.redhat.com/2480746", "https://bugzilla.redhat.com/show_bug.cgi?id=2480746", "https://creativecommons.org/licenses/by/4.0/", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9256", "https://errata.almalinux.org/8/ALSA-2026-28921.html", "https://errata.rockylinux.org/RLSA-2026:29151", "https://linux.oracle.com/cve/CVE-2026-9256.html", "https://linux.oracle.com/errata/ELSA-2026-29874.html", "https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html", "https://my.f5.com/manage/s/article/K000161377", "https://nvd.nist.gov/vuln/detail/CVE-2026-9256", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json", "https://ubuntu.com/security/notices/USN-8354-1", "https://ubuntu.com/security/notices/USN-8375-1", "https://www.cve.org/CVERecord?id=CVE-2026-9256" ], "PublishedDate": "2026-05-22T15:16:27.073Z", "LastModifiedDate": "2026-08-25T13:19:33.4Z" }, { "VulnerabilityID": "CVE-2026-22184", "PkgID": "zlib@1.3.1-r2", "PkgName": "zlib", "PkgIdentifier": { "PURL": "pkg:apk/alpine/zlib@1.3.1-r2?arch=x86_64\u0026distro=3.23.3", "UID": "792cdc69bc59d880" }, "InstalledVersion": "1.3.1-r2", "FixedVersion": "1.3.2-r0", "Status": "fixed", "Layer": { "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" }, "SeveritySource": "nvd", "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-22184", "DataSource": { "ID": "alpine", "Name": "Alpine Secdb", "URL": "https://secdb.alpinelinux.org/" }, "Fingerprint": "sha256:635e1ed2b82ba940b100fd7b9963aa7ba3db5ba6bfedce83256ddf5097a66e62", "Title": "zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility", "Description": "zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.", "Severity": "HIGH", "CweIDs": [ "CWE-787", "CWE-120" ], "VendorSeverity": { "nvd": 3, "redhat": 3 }, "CVSS": { "nvd": { "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "V3Score": 7.8 }, "redhat": { "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "V3Score": 8.6 } }, "References": [ "https://access.redhat.com/security/cve/CVE-2026-22184", "https://bugzilla.redhat.com/show_bug.cgi?id=2427688", "https://cert-portal.siemens.com/productcert/html/ssa-470355.html", "https://github.com/madler/zlib", "https://github.com/madler/zlib/issues/1142", "https://nvd.nist.gov/vuln/detail/CVE-2026-22184", "https://seclists.org/fulldisclosure/2026/Jan/3", "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22184.json", "https://www.cve.org/CVERecord?id=CVE-2026-22184", "https://www.vulncheck.com/advisories/zlib-untgz-global-buffer-overflow-in-tgzfname", "https://zlib.net/" ], "PublishedDate": "2026-01-07T21:16:01.563Z", "LastModifiedDate": "2026-09-01T13:18:19.867Z" } ] } ] }