Files
dtf-system/output/security/postgres-container-audit.json
Cauê Faleiros 98c951d374
Some checks failed
Validate, publish and deploy / validate (push) Successful in 2m2s
Validate, publish and deploy / publish-and-deploy (push) Failing after 8s
first commit
2026-09-15 16:42:34 -03:00

6388 lines
313 KiB
JSON

{
"SchemaVersion": 2,
"Trivy": {
"Version": "0.74.0"
},
"ReportID": "01a0a031-5163-772d-a4fa-e9c174ed058b",
"CreatedAt": "2026-09-14T13:53:01.795473157Z",
"ArtifactID": "sha256:5e3704ea581305776a643c58dbedfc0cc2e72f31ae7a3a4b073fb87e48af539a",
"ArtifactName": "postgres:17-alpine",
"ArtifactType": "container_image",
"Metadata": {
"Size": 300003840,
"OS": {
"Family": "alpine",
"Name": "3.24.1"
},
"ImageID": "sha256:18cfe3ef5e6815560c98237d6216d1e5119702fb0f3894c8785dd58b8bbe5d73",
"DiffIDs": [
"sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c",
"sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226",
"sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58",
"sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e",
"sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99",
"sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0",
"sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0",
"sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d",
"sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242",
"sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212"
],
"RepoTags": [
"postgres:17-alpine"
],
"RepoDigests": [
"postgres@sha256:18cfe3ef5e6815560c98237d6216d1e5119702fb0f3894c8785dd58b8bbe5d73"
],
"Reference": "postgres:17-alpine",
"ImageConfig": {
"architecture": "amd64",
"created": "2026-08-13T19:17:35.122910679Z",
"history": [
{
"created": "2026-06-16T00:01:29Z",
"created_by": "ADD alpine-minirootfs-3.24.1-x86_64.tar.gz / # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-06-16T00:01:29Z",
"created_by": "CMD [\"/bin/sh\"]",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:15:15Z",
"created_by": "RUN /bin/sh -c set -eux; \taddgroup -g 70 -S postgres; \tadduser -u 70 -S -D -G postgres -H -h /var/lib/postgresql -s /bin/sh postgres; \tinstall --verbose --directory --owner postgres --group postgres --mode 1777 /var/lib/postgresql # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "ENV GOSU_VERSION=1.19",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "RUN /bin/sh -c set -eux; \t\tapk add --no-cache --virtual .gosu-deps \t\tca-certificates \t\tdpkg \t\tgnupg \t; \t\tdpkgArch=\"$(dpkg --print-architecture | awk -F- '{ print $NF }')\"; \twget -O /usr/local/bin/gosu \"https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$dpkgArch\"; \twget -O /usr/local/bin/gosu.asc \"https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$dpkgArch.asc\"; \t\texport GNUPGHOME=\"$(mktemp -d)\"; \tgpg --batch --keyserver hkps://keys.openpgp.org --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4; \tgpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu; \tgpgconf --kill all; \trm -rf \"$GNUPGHOME\" /usr/local/bin/gosu.asc; \t\tapk del --no-network .gosu-deps; \t\tchmod +x /usr/local/bin/gosu; \tgosu --version; \tgosu nobody true # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "ENV LANG=en_US.utf8",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "RUN /bin/sh -c mkdir /docker-entrypoint-initdb.d # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "ENV PG_MAJOR=17",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "ENV PG_VERSION=17.11",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "ENV PG_SHA256=dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:15:18Z",
"created_by": "ENV DOCKER_PG_LLVM_DEPS=llvm21-dev \t\tclang21",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:17:34Z",
"created_by": "RUN /bin/sh -c set -eux; \t\twget -O postgresql.tar.bz2 \"https://ftp.postgresql.org/pub/source/v$PG_VERSION/postgresql-$PG_VERSION.tar.bz2\"; \techo \"$PG_SHA256 *postgresql.tar.bz2\" | sha256sum -c -; \tmkdir -p /usr/src/postgresql; \ttar \t\t--extract \t\t--file postgresql.tar.bz2 \t\t--directory /usr/src/postgresql \t\t--strip-components 1 \t; \trm postgresql.tar.bz2; \t\tapk add --no-cache --virtual .build-deps \t\t$DOCKER_PG_LLVM_DEPS \t\tbison \t\tcoreutils \t\tdpkg-dev dpkg \t\tflex \t\tg++ \t\tgcc \t\tkrb5-dev \t\tlibc-dev \t\tlibedit-dev \t\tlibxml2-dev \t\tlibxslt-dev \t\tlinux-headers \t\tmake \t\topenldap-dev \t\topenssl-dev \t\tperl-dev \t\tperl-ipc-run \t\tperl-utils \t\tpython3-dev \t\ttcl-dev \t\tutil-linux-dev \t\tzlib-dev \t\ticu-dev \t\tlz4-dev \t\tzstd-dev \t; \t\tcd /usr/src/postgresql; \tawk '$1 == \"#define\" \u0026\u0026 $2 == \"DEFAULT_PGSOCKET_DIR\" \u0026\u0026 $3 == \"\\\"/tmp\\\"\" { $3 = \"\\\"/var/run/postgresql\\\"\"; print; next } { print }' src/include/pg_config_manual.h \u003e src/include/pg_config_manual.h.new; \tgrep '/var/run/postgresql' src/include/pg_config_manual.h.new; \tmv src/include/pg_config_manual.h.new src/include/pg_config_manual.h; \tgnuArch=\"$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)\"; \t\texport LLVM_CONFIG=\"/usr/lib/llvm21/bin/llvm-config\"; \texport CLANG=clang-21; \t\t./configure \t\t--enable-option-checking=fatal \t\t--build=\"$gnuArch\" \t\t--enable-integer-datetimes \t\t--enable-tap-tests \t\t--disable-rpath \t\t--with-uuid=e2fs \t\t--with-pgport=5432 \t\t--with-system-tzdata=/usr/share/zoneinfo \t\t--prefix=/usr/local \t\t--with-includes=/usr/local/include \t\t--with-libraries=/usr/local/lib \t\t--with-gssapi \t\t--with-icu \t\t--with-ldap \t\t--with-libxml \t\t--with-libxslt \t\t--with-llvm \t\t--with-lz4 \t\t--with-openssl \t\t--with-perl \t\t--with-python \t\t--with-tcl \t\t--with-zstd \t; \tmake -j \"$(nproc)\" world-bin; \tmake install-world-bin; \tmake -C contrib install; \t\trunDeps=\"$( \t\tscanelf --needed --nobanner --format '%n#p' --recursive /usr/local \t\t\t| tr ',' '\\n' \t\t\t| sort -u \t\t\t| awk 'system(\"[ -e /usr/local/lib/\" $1 \" ]\") == 0 { next } { print \"so:\" $1 }' \t\t\t| grep -v -e perl -e python -e tcl \t)\"; \tapk add --no-cache --virtual .postgresql-rundeps \t\t$runDeps \t\tbash \t\ttzdata \t\tzstd \t\ticu-data-full \t\t$([ \"$(apk --print-arch)\" != 'ppc64le' ] \u0026\u0026 echo 'nss_wrapper') \t; \tapk del --no-network .build-deps; \tcd /; \trm -rf \t\t/usr/src/postgresql \t\t/usr/local/share/doc \t\t/usr/local/share/man \t; \t\tpostgres --version # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:17:34Z",
"created_by": "RUN /bin/sh -c set -eux; \tcp -v /usr/local/share/postgresql/postgresql.conf.sample /usr/local/share/postgresql/postgresql.conf.sample.orig; \tsed -ri \"s!^#?(listen_addresses)\\s*=\\s*\\S+.*!\\1 = '*'!\" /usr/local/share/postgresql/postgresql.conf.sample; \tgrep -F \"listen_addresses = '*'\" /usr/local/share/postgresql/postgresql.conf.sample # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:17:34Z",
"created_by": "RUN /bin/sh -c install --verbose --directory --owner postgres --group postgres --mode 3777 /var/run/postgresql # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:17:34Z",
"created_by": "ENV PGDATA=/var/lib/postgresql/data",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "RUN /bin/sh -c install --verbose --directory --owner postgres --group postgres --mode 1777 \"$PGDATA\" # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "VOLUME [/var/lib/postgresql/data]",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "COPY docker-entrypoint.sh docker-ensure-initdb.sh /usr/local/bin/ # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "RUN /bin/sh -c ln -sT docker-ensure-initdb.sh /usr/local/bin/docker-enforce-initdb.sh # buildkit",
"comment": "buildkit.dockerfile.v0"
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "ENTRYPOINT [\"docker-entrypoint.sh\"]",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "STOPSIGNAL SIGINT",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "EXPOSE map[5432/tcp:{}]",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
},
{
"created": "2026-08-13T19:17:35Z",
"created_by": "CMD [\"postgres\"]",
"comment": "buildkit.dockerfile.v0",
"empty_layer": true
}
],
"os": "linux",
"rootfs": {
"type": "layers",
"diff_ids": [
"sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c",
"sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226",
"sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58",
"sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e",
"sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99",
"sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0",
"sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0",
"sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d",
"sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242",
"sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212"
]
},
"config": {
"Cmd": [
"postgres"
],
"Entrypoint": [
"docker-entrypoint.sh"
],
"Env": [
"PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
"GOSU_VERSION=1.19",
"LANG=en_US.utf8",
"PG_MAJOR=17",
"PG_VERSION=17.11",
"PG_SHA256=dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979",
"DOCKER_PG_LLVM_DEPS=llvm21-dev \t\tclang21",
"PGDATA=/var/lib/postgresql/data"
],
"Volumes": {
"/var/lib/postgresql/data": {}
},
"WorkingDir": "/",
"ExposedPorts": {
"5432/tcp": {}
},
"StopSignal": "SIGINT"
}
},
"Layers": [
{
"Size": 8697856,
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
{
"Size": 11264,
"Digest": "sha256:4d80c046a9c75283330c9ea2f7f3e5b3fbfe521c980e19d4164116dd95dfc730",
"DiffID": "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226"
},
{
"Size": 1988096,
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
{
"Size": 1536,
"Digest": "sha256:a12187db4b1792bf47380df49cfd84fd703811abd04c5d84568001a484afbf2d",
"DiffID": "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e"
},
{
"Size": 289209344,
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
{
"Size": 66560,
"Digest": "sha256:75de48f507ff913f69fa75a49da59f83db0ece385f649eefa7bcde930a9b573e",
"DiffID": "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0"
},
{
"Size": 2048,
"Digest": "sha256:d884d6f49732553e9690257554497e612cdcc1a6d83562fe08d582dec39e34e9",
"DiffID": "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0"
},
{
"Size": 3072,
"Digest": "sha256:b36c1b75fdb7939cb2a580ab05adfa65c8b118425f42cd8811cf632f37bb8616",
"DiffID": "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d"
},
{
"Size": 20992,
"Digest": "sha256:f070a657786685e37135e54207238cd1580e6869c6f5e8e6da85b2c9871ab31e",
"DiffID": "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242"
},
{
"Size": 3072,
"Digest": "sha256:7f3590dcd8434508e0c0bd953c80ed459f14f3a9005a3ac945bdb855abe58389",
"DiffID": "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212"
}
]
},
"Results": [
{
"Target": "postgres:17-alpine (alpine 3.24.1)",
"Class": "os-pkgs",
"Type": "alpine",
"Packages": [
{
"ID": ".postgresql-rundeps@20260813.191733",
"Name": ".postgresql-rundeps",
"Identifier": {
"PURL": "pkg:apk/alpine/.postgresql-rundeps@20260813.191733?arch=noarch\u0026distro=3.24.1",
"UID": "3e859114216d029b"
},
"Version": "20260813.191733",
"Arch": "noarch",
"DependsOn": [
"bash@5.3.9-r1",
"icu-data-full@78.1-r0",
"icu-libs@78.1-r0",
"krb5-libs@1.22.2-r1",
"libcrypto3@3.5.7-r0",
"libedit@20260508.3.1-r1",
"libgcc@15.2.0-r5",
"libldap@2.6.14-r0",
"libssl3@3.5.7-r0",
"libstdc++@15.2.0-r5",
"libuuid@2.42.1-r0",
"libxml2@2.13.9-r2",
"libxslt@1.1.43-r3",
"llvm21-libs@21.1.8-r1",
"lz4-libs@1.10.0-r1",
"musl@1.2.6-r2",
"nss_wrapper@1.1.12-r1",
"tzdata@2026c-r0",
"zlib@1.3.2-r0",
"zstd-libs@1.5.7-r2",
"zstd@1.5.7-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:e22124318c23791fa7e066f4281f078493b426be",
"AnalyzedBy": "apk"
},
{
"ID": "alpine-baselayout@3.7.2-r1",
"Name": "alpine-baselayout",
"Identifier": {
"PURL": "pkg:apk/alpine/alpine-baselayout@3.7.2-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "1b9c543300f8073e"
},
"Version": "3.7.2-r1",
"Arch": "x86_64",
"SrcName": "alpine-baselayout",
"SrcVersion": "3.7.2-r1",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"alpine-baselayout-data@3.7.2-r1",
"busybox-binsh@1.37.0-r31"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:f0fcfdc2f4da058af6473bc45c4eab62916225b2",
"InstalledFiles": [
"etc/motd",
"etc/crontabs/root",
"etc/modprobe.d/aliases.conf",
"etc/modprobe.d/blacklist.conf",
"etc/modprobe.d/i386.conf",
"etc/profile.d/20locale.sh",
"etc/profile.d/README",
"etc/profile.d/color_prompt.sh.disabled",
"usr/lib/sysctl.d/00-alpine.conf",
"var/lock",
"var/run",
"var/spool/mail",
"var/spool/cron/crontabs"
],
"AnalyzedBy": "apk"
},
{
"ID": "alpine-baselayout-data@3.7.2-r1",
"Name": "alpine-baselayout-data",
"Identifier": {
"PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.2-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "fcc3cd90122d8aa7"
},
"Version": "3.7.2-r1",
"Arch": "x86_64",
"SrcName": "alpine-baselayout",
"SrcVersion": "3.7.2-r1",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:c6f9bded17d844b6f1b0bb5766d2c35c0d5c8508",
"InstalledFiles": [
"etc/fstab",
"etc/group",
"etc/hostname",
"etc/hosts",
"etc/inittab",
"etc/modules",
"etc/mtab",
"etc/nsswitch.conf",
"etc/passwd",
"etc/profile",
"etc/protocols",
"etc/services",
"etc/shadow",
"etc/shells",
"etc/sysctl.conf"
],
"AnalyzedBy": "apk"
},
{
"ID": "alpine-keys@2.6-r0",
"Name": "alpine-keys",
"Identifier": {
"PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "cb1f6c8fa74713e0"
},
"Version": "2.6-r0",
"Arch": "x86_64",
"SrcName": "alpine-keys",
"SrcVersion": "2.6-r0",
"Licenses": [
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:d8d6b80e53c059a77e4915da78ba964f3ffea240",
"InstalledFiles": [
"etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub",
"etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub",
"etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub",
"usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub",
"usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub",
"usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub",
"usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub",
"usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub",
"usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub",
"usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub",
"usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub",
"usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub",
"usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub",
"usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub",
"usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub",
"usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub",
"usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub",
"usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub",
"usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub",
"usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub",
"usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub",
"usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub",
"usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub",
"usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub"
],
"AnalyzedBy": "apk"
},
{
"ID": "alpine-release@3.24.1-r0",
"Name": "alpine-release",
"Identifier": {
"PURL": "pkg:apk/alpine/alpine-release@3.24.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "6cfad6f36e1f31aa"
},
"Version": "3.24.1-r0",
"Arch": "x86_64",
"SrcName": "alpine-base",
"SrcVersion": "3.24.1-r0",
"Licenses": [
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"alpine-keys@2.6-r0"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:bc6912a25cdc7733e0035ed509eceaa4026946e3",
"InstalledFiles": [
"etc/alpine-release",
"etc/issue",
"etc/os-release",
"etc/secfixes.d/alpine",
"usr/lib/os-release"
],
"AnalyzedBy": "apk"
},
{
"ID": "apk-tools@3.0.6-r0",
"Name": "apk-tools",
"Identifier": {
"PURL": "pkg:apk/alpine/apk-tools@3.0.6-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "c6097cc137f3de8c"
},
"Version": "3.0.6-r0",
"Arch": "x86_64",
"SrcName": "apk-tools",
"SrcVersion": "3.0.6-r0",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"ca-certificates-bundle@20260611-r0",
"libapk@3.0.6-r0",
"libcrypto3@3.5.7-r0",
"musl@1.2.6-r2",
"zlib@1.3.2-r0"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:043333589798a1f52e09ae63f026c6c8fa676d34",
"InstalledFiles": [
"sbin/apk"
],
"AnalyzedBy": "apk"
},
{
"ID": "bash@5.3.9-r1",
"Name": "bash",
"Identifier": {
"PURL": "pkg:apk/alpine/bash@5.3.9-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "89d1544dc9bae858"
},
"Version": "5.3.9-r1",
"Arch": "x86_64",
"SrcName": "bash",
"SrcVersion": "5.3.9-r1",
"Licenses": [
"GPL-3.0-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"busybox-binsh@1.37.0-r31",
"musl@1.2.6-r2",
"readline@8.3.3-r1"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:2ce9606f1c31438297b40df5875dbceb66afb675",
"InstalledFiles": [
"bin/bash",
"etc/bash/bashrc",
"etc/profile.d/00-bashrc.sh",
"usr/lib/bash/accept",
"usr/lib/bash/basename",
"usr/lib/bash/chmod",
"usr/lib/bash/csv",
"usr/lib/bash/cut",
"usr/lib/bash/dirname",
"usr/lib/bash/dsv",
"usr/lib/bash/fdflags",
"usr/lib/bash/finfo",
"usr/lib/bash/fltexpr",
"usr/lib/bash/getconf",
"usr/lib/bash/head",
"usr/lib/bash/id",
"usr/lib/bash/kv",
"usr/lib/bash/ln",
"usr/lib/bash/logname",
"usr/lib/bash/mkdir",
"usr/lib/bash/mkfifo",
"usr/lib/bash/mktemp",
"usr/lib/bash/mypid",
"usr/lib/bash/pathchk",
"usr/lib/bash/print",
"usr/lib/bash/printenv",
"usr/lib/bash/push",
"usr/lib/bash/realpath",
"usr/lib/bash/rm",
"usr/lib/bash/rmdir",
"usr/lib/bash/seq",
"usr/lib/bash/setpgid",
"usr/lib/bash/sleep",
"usr/lib/bash/stat",
"usr/lib/bash/strftime",
"usr/lib/bash/strptime",
"usr/lib/bash/sync",
"usr/lib/bash/tee",
"usr/lib/bash/truefalse",
"usr/lib/bash/tty",
"usr/lib/bash/uname",
"usr/lib/bash/unlink",
"usr/lib/bash/whoami"
],
"AnalyzedBy": "apk"
},
{
"ID": "busybox@1.37.0-r31",
"Name": "busybox",
"Identifier": {
"PURL": "pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64\u0026distro=3.24.1",
"UID": "771020c43c8440bf"
},
"Version": "1.37.0-r31",
"Arch": "x86_64",
"SrcName": "busybox",
"SrcVersion": "1.37.0-r31",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:b5405ebc02f7dd8be95b6265c54b243d5456ab8f",
"InstalledFiles": [
"bin/busybox",
"etc/securetty",
"etc/busybox-paths.d/busybox",
"etc/logrotate.d/acpid",
"etc/network/if-up.d/dad",
"etc/udhcpc/udhcpc.conf",
"usr/share/udhcpc/default.script"
],
"AnalyzedBy": "apk"
},
{
"ID": "busybox-binsh@1.37.0-r31",
"Name": "busybox-binsh",
"Identifier": {
"PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64\u0026distro=3.24.1",
"UID": "1ec8a3d5d2b63297"
},
"Version": "1.37.0-r31",
"Arch": "x86_64",
"SrcName": "busybox",
"SrcVersion": "1.37.0-r31",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
"DependsOn": [
"busybox@1.37.0-r31"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:5cbd14acc6f1804c5bac6c77dc2c492f010b0fc7",
"InstalledFiles": [
"bin/sh"
],
"AnalyzedBy": "apk"
},
{
"ID": "ca-certificates-bundle@20260611-r0",
"Name": "ca-certificates-bundle",
"Identifier": {
"PURL": "pkg:apk/alpine/ca-certificates-bundle@20260611-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "20337c2ea28bef28"
},
"Version": "20260611-r0",
"Arch": "x86_64",
"SrcName": "ca-certificates",
"SrcVersion": "20260611-r0",
"Licenses": [
"MPL-2.0",
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:c9534a03750bdfae341f10969016090fc11febbd",
"InstalledFiles": [
"etc/ssl/cert.pem",
"etc/ssl/certs/ca-certificates.crt",
"etc/ssl1.1/cert.pem",
"etc/ssl1.1/certs"
],
"AnalyzedBy": "apk"
},
{
"ID": "gdbm@1.26-r0",
"Name": "gdbm",
"Identifier": {
"PURL": "pkg:apk/alpine/gdbm@1.26-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "5eb1a3f86262ca77"
},
"Version": "1.26-r0",
"Arch": "x86_64",
"SrcName": "gdbm",
"SrcVersion": "1.26-r0",
"Licenses": [
"GPL-3.0-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:619493d8124fe49a8ee1d8f7a1372cf7e3977337",
"InstalledFiles": [
"usr/lib/libgdbm.so.6",
"usr/lib/libgdbm.so.6.0.0",
"usr/lib/libgdbm_compat.so.4",
"usr/lib/libgdbm_compat.so.4.0.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "icu-data-full@78.1-r0",
"Name": "icu-data-full",
"Identifier": {
"PURL": "pkg:apk/alpine/icu-data-full@78.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "4fa30f43b2e5f036"
},
"Version": "78.1-r0",
"Arch": "x86_64",
"SrcName": "icu",
"SrcVersion": "78.1-r0",
"Licenses": [
"ICU"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:1a2db5e6bc16c62c85c29cfc8897570f9051cf14",
"InstalledFiles": [
"usr/share/icu/78.1/icudt78l.dat"
],
"AnalyzedBy": "apk"
},
{
"ID": "icu-libs@78.1-r0",
"Name": "icu-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/icu-libs@78.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "66c4aa79b293e4ff"
},
"Version": "78.1-r0",
"Arch": "x86_64",
"SrcName": "icu",
"SrcVersion": "78.1-r0",
"Licenses": [
"ICU"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"icu-data-full@78.1-r0",
"libgcc@15.2.0-r5",
"libstdc++@15.2.0-r5",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:46bd3617f6d112f035d806d24c5cf8ea6e597f50",
"InstalledFiles": [
"usr/lib/libicudata.so.78",
"usr/lib/libicudata.so.78.1",
"usr/lib/libicui18n.so.78",
"usr/lib/libicui18n.so.78.1",
"usr/lib/libicuio.so.78",
"usr/lib/libicuio.so.78.1",
"usr/lib/libicuuc.so.78",
"usr/lib/libicuuc.so.78.1"
],
"AnalyzedBy": "apk"
},
{
"ID": "keyutils-libs@1.6.3-r4",
"Name": "keyutils-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/keyutils-libs@1.6.3-r4?arch=x86_64\u0026distro=3.24.1",
"UID": "a1a29120eb342032"
},
"Version": "1.6.3-r4",
"Arch": "x86_64",
"SrcName": "keyutils",
"SrcVersion": "1.6.3-r4",
"Licenses": [
"GPL-2.0-or-later",
"LGPL-2.0-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:b7331c96f077fc3522ee4361a441d1097204cd90",
"InstalledFiles": [
"usr/lib/libkeyutils.so.1",
"usr/lib/libkeyutils.so.1.10"
],
"AnalyzedBy": "apk"
},
{
"ID": "krb5-conf@1.0-r2",
"Name": "krb5-conf",
"Identifier": {
"PURL": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "e7cf94ba8b6dbc33"
},
"Version": "1.0-r2",
"Arch": "x86_64",
"SrcName": "krb5-conf",
"SrcVersion": "1.0-r2",
"Licenses": [
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:40a11e0690a59e110367b62a80661024e9942a2d",
"InstalledFiles": [
"etc/krb5.conf"
],
"AnalyzedBy": "apk"
},
{
"ID": "krb5-libs@1.22.2-r1",
"Name": "krb5-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/krb5-libs@1.22.2-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "b2a26eefd488c92b"
},
"Version": "1.22.2-r1",
"Arch": "x86_64",
"SrcName": "krb5",
"SrcVersion": "1.22.2-r1",
"Licenses": [
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"keyutils-libs@1.6.3-r4",
"krb5-conf@1.0-r2",
"libcom_err@1.47.4-r0",
"libcrypto3@3.5.7-r0",
"libssl3@3.5.7-r0",
"libverto@0.3.2-r2",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:ef02346e21b817ff379e4601e5b1fc9760e5e31a",
"InstalledFiles": [
"usr/lib/libgssapi_krb5.so.2",
"usr/lib/libgssapi_krb5.so.2.2",
"usr/lib/libgssrpc.so.4",
"usr/lib/libgssrpc.so.4.2",
"usr/lib/libk5crypto.so.3",
"usr/lib/libk5crypto.so.3.1",
"usr/lib/libkadm5clnt_mit.so.12",
"usr/lib/libkadm5clnt_mit.so.12.0",
"usr/lib/libkadm5srv_mit.so.12",
"usr/lib/libkadm5srv_mit.so.12.0",
"usr/lib/libkdb5.so.10",
"usr/lib/libkdb5.so.10.0",
"usr/lib/libkrad.so.0",
"usr/lib/libkrad.so.0.0",
"usr/lib/libkrb5.so.3",
"usr/lib/libkrb5.so.3.3",
"usr/lib/libkrb5support.so.0",
"usr/lib/libkrb5support.so.0.1",
"usr/lib/krb5/plugins/kdb/db2.so",
"usr/lib/krb5/plugins/preauth/otp.so",
"usr/lib/krb5/plugins/preauth/spake.so",
"usr/lib/krb5/plugins/preauth/test.so",
"usr/lib/krb5/plugins/tls/k5tls.so"
],
"AnalyzedBy": "apk"
},
{
"ID": "libapk@3.0.6-r0",
"Name": "libapk",
"Identifier": {
"PURL": "pkg:apk/alpine/libapk@3.0.6-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "99b3039c6c4890c4"
},
"Version": "3.0.6-r0",
"Arch": "x86_64",
"SrcName": "apk-tools",
"SrcVersion": "3.0.6-r0",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"libcrypto3@3.5.7-r0",
"libssl3@3.5.7-r0",
"musl@1.2.6-r2",
"zlib@1.3.2-r0"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:523a8f58104589f74f743d501c81bf6517155378",
"InstalledFiles": [
"usr/lib/libapk.so.3.0.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "libcom_err@1.47.4-r0",
"Name": "libcom_err",
"Identifier": {
"PURL": "pkg:apk/alpine/libcom_err@1.47.4-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "3fc35a3f66d192af"
},
"Version": "1.47.4-r0",
"Arch": "x86_64",
"SrcName": "e2fsprogs",
"SrcVersion": "1.47.4-r0",
"Licenses": [
"GPL-2.0-or-later",
"LGPL-2.0-or-later",
"BSD-3-Clause",
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:4b9fb5899ea0b1c0cfbb2a2c5952704437d4ecef",
"InstalledFiles": [
"usr/lib/libcom_err.so.2",
"usr/lib/libcom_err.so.2.1"
],
"AnalyzedBy": "apk"
},
{
"ID": "libcrypto3@3.5.7-r0",
"Name": "libcrypto3",
"Identifier": {
"PURL": "pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "9ce2cdb3f0bf014b"
},
"Version": "3.5.7-r0",
"Arch": "x86_64",
"SrcName": "openssl",
"SrcVersion": "3.5.7-r0",
"Licenses": [
"Apache-2.0"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:481afbc52bcf06f2316c93a0a81ce8f72bed503e",
"InstalledFiles": [
"etc/ssl/ct_log_list.cnf",
"etc/ssl/ct_log_list.cnf.dist",
"etc/ssl/openssl.cnf",
"etc/ssl/openssl.cnf.dist",
"usr/lib/libcrypto.so.3",
"usr/lib/engines-3/afalg.so",
"usr/lib/engines-3/capi.so",
"usr/lib/engines-3/loader_attic.so",
"usr/lib/engines-3/padlock.so",
"usr/lib/ossl-modules/legacy.so"
],
"AnalyzedBy": "apk"
},
{
"ID": "libedit@20260508.3.1-r1",
"Name": "libedit",
"Identifier": {
"PURL": "pkg:apk/alpine/libedit@20260508.3.1-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "98a763e822f29606"
},
"Version": "20260508.3.1-r1",
"Arch": "x86_64",
"SrcName": "libedit",
"SrcVersion": "20260508.3.1-r1",
"Licenses": [
"BSD-3-Clause"
],
"Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e",
"DependsOn": [
"libncursesw@6.6_p20260516-r0",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:4084f8ff8e83fe17ce0c9ec3f313604d6adc7481",
"InstalledFiles": [
"usr/lib/libedit.so.0",
"usr/lib/libedit.so.0.0.77"
],
"AnalyzedBy": "apk"
},
{
"ID": "libffi@3.5.2-r1",
"Name": "libffi",
"Identifier": {
"PURL": "pkg:apk/alpine/libffi@3.5.2-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "d3eaa921287b1ccd"
},
"Version": "3.5.2-r1",
"Arch": "x86_64",
"SrcName": "libffi",
"SrcVersion": "3.5.2-r1",
"Licenses": [
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:2f7b261f7fcecc4eebd8b330e7f6fb80713bfe3a",
"InstalledFiles": [
"usr/lib/libffi.so.8",
"usr/lib/libffi.so.8.2.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "libgcc@15.2.0-r5",
"Name": "libgcc",
"Identifier": {
"PURL": "pkg:apk/alpine/libgcc@15.2.0-r5?arch=x86_64\u0026distro=3.24.1",
"UID": "8cf3d813d20beeee"
},
"Version": "15.2.0-r5",
"Arch": "x86_64",
"SrcName": "gcc",
"SrcVersion": "15.2.0-r5",
"Licenses": [
"GPL-2.0-or-later",
"LGPL-2.1-or-later"
],
"Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:379c156c53e0cc140e87c79c0a3dd22b6ee51552",
"InstalledFiles": [
"usr/lib/libgcc_s.so.1"
],
"AnalyzedBy": "apk"
},
{
"ID": "libldap@2.6.14-r0",
"Name": "libldap",
"Identifier": {
"PURL": "pkg:apk/alpine/libldap@2.6.14-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "2094cbf3bb65575a"
},
"Version": "2.6.14-r0",
"Arch": "x86_64",
"SrcName": "openldap",
"SrcVersion": "2.6.14-r0",
"Licenses": [
"OLDAP-2.8"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"libcrypto3@3.5.7-r0",
"libsasl@2.1.28-r9",
"libssl3@3.5.7-r0",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:112ff31072f41119840e739c4195b6f2489fe048",
"InstalledFiles": [
"etc/openldap/ldap.conf",
"usr/lib/liblber.so.2",
"usr/lib/liblber.so.2.0.200",
"usr/lib/libldap.so.2",
"usr/lib/libldap.so.2.0.200"
],
"AnalyzedBy": "apk"
},
{
"ID": "libncursesw@6.6_p20260516-r0",
"Name": "libncursesw",
"Identifier": {
"PURL": "pkg:apk/alpine/libncursesw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "e8939f45e2191bcc"
},
"Version": "6.6_p20260516-r0",
"Arch": "x86_64",
"SrcName": "ncurses",
"SrcVersion": "6.6_p20260516-r0",
"Licenses": [
"X-11"
],
"Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e",
"DependsOn": [
"musl@1.2.6-r2",
"ncurses-terminfo-base@6.6_p20260516-r0"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:9f318e6e324d6827274829194cf6ac6afbaded12",
"InstalledFiles": [
"usr/lib/libncursesw.so.6",
"usr/lib/libncursesw.so.6.6"
],
"AnalyzedBy": "apk"
},
{
"ID": "libsasl@2.1.28-r9",
"Name": "libsasl",
"Identifier": {
"PURL": "pkg:apk/alpine/libsasl@2.1.28-r9?arch=x86_64\u0026distro=3.24.1",
"UID": "28cd83afcf08300b"
},
"Version": "2.1.28-r9",
"Arch": "x86_64",
"SrcName": "cyrus-sasl",
"SrcVersion": "2.1.28-r9",
"Licenses": [
"BSD-3-Clause-Attribution",
"BSD-4-Clause"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"gdbm@1.26-r0",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:422ebe8defd4a2d2aaea34662f6ff853cfc2f95f",
"InstalledFiles": [
"usr/lib/libsasl2.so.3",
"usr/lib/libsasl2.so.3.0.0",
"usr/lib/sasl2/libanonymous.so",
"usr/lib/sasl2/libanonymous.so.3",
"usr/lib/sasl2/libanonymous.so.3.0.0",
"usr/lib/sasl2/libplain.so",
"usr/lib/sasl2/libplain.so.3",
"usr/lib/sasl2/libplain.so.3.0.0",
"usr/lib/sasl2/libsasldb.so",
"usr/lib/sasl2/libsasldb.so.3",
"usr/lib/sasl2/libsasldb.so.3.0.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "libssl3@3.5.7-r0",
"Name": "libssl3",
"Identifier": {
"PURL": "pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "a25152af95b643e0"
},
"Version": "3.5.7-r0",
"Arch": "x86_64",
"SrcName": "openssl",
"SrcVersion": "3.5.7-r0",
"Licenses": [
"Apache-2.0"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"libcrypto3@3.5.7-r0",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:240c8252d1ca145873c03c997966698eb509f745",
"InstalledFiles": [
"usr/lib/libssl.so.3"
],
"AnalyzedBy": "apk"
},
{
"ID": "libstdc++@15.2.0-r5",
"Name": "libstdc++",
"Identifier": {
"PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r5?arch=x86_64\u0026distro=3.24.1",
"UID": "2eed307edf277aae"
},
"Version": "15.2.0-r5",
"Arch": "x86_64",
"SrcName": "gcc",
"SrcVersion": "15.2.0-r5",
"Licenses": [
"GPL-2.0-or-later",
"LGPL-2.1-or-later"
],
"Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
"DependsOn": [
"libgcc@15.2.0-r5",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:5f7a2ad7646128ba02cc0d6fb94672b6845648d5",
"InstalledFiles": [
"usr/lib/libstdc++.so.6",
"usr/lib/libstdc++.so.6.0.34"
],
"AnalyzedBy": "apk"
},
{
"ID": "libuuid@2.42.1-r0",
"Name": "libuuid",
"Identifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"Version": "2.42.1-r0",
"Arch": "x86_64",
"SrcName": "util-linux",
"SrcVersion": "2.42.1-r0",
"Licenses": [
"BSD-3-Clause"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:6acb0e27112dfb784e6f7ccceb0e968fafa09713",
"InstalledFiles": [
"usr/lib/libuuid.so.1",
"usr/lib/libuuid.so.1.3.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "libverto@0.3.2-r2",
"Name": "libverto",
"Identifier": {
"PURL": "pkg:apk/alpine/libverto@0.3.2-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "9df4321a283a6cf6"
},
"Version": "0.3.2-r2",
"Arch": "x86_64",
"SrcName": "libverto",
"SrcVersion": "0.3.2-r2",
"Licenses": [
"MIT"
],
"Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:73233059338142e4ac6d8fb8bb0074e93da75dc1",
"InstalledFiles": [
"usr/lib/libverto.so.1",
"usr/lib/libverto.so.1.0.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "libxml2@2.13.9-r2",
"Name": "libxml2",
"Identifier": {
"PURL": "pkg:apk/alpine/libxml2@2.13.9-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "661e2a4b0a2b6c43"
},
"Version": "2.13.9-r2",
"Arch": "x86_64",
"SrcName": "libxml2",
"SrcVersion": "2.13.9-r2",
"Licenses": [
"MIT"
],
"Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2",
"xz-libs@5.8.3-r0",
"zlib@1.3.2-r0"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:c2c2cb44647ddc8c82ae78c8aca9bd4ad5a736da",
"InstalledFiles": [
"usr/lib/libxml2.so.2",
"usr/lib/libxml2.so.2.13.9"
],
"AnalyzedBy": "apk"
},
{
"ID": "libxslt@1.1.43-r3",
"Name": "libxslt",
"Identifier": {
"PURL": "pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64\u0026distro=3.24.1",
"UID": "2810f2fbfcee454a"
},
"Version": "1.1.43-r3",
"Arch": "x86_64",
"SrcName": "libxslt",
"SrcVersion": "1.1.43-r3",
"Licenses": [
"X-11"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"libxml2@2.13.9-r2",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:a78a1c96aa4f4a763ab8d2eeb285734c0387eb31",
"InstalledFiles": [
"usr/bin/xsltproc",
"usr/lib/libexslt.so.0",
"usr/lib/libexslt.so.0.8.24",
"usr/lib/libxslt.so.1",
"usr/lib/libxslt.so.1.1.43"
],
"AnalyzedBy": "apk"
},
{
"ID": "llvm21-libs@21.1.8-r1",
"Name": "llvm21-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/llvm21-libs@21.1.8-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "b4a6fa05ae868a0d"
},
"Version": "21.1.8-r1",
"Arch": "x86_64",
"SrcName": "llvm21",
"SrcVersion": "21.1.8-r1",
"Licenses": [
"Apache-2.0"
],
"Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e",
"DependsOn": [
"libffi@3.5.2-r1",
"libgcc@15.2.0-r5",
"libstdc++@15.2.0-r5",
"libxml2@2.13.9-r2",
"musl@1.2.6-r2",
"zlib@1.3.2-r0",
"zstd-libs@1.5.7-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:d9f9cafee3a86cc6103c92614ea769b3a169cff3",
"InstalledFiles": [
"usr/lib/libLLVM-21.so",
"usr/lib/libLLVM.so.21.1",
"usr/lib/llvm21/lib/libLLVM.so.21.1"
],
"AnalyzedBy": "apk"
},
{
"ID": "lz4-libs@1.10.0-r1",
"Name": "lz4-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/lz4-libs@1.10.0-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "697c5d416b5775fb"
},
"Version": "1.10.0-r1",
"Arch": "x86_64",
"SrcName": "lz4",
"SrcVersion": "1.10.0-r1",
"Licenses": [
"BSD-2-Clause",
"GPL-2.0-or-later"
],
"Maintainer": "Stuart Cardall \u003cdeveloper@it-offshore.co.uk\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:d63bb2e1707aa4ca0b75a867706ea03df70bc5bd",
"InstalledFiles": [
"usr/lib/liblz4.so.1",
"usr/lib/liblz4.so.1.10.0"
],
"AnalyzedBy": "apk"
},
{
"ID": "musl@1.2.6-r2",
"Name": "musl",
"Identifier": {
"PURL": "pkg:apk/alpine/musl@1.2.6-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "1f8cb44befe503d4"
},
"Version": "1.2.6-r2",
"Arch": "x86_64",
"SrcName": "musl",
"SrcVersion": "1.2.6-r2",
"Licenses": [
"MIT"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:0f7e5827e4e1a73631beda27b78431a8ba240e05",
"InstalledFiles": [
"lib/ld-musl-x86_64.so.1",
"lib/libc.musl-x86_64.so.1"
],
"AnalyzedBy": "apk"
},
{
"ID": "musl-utils@1.2.6-r2",
"Name": "musl-utils",
"Identifier": {
"PURL": "pkg:apk/alpine/musl-utils@1.2.6-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "4497482ec1d943e1"
},
"Version": "1.2.6-r2",
"Arch": "x86_64",
"SrcName": "musl",
"SrcVersion": "1.2.6-r2",
"Licenses": [
"MIT",
"BSD-2-Clause",
"GPL-2.0-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2",
"scanelf@1.3.9-r1"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:75ada3c48d63ec5d87c42fdf934a3fdd11298dc5",
"InstalledFiles": [
"sbin/ldconfig",
"usr/bin/getconf",
"usr/bin/getent",
"usr/bin/iconv",
"usr/bin/ldd"
],
"AnalyzedBy": "apk"
},
{
"ID": "ncurses-terminfo-base@6.6_p20260516-r0",
"Name": "ncurses-terminfo-base",
"Identifier": {
"PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "e7fac5c6a6e9ae8"
},
"Version": "6.6_p20260516-r0",
"Arch": "x86_64",
"SrcName": "ncurses",
"SrcVersion": "6.6_p20260516-r0",
"Licenses": [
"X-11"
],
"Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:9d551d828e9c8ee52c5801c1d6046828ebf15752",
"InstalledFiles": [
"etc/terminfo/a/alacritty",
"etc/terminfo/a/ansi",
"etc/terminfo/d/dumb",
"etc/terminfo/g/gnome",
"etc/terminfo/g/gnome-256color",
"etc/terminfo/k/konsole",
"etc/terminfo/k/konsole-256color",
"etc/terminfo/k/konsole-linux",
"etc/terminfo/l/linux",
"etc/terminfo/p/putty",
"etc/terminfo/p/putty-256color",
"etc/terminfo/r/rxvt",
"etc/terminfo/r/rxvt-256color",
"etc/terminfo/s/screen",
"etc/terminfo/s/screen-256color",
"etc/terminfo/s/st-0.6",
"etc/terminfo/s/st-0.7",
"etc/terminfo/s/st-0.8",
"etc/terminfo/s/st-0.8.5",
"etc/terminfo/s/st-16color",
"etc/terminfo/s/st-256color",
"etc/terminfo/s/st-direct",
"etc/terminfo/s/sun",
"etc/terminfo/t/terminator",
"etc/terminfo/t/terminology",
"etc/terminfo/t/terminology-0.6.1",
"etc/terminfo/t/terminology-1.0.0",
"etc/terminfo/t/terminology-1.8.1",
"etc/terminfo/t/tmux",
"etc/terminfo/t/tmux-256color",
"etc/terminfo/v/vt100",
"etc/terminfo/v/vt102",
"etc/terminfo/v/vt200",
"etc/terminfo/v/vt220",
"etc/terminfo/v/vt52",
"etc/terminfo/v/vte",
"etc/terminfo/v/vte-256color",
"etc/terminfo/x/xterm",
"etc/terminfo/x/xterm-256color",
"etc/terminfo/x/xterm-color",
"etc/terminfo/x/xterm-xfree86"
],
"AnalyzedBy": "apk"
},
{
"ID": "nss_wrapper@1.1.12-r1",
"Name": "nss_wrapper",
"Identifier": {
"PURL": "pkg:apk/alpine/nss_wrapper@1.1.12-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "da8371470b181c32"
},
"Version": "1.1.12-r1",
"Arch": "x86_64",
"SrcName": "nss_wrapper",
"SrcVersion": "1.1.12-r1",
"Licenses": [
"BSD-3-Clause"
],
"Maintainer": "Wolfgang Walther \u003copensource@technowledgy.de\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:46b34dd323a8388eb2480dc65ee56d9179148ffe",
"InstalledFiles": [
"usr/lib/libnss_wrapper.so",
"usr/lib/libnss_wrapper.so.0",
"usr/lib/libnss_wrapper.so.0.3.2"
],
"AnalyzedBy": "apk"
},
{
"ID": "readline@8.3.3-r1",
"Name": "readline",
"Identifier": {
"PURL": "pkg:apk/alpine/readline@8.3.3-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "f50058781c93e1f2"
},
"Version": "8.3.3-r1",
"Arch": "x86_64",
"SrcName": "readline",
"SrcVersion": "8.3.3-r1",
"Licenses": [
"GPL-3.0-or-later"
],
"Maintainer": "qaqland \u003cqaq@qaq.land\u003e",
"DependsOn": [
"libncursesw@6.6_p20260516-r0",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:945b16e378bc00e44d89d4de8124bba7647fdf4d",
"InstalledFiles": [
"etc/inputrc",
"usr/lib/libreadline.so.8",
"usr/lib/libreadline.so.8.3"
],
"AnalyzedBy": "apk"
},
{
"ID": "scanelf@1.3.9-r1",
"Name": "scanelf",
"Identifier": {
"PURL": "pkg:apk/alpine/scanelf@1.3.9-r1?arch=x86_64\u0026distro=3.24.1",
"UID": "936394657a1626fb"
},
"Version": "1.3.9-r1",
"Arch": "x86_64",
"SrcName": "pax-utils",
"SrcVersion": "1.3.9-r1",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:013f903d0ba219673aebbdd04f74bb5ed82b01f0",
"InstalledFiles": [
"usr/bin/scanelf"
],
"AnalyzedBy": "apk"
},
{
"ID": "ssl_client@1.37.0-r31",
"Name": "ssl_client",
"Identifier": {
"PURL": "pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64\u0026distro=3.24.1",
"UID": "2884df80ae89778e"
},
"Version": "1.37.0-r31",
"Arch": "x86_64",
"SrcName": "busybox",
"SrcVersion": "1.37.0-r31",
"Licenses": [
"GPL-2.0-only"
],
"Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
"DependsOn": [
"libcrypto3@3.5.7-r0",
"libssl3@3.5.7-r0",
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:c220f4a5125a313af733e98def94132bb1e9d40d",
"InstalledFiles": [
"usr/bin/ssl_client"
],
"AnalyzedBy": "apk"
},
{
"ID": "tzdata@2026c-r0",
"Name": "tzdata",
"Identifier": {
"PURL": "pkg:apk/alpine/tzdata@2026c-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "52c6b50eff629f9d"
},
"Version": "2026c-r0",
"Arch": "x86_64",
"SrcName": "tzdata",
"SrcVersion": "2026c-r0",
"Licenses": [
"Public-Domain"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:61f7544ecd8dd63eac23fe3e645702fda92ef02a",
"InstalledFiles": [
"usr/share/zoneinfo/CET",
"usr/share/zoneinfo/CST6CDT",
"usr/share/zoneinfo/Cuba",
"usr/share/zoneinfo/EET",
"usr/share/zoneinfo/EST",
"usr/share/zoneinfo/EST5EDT",
"usr/share/zoneinfo/Egypt",
"usr/share/zoneinfo/Eire",
"usr/share/zoneinfo/Factory",
"usr/share/zoneinfo/GB",
"usr/share/zoneinfo/GB-Eire",
"usr/share/zoneinfo/GMT",
"usr/share/zoneinfo/GMT+0",
"usr/share/zoneinfo/GMT-0",
"usr/share/zoneinfo/GMT0",
"usr/share/zoneinfo/Greenwich",
"usr/share/zoneinfo/HST",
"usr/share/zoneinfo/Hongkong",
"usr/share/zoneinfo/Iceland",
"usr/share/zoneinfo/Iran",
"usr/share/zoneinfo/Israel",
"usr/share/zoneinfo/Jamaica",
"usr/share/zoneinfo/Japan",
"usr/share/zoneinfo/Kwajalein",
"usr/share/zoneinfo/Libya",
"usr/share/zoneinfo/MET",
"usr/share/zoneinfo/MST",
"usr/share/zoneinfo/MST7MDT",
"usr/share/zoneinfo/NZ",
"usr/share/zoneinfo/NZ-CHAT",
"usr/share/zoneinfo/Navajo",
"usr/share/zoneinfo/PRC",
"usr/share/zoneinfo/PST8PDT",
"usr/share/zoneinfo/Poland",
"usr/share/zoneinfo/Portugal",
"usr/share/zoneinfo/ROC",
"usr/share/zoneinfo/ROK",
"usr/share/zoneinfo/Singapore",
"usr/share/zoneinfo/Turkey",
"usr/share/zoneinfo/UCT",
"usr/share/zoneinfo/UTC",
"usr/share/zoneinfo/Universal",
"usr/share/zoneinfo/W-SU",
"usr/share/zoneinfo/WET",
"usr/share/zoneinfo/Zulu",
"usr/share/zoneinfo/iso3166.tab",
"usr/share/zoneinfo/leap-seconds.list",
"usr/share/zoneinfo/posixrules",
"usr/share/zoneinfo/zone.tab",
"usr/share/zoneinfo/zone1970.tab",
"usr/share/zoneinfo/Africa/Abidjan",
"usr/share/zoneinfo/Africa/Accra",
"usr/share/zoneinfo/Africa/Addis_Ababa",
"usr/share/zoneinfo/Africa/Algiers",
"usr/share/zoneinfo/Africa/Asmara",
"usr/share/zoneinfo/Africa/Asmera",
"usr/share/zoneinfo/Africa/Bamako",
"usr/share/zoneinfo/Africa/Bangui",
"usr/share/zoneinfo/Africa/Banjul",
"usr/share/zoneinfo/Africa/Bissau",
"usr/share/zoneinfo/Africa/Blantyre",
"usr/share/zoneinfo/Africa/Brazzaville",
"usr/share/zoneinfo/Africa/Bujumbura",
"usr/share/zoneinfo/Africa/Cairo",
"usr/share/zoneinfo/Africa/Casablanca",
"usr/share/zoneinfo/Africa/Ceuta",
"usr/share/zoneinfo/Africa/Conakry",
"usr/share/zoneinfo/Africa/Dakar",
"usr/share/zoneinfo/Africa/Dar_es_Salaam",
"usr/share/zoneinfo/Africa/Djibouti",
"usr/share/zoneinfo/Africa/Douala",
"usr/share/zoneinfo/Africa/El_Aaiun",
"usr/share/zoneinfo/Africa/Freetown",
"usr/share/zoneinfo/Africa/Gaborone",
"usr/share/zoneinfo/Africa/Harare",
"usr/share/zoneinfo/Africa/Johannesburg",
"usr/share/zoneinfo/Africa/Juba",
"usr/share/zoneinfo/Africa/Kampala",
"usr/share/zoneinfo/Africa/Khartoum",
"usr/share/zoneinfo/Africa/Kigali",
"usr/share/zoneinfo/Africa/Kinshasa",
"usr/share/zoneinfo/Africa/Lagos",
"usr/share/zoneinfo/Africa/Libreville",
"usr/share/zoneinfo/Africa/Lome",
"usr/share/zoneinfo/Africa/Luanda",
"usr/share/zoneinfo/Africa/Lubumbashi",
"usr/share/zoneinfo/Africa/Lusaka",
"usr/share/zoneinfo/Africa/Malabo",
"usr/share/zoneinfo/Africa/Maputo",
"usr/share/zoneinfo/Africa/Maseru",
"usr/share/zoneinfo/Africa/Mbabane",
"usr/share/zoneinfo/Africa/Mogadishu",
"usr/share/zoneinfo/Africa/Monrovia",
"usr/share/zoneinfo/Africa/Nairobi",
"usr/share/zoneinfo/Africa/Ndjamena",
"usr/share/zoneinfo/Africa/Niamey",
"usr/share/zoneinfo/Africa/Nouakchott",
"usr/share/zoneinfo/Africa/Ouagadougou",
"usr/share/zoneinfo/Africa/Porto-Novo",
"usr/share/zoneinfo/Africa/Sao_Tome",
"usr/share/zoneinfo/Africa/Timbuktu",
"usr/share/zoneinfo/Africa/Tripoli",
"usr/share/zoneinfo/Africa/Tunis",
"usr/share/zoneinfo/Africa/Windhoek",
"usr/share/zoneinfo/America/Adak",
"usr/share/zoneinfo/America/Anchorage",
"usr/share/zoneinfo/America/Anguilla",
"usr/share/zoneinfo/America/Antigua",
"usr/share/zoneinfo/America/Araguaina",
"usr/share/zoneinfo/America/Aruba",
"usr/share/zoneinfo/America/Asuncion",
"usr/share/zoneinfo/America/Atikokan",
"usr/share/zoneinfo/America/Atka",
"usr/share/zoneinfo/America/Bahia",
"usr/share/zoneinfo/America/Bahia_Banderas",
"usr/share/zoneinfo/America/Barbados",
"usr/share/zoneinfo/America/Belem",
"usr/share/zoneinfo/America/Belize",
"usr/share/zoneinfo/America/Blanc-Sablon",
"usr/share/zoneinfo/America/Boa_Vista",
"usr/share/zoneinfo/America/Bogota",
"usr/share/zoneinfo/America/Boise",
"usr/share/zoneinfo/America/Buenos_Aires",
"usr/share/zoneinfo/America/Cambridge_Bay",
"usr/share/zoneinfo/America/Campo_Grande",
"usr/share/zoneinfo/America/Cancun",
"usr/share/zoneinfo/America/Caracas",
"usr/share/zoneinfo/America/Catamarca",
"usr/share/zoneinfo/America/Cayenne",
"usr/share/zoneinfo/America/Cayman",
"usr/share/zoneinfo/America/Chicago",
"usr/share/zoneinfo/America/Chihuahua",
"usr/share/zoneinfo/America/Ciudad_Juarez",
"usr/share/zoneinfo/America/Coral_Harbour",
"usr/share/zoneinfo/America/Cordoba",
"usr/share/zoneinfo/America/Costa_Rica",
"usr/share/zoneinfo/America/Coyhaique",
"usr/share/zoneinfo/America/Creston",
"usr/share/zoneinfo/America/Cuiaba",
"usr/share/zoneinfo/America/Curacao",
"usr/share/zoneinfo/America/Danmarkshavn",
"usr/share/zoneinfo/America/Dawson",
"usr/share/zoneinfo/America/Dawson_Creek",
"usr/share/zoneinfo/America/Denver",
"usr/share/zoneinfo/America/Detroit",
"usr/share/zoneinfo/America/Dominica",
"usr/share/zoneinfo/America/Edmonton",
"usr/share/zoneinfo/America/Eirunepe",
"usr/share/zoneinfo/America/El_Salvador",
"usr/share/zoneinfo/America/Ensenada",
"usr/share/zoneinfo/America/Fort_Nelson",
"usr/share/zoneinfo/America/Fort_Wayne",
"usr/share/zoneinfo/America/Fortaleza",
"usr/share/zoneinfo/America/Glace_Bay",
"usr/share/zoneinfo/America/Godthab",
"usr/share/zoneinfo/America/Goose_Bay",
"usr/share/zoneinfo/America/Grand_Turk",
"usr/share/zoneinfo/America/Grenada",
"usr/share/zoneinfo/America/Guadeloupe",
"usr/share/zoneinfo/America/Guatemala",
"usr/share/zoneinfo/America/Guayaquil",
"usr/share/zoneinfo/America/Guyana",
"usr/share/zoneinfo/America/Halifax",
"usr/share/zoneinfo/America/Havana",
"usr/share/zoneinfo/America/Hermosillo",
"usr/share/zoneinfo/America/Indianapolis",
"usr/share/zoneinfo/America/Inuvik",
"usr/share/zoneinfo/America/Iqaluit",
"usr/share/zoneinfo/America/Jamaica",
"usr/share/zoneinfo/America/Jujuy",
"usr/share/zoneinfo/America/Juneau",
"usr/share/zoneinfo/America/Knox_IN",
"usr/share/zoneinfo/America/Kralendijk",
"usr/share/zoneinfo/America/La_Paz",
"usr/share/zoneinfo/America/Lima",
"usr/share/zoneinfo/America/Los_Angeles",
"usr/share/zoneinfo/America/Louisville",
"usr/share/zoneinfo/America/Lower_Princes",
"usr/share/zoneinfo/America/Maceio",
"usr/share/zoneinfo/America/Managua",
"usr/share/zoneinfo/America/Manaus",
"usr/share/zoneinfo/America/Marigot",
"usr/share/zoneinfo/America/Martinique",
"usr/share/zoneinfo/America/Matamoros",
"usr/share/zoneinfo/America/Mazatlan",
"usr/share/zoneinfo/America/Mendoza",
"usr/share/zoneinfo/America/Menominee",
"usr/share/zoneinfo/America/Merida",
"usr/share/zoneinfo/America/Metlakatla",
"usr/share/zoneinfo/America/Mexico_City",
"usr/share/zoneinfo/America/Miquelon",
"usr/share/zoneinfo/America/Moncton",
"usr/share/zoneinfo/America/Monterrey",
"usr/share/zoneinfo/America/Montevideo",
"usr/share/zoneinfo/America/Montreal",
"usr/share/zoneinfo/America/Montserrat",
"usr/share/zoneinfo/America/Nassau",
"usr/share/zoneinfo/America/New_York",
"usr/share/zoneinfo/America/Nipigon",
"usr/share/zoneinfo/America/Nome",
"usr/share/zoneinfo/America/Noronha",
"usr/share/zoneinfo/America/Nuuk",
"usr/share/zoneinfo/America/Ojinaga",
"usr/share/zoneinfo/America/Panama",
"usr/share/zoneinfo/America/Pangnirtung",
"usr/share/zoneinfo/America/Paramaribo",
"usr/share/zoneinfo/America/Phoenix",
"usr/share/zoneinfo/America/Port-au-Prince",
"usr/share/zoneinfo/America/Port_of_Spain",
"usr/share/zoneinfo/America/Porto_Acre",
"usr/share/zoneinfo/America/Porto_Velho",
"usr/share/zoneinfo/America/Puerto_Rico",
"usr/share/zoneinfo/America/Punta_Arenas",
"usr/share/zoneinfo/America/Rainy_River",
"usr/share/zoneinfo/America/Rankin_Inlet",
"usr/share/zoneinfo/America/Recife",
"usr/share/zoneinfo/America/Regina",
"usr/share/zoneinfo/America/Resolute",
"usr/share/zoneinfo/America/Rio_Branco",
"usr/share/zoneinfo/America/Rosario",
"usr/share/zoneinfo/America/Santa_Isabel",
"usr/share/zoneinfo/America/Santarem",
"usr/share/zoneinfo/America/Santiago",
"usr/share/zoneinfo/America/Santo_Domingo",
"usr/share/zoneinfo/America/Sao_Paulo",
"usr/share/zoneinfo/America/Scoresbysund",
"usr/share/zoneinfo/America/Shiprock",
"usr/share/zoneinfo/America/Sitka",
"usr/share/zoneinfo/America/St_Barthelemy",
"usr/share/zoneinfo/America/St_Johns",
"usr/share/zoneinfo/America/St_Kitts",
"usr/share/zoneinfo/America/St_Lucia",
"usr/share/zoneinfo/America/St_Thomas",
"usr/share/zoneinfo/America/St_Vincent",
"usr/share/zoneinfo/America/Swift_Current",
"usr/share/zoneinfo/America/Tegucigalpa",
"usr/share/zoneinfo/America/Thule",
"usr/share/zoneinfo/America/Thunder_Bay",
"usr/share/zoneinfo/America/Tijuana",
"usr/share/zoneinfo/America/Toronto",
"usr/share/zoneinfo/America/Tortola",
"usr/share/zoneinfo/America/Vancouver",
"usr/share/zoneinfo/America/Virgin",
"usr/share/zoneinfo/America/Whitehorse",
"usr/share/zoneinfo/America/Winnipeg",
"usr/share/zoneinfo/America/Yakutat",
"usr/share/zoneinfo/America/Yellowknife",
"usr/share/zoneinfo/America/Argentina/Buenos_Aires",
"usr/share/zoneinfo/America/Argentina/Catamarca",
"usr/share/zoneinfo/America/Argentina/ComodRivadavia",
"usr/share/zoneinfo/America/Argentina/Cordoba",
"usr/share/zoneinfo/America/Argentina/Jujuy",
"usr/share/zoneinfo/America/Argentina/La_Rioja",
"usr/share/zoneinfo/America/Argentina/Mendoza",
"usr/share/zoneinfo/America/Argentina/Rio_Gallegos",
"usr/share/zoneinfo/America/Argentina/Salta",
"usr/share/zoneinfo/America/Argentina/San_Juan",
"usr/share/zoneinfo/America/Argentina/San_Luis",
"usr/share/zoneinfo/America/Argentina/Tucuman",
"usr/share/zoneinfo/America/Argentina/Ushuaia",
"usr/share/zoneinfo/America/Indiana/Indianapolis",
"usr/share/zoneinfo/America/Indiana/Knox",
"usr/share/zoneinfo/America/Indiana/Marengo",
"usr/share/zoneinfo/America/Indiana/Petersburg",
"usr/share/zoneinfo/America/Indiana/Tell_City",
"usr/share/zoneinfo/America/Indiana/Vevay",
"usr/share/zoneinfo/America/Indiana/Vincennes",
"usr/share/zoneinfo/America/Indiana/Winamac",
"usr/share/zoneinfo/America/Kentucky/Louisville",
"usr/share/zoneinfo/America/Kentucky/Monticello",
"usr/share/zoneinfo/America/North_Dakota/Beulah",
"usr/share/zoneinfo/America/North_Dakota/Center",
"usr/share/zoneinfo/America/North_Dakota/New_Salem",
"usr/share/zoneinfo/Antarctica/Casey",
"usr/share/zoneinfo/Antarctica/Davis",
"usr/share/zoneinfo/Antarctica/DumontDUrville",
"usr/share/zoneinfo/Antarctica/Macquarie",
"usr/share/zoneinfo/Antarctica/Mawson",
"usr/share/zoneinfo/Antarctica/McMurdo",
"usr/share/zoneinfo/Antarctica/Palmer",
"usr/share/zoneinfo/Antarctica/Rothera",
"usr/share/zoneinfo/Antarctica/South_Pole",
"usr/share/zoneinfo/Antarctica/Syowa",
"usr/share/zoneinfo/Antarctica/Troll",
"usr/share/zoneinfo/Antarctica/Vostok",
"usr/share/zoneinfo/Arctic/Longyearbyen",
"usr/share/zoneinfo/Asia/Aden",
"usr/share/zoneinfo/Asia/Almaty",
"usr/share/zoneinfo/Asia/Amman",
"usr/share/zoneinfo/Asia/Anadyr",
"usr/share/zoneinfo/Asia/Aqtau",
"usr/share/zoneinfo/Asia/Aqtobe",
"usr/share/zoneinfo/Asia/Ashgabat",
"usr/share/zoneinfo/Asia/Ashkhabad",
"usr/share/zoneinfo/Asia/Atyrau",
"usr/share/zoneinfo/Asia/Baghdad",
"usr/share/zoneinfo/Asia/Bahrain",
"usr/share/zoneinfo/Asia/Baku",
"usr/share/zoneinfo/Asia/Bangkok",
"usr/share/zoneinfo/Asia/Barnaul",
"usr/share/zoneinfo/Asia/Beirut",
"usr/share/zoneinfo/Asia/Bishkek",
"usr/share/zoneinfo/Asia/Brunei",
"usr/share/zoneinfo/Asia/Calcutta",
"usr/share/zoneinfo/Asia/Chita",
"usr/share/zoneinfo/Asia/Choibalsan",
"usr/share/zoneinfo/Asia/Chongqing",
"usr/share/zoneinfo/Asia/Chungking",
"usr/share/zoneinfo/Asia/Colombo",
"usr/share/zoneinfo/Asia/Dacca",
"usr/share/zoneinfo/Asia/Damascus",
"usr/share/zoneinfo/Asia/Dhaka",
"usr/share/zoneinfo/Asia/Dili",
"usr/share/zoneinfo/Asia/Dubai",
"usr/share/zoneinfo/Asia/Dushanbe",
"usr/share/zoneinfo/Asia/Famagusta",
"usr/share/zoneinfo/Asia/Gaza",
"usr/share/zoneinfo/Asia/Harbin",
"usr/share/zoneinfo/Asia/Hebron",
"usr/share/zoneinfo/Asia/Ho_Chi_Minh",
"usr/share/zoneinfo/Asia/Hong_Kong",
"usr/share/zoneinfo/Asia/Hovd",
"usr/share/zoneinfo/Asia/Irkutsk",
"usr/share/zoneinfo/Asia/Istanbul",
"usr/share/zoneinfo/Asia/Jakarta",
"usr/share/zoneinfo/Asia/Jayapura",
"usr/share/zoneinfo/Asia/Jerusalem",
"usr/share/zoneinfo/Asia/Kabul",
"usr/share/zoneinfo/Asia/Kamchatka",
"usr/share/zoneinfo/Asia/Karachi",
"usr/share/zoneinfo/Asia/Kashgar",
"usr/share/zoneinfo/Asia/Kathmandu",
"usr/share/zoneinfo/Asia/Katmandu",
"usr/share/zoneinfo/Asia/Khandyga",
"usr/share/zoneinfo/Asia/Kolkata",
"usr/share/zoneinfo/Asia/Krasnoyarsk",
"usr/share/zoneinfo/Asia/Kuala_Lumpur",
"usr/share/zoneinfo/Asia/Kuching",
"usr/share/zoneinfo/Asia/Kuwait",
"usr/share/zoneinfo/Asia/Macao",
"usr/share/zoneinfo/Asia/Macau",
"usr/share/zoneinfo/Asia/Magadan",
"usr/share/zoneinfo/Asia/Makassar",
"usr/share/zoneinfo/Asia/Manila",
"usr/share/zoneinfo/Asia/Muscat",
"usr/share/zoneinfo/Asia/Nicosia",
"usr/share/zoneinfo/Asia/Novokuznetsk",
"usr/share/zoneinfo/Asia/Novosibirsk",
"usr/share/zoneinfo/Asia/Omsk",
"usr/share/zoneinfo/Asia/Oral",
"usr/share/zoneinfo/Asia/Phnom_Penh",
"usr/share/zoneinfo/Asia/Pontianak",
"usr/share/zoneinfo/Asia/Pyongyang",
"usr/share/zoneinfo/Asia/Qatar",
"usr/share/zoneinfo/Asia/Qostanay",
"usr/share/zoneinfo/Asia/Qyzylorda",
"usr/share/zoneinfo/Asia/Rangoon",
"usr/share/zoneinfo/Asia/Riyadh",
"usr/share/zoneinfo/Asia/Saigon",
"usr/share/zoneinfo/Asia/Sakhalin",
"usr/share/zoneinfo/Asia/Samarkand",
"usr/share/zoneinfo/Asia/Seoul",
"usr/share/zoneinfo/Asia/Shanghai",
"usr/share/zoneinfo/Asia/Singapore",
"usr/share/zoneinfo/Asia/Srednekolymsk",
"usr/share/zoneinfo/Asia/Taipei",
"usr/share/zoneinfo/Asia/Tashkent",
"usr/share/zoneinfo/Asia/Tbilisi",
"usr/share/zoneinfo/Asia/Tehran",
"usr/share/zoneinfo/Asia/Tel_Aviv",
"usr/share/zoneinfo/Asia/Thimbu",
"usr/share/zoneinfo/Asia/Thimphu",
"usr/share/zoneinfo/Asia/Tokyo",
"usr/share/zoneinfo/Asia/Tomsk",
"usr/share/zoneinfo/Asia/Ujung_Pandang",
"usr/share/zoneinfo/Asia/Ulaanbaatar",
"usr/share/zoneinfo/Asia/Ulan_Bator",
"usr/share/zoneinfo/Asia/Urumqi",
"usr/share/zoneinfo/Asia/Ust-Nera",
"usr/share/zoneinfo/Asia/Vientiane",
"usr/share/zoneinfo/Asia/Vladivostok",
"usr/share/zoneinfo/Asia/Yakutsk",
"usr/share/zoneinfo/Asia/Yangon",
"usr/share/zoneinfo/Asia/Yekaterinburg",
"usr/share/zoneinfo/Asia/Yerevan",
"usr/share/zoneinfo/Atlantic/Azores",
"usr/share/zoneinfo/Atlantic/Bermuda",
"usr/share/zoneinfo/Atlantic/Canary",
"usr/share/zoneinfo/Atlantic/Cape_Verde",
"usr/share/zoneinfo/Atlantic/Faeroe",
"usr/share/zoneinfo/Atlantic/Faroe",
"usr/share/zoneinfo/Atlantic/Jan_Mayen",
"usr/share/zoneinfo/Atlantic/Madeira",
"usr/share/zoneinfo/Atlantic/Reykjavik",
"usr/share/zoneinfo/Atlantic/South_Georgia",
"usr/share/zoneinfo/Atlantic/St_Helena",
"usr/share/zoneinfo/Atlantic/Stanley",
"usr/share/zoneinfo/Australia/ACT",
"usr/share/zoneinfo/Australia/Adelaide",
"usr/share/zoneinfo/Australia/Brisbane",
"usr/share/zoneinfo/Australia/Broken_Hill",
"usr/share/zoneinfo/Australia/Canberra",
"usr/share/zoneinfo/Australia/Currie",
"usr/share/zoneinfo/Australia/Darwin",
"usr/share/zoneinfo/Australia/Eucla",
"usr/share/zoneinfo/Australia/Hobart",
"usr/share/zoneinfo/Australia/LHI",
"usr/share/zoneinfo/Australia/Lindeman",
"usr/share/zoneinfo/Australia/Lord_Howe",
"usr/share/zoneinfo/Australia/Melbourne",
"usr/share/zoneinfo/Australia/NSW",
"usr/share/zoneinfo/Australia/North",
"usr/share/zoneinfo/Australia/Perth",
"usr/share/zoneinfo/Australia/Queensland",
"usr/share/zoneinfo/Australia/South",
"usr/share/zoneinfo/Australia/Sydney",
"usr/share/zoneinfo/Australia/Tasmania",
"usr/share/zoneinfo/Australia/Victoria",
"usr/share/zoneinfo/Australia/West",
"usr/share/zoneinfo/Australia/Yancowinna",
"usr/share/zoneinfo/Brazil/Acre",
"usr/share/zoneinfo/Brazil/DeNoronha",
"usr/share/zoneinfo/Brazil/East",
"usr/share/zoneinfo/Brazil/West",
"usr/share/zoneinfo/Canada/Atlantic",
"usr/share/zoneinfo/Canada/Central",
"usr/share/zoneinfo/Canada/Eastern",
"usr/share/zoneinfo/Canada/Mountain",
"usr/share/zoneinfo/Canada/Newfoundland",
"usr/share/zoneinfo/Canada/Pacific",
"usr/share/zoneinfo/Canada/Saskatchewan",
"usr/share/zoneinfo/Canada/Yukon",
"usr/share/zoneinfo/Chile/Continental",
"usr/share/zoneinfo/Chile/EasterIsland",
"usr/share/zoneinfo/Etc/GMT",
"usr/share/zoneinfo/Etc/GMT+0",
"usr/share/zoneinfo/Etc/GMT+1",
"usr/share/zoneinfo/Etc/GMT+10",
"usr/share/zoneinfo/Etc/GMT+11",
"usr/share/zoneinfo/Etc/GMT+12",
"usr/share/zoneinfo/Etc/GMT+2",
"usr/share/zoneinfo/Etc/GMT+3",
"usr/share/zoneinfo/Etc/GMT+4",
"usr/share/zoneinfo/Etc/GMT+5",
"usr/share/zoneinfo/Etc/GMT+6",
"usr/share/zoneinfo/Etc/GMT+7",
"usr/share/zoneinfo/Etc/GMT+8",
"usr/share/zoneinfo/Etc/GMT+9",
"usr/share/zoneinfo/Etc/GMT-0",
"usr/share/zoneinfo/Etc/GMT-1",
"usr/share/zoneinfo/Etc/GMT-10",
"usr/share/zoneinfo/Etc/GMT-11",
"usr/share/zoneinfo/Etc/GMT-12",
"usr/share/zoneinfo/Etc/GMT-13",
"usr/share/zoneinfo/Etc/GMT-14",
"usr/share/zoneinfo/Etc/GMT-2",
"usr/share/zoneinfo/Etc/GMT-3",
"usr/share/zoneinfo/Etc/GMT-4",
"usr/share/zoneinfo/Etc/GMT-5",
"usr/share/zoneinfo/Etc/GMT-6",
"usr/share/zoneinfo/Etc/GMT-7",
"usr/share/zoneinfo/Etc/GMT-8",
"usr/share/zoneinfo/Etc/GMT-9",
"usr/share/zoneinfo/Etc/GMT0",
"usr/share/zoneinfo/Etc/Greenwich",
"usr/share/zoneinfo/Etc/UCT",
"usr/share/zoneinfo/Etc/UTC",
"usr/share/zoneinfo/Etc/Universal",
"usr/share/zoneinfo/Etc/Zulu",
"usr/share/zoneinfo/Europe/Amsterdam",
"usr/share/zoneinfo/Europe/Andorra",
"usr/share/zoneinfo/Europe/Astrakhan",
"usr/share/zoneinfo/Europe/Athens",
"usr/share/zoneinfo/Europe/Belfast",
"usr/share/zoneinfo/Europe/Belgrade",
"usr/share/zoneinfo/Europe/Berlin",
"usr/share/zoneinfo/Europe/Bratislava",
"usr/share/zoneinfo/Europe/Brussels",
"usr/share/zoneinfo/Europe/Bucharest",
"usr/share/zoneinfo/Europe/Budapest",
"usr/share/zoneinfo/Europe/Busingen",
"usr/share/zoneinfo/Europe/Chisinau",
"usr/share/zoneinfo/Europe/Copenhagen",
"usr/share/zoneinfo/Europe/Dublin",
"usr/share/zoneinfo/Europe/Gibraltar",
"usr/share/zoneinfo/Europe/Guernsey",
"usr/share/zoneinfo/Europe/Helsinki",
"usr/share/zoneinfo/Europe/Isle_of_Man",
"usr/share/zoneinfo/Europe/Istanbul",
"usr/share/zoneinfo/Europe/Jersey",
"usr/share/zoneinfo/Europe/Kaliningrad",
"usr/share/zoneinfo/Europe/Kiev",
"usr/share/zoneinfo/Europe/Kirov",
"usr/share/zoneinfo/Europe/Kyiv",
"usr/share/zoneinfo/Europe/Lisbon",
"usr/share/zoneinfo/Europe/Ljubljana",
"usr/share/zoneinfo/Europe/London",
"usr/share/zoneinfo/Europe/Luxembourg",
"usr/share/zoneinfo/Europe/Madrid",
"usr/share/zoneinfo/Europe/Malta",
"usr/share/zoneinfo/Europe/Mariehamn",
"usr/share/zoneinfo/Europe/Minsk",
"usr/share/zoneinfo/Europe/Monaco",
"usr/share/zoneinfo/Europe/Moscow",
"usr/share/zoneinfo/Europe/Nicosia",
"usr/share/zoneinfo/Europe/Oslo",
"usr/share/zoneinfo/Europe/Paris",
"usr/share/zoneinfo/Europe/Podgorica",
"usr/share/zoneinfo/Europe/Prague",
"usr/share/zoneinfo/Europe/Riga",
"usr/share/zoneinfo/Europe/Rome",
"usr/share/zoneinfo/Europe/Samara",
"usr/share/zoneinfo/Europe/San_Marino",
"usr/share/zoneinfo/Europe/Sarajevo",
"usr/share/zoneinfo/Europe/Saratov",
"usr/share/zoneinfo/Europe/Simferopol",
"usr/share/zoneinfo/Europe/Skopje",
"usr/share/zoneinfo/Europe/Sofia",
"usr/share/zoneinfo/Europe/Stockholm",
"usr/share/zoneinfo/Europe/Tallinn",
"usr/share/zoneinfo/Europe/Tirane",
"usr/share/zoneinfo/Europe/Tiraspol",
"usr/share/zoneinfo/Europe/Ulyanovsk",
"usr/share/zoneinfo/Europe/Uzhgorod",
"usr/share/zoneinfo/Europe/Vaduz",
"usr/share/zoneinfo/Europe/Vatican",
"usr/share/zoneinfo/Europe/Vienna",
"usr/share/zoneinfo/Europe/Vilnius",
"usr/share/zoneinfo/Europe/Volgograd",
"usr/share/zoneinfo/Europe/Warsaw",
"usr/share/zoneinfo/Europe/Zagreb",
"usr/share/zoneinfo/Europe/Zaporozhye",
"usr/share/zoneinfo/Europe/Zurich",
"usr/share/zoneinfo/Indian/Antananarivo",
"usr/share/zoneinfo/Indian/Chagos",
"usr/share/zoneinfo/Indian/Christmas",
"usr/share/zoneinfo/Indian/Cocos",
"usr/share/zoneinfo/Indian/Comoro",
"usr/share/zoneinfo/Indian/Kerguelen",
"usr/share/zoneinfo/Indian/Mahe",
"usr/share/zoneinfo/Indian/Maldives",
"usr/share/zoneinfo/Indian/Mauritius",
"usr/share/zoneinfo/Indian/Mayotte",
"usr/share/zoneinfo/Indian/Reunion",
"usr/share/zoneinfo/Mexico/BajaNorte",
"usr/share/zoneinfo/Mexico/BajaSur",
"usr/share/zoneinfo/Mexico/General",
"usr/share/zoneinfo/Pacific/Apia",
"usr/share/zoneinfo/Pacific/Auckland",
"usr/share/zoneinfo/Pacific/Bougainville",
"usr/share/zoneinfo/Pacific/Chatham",
"usr/share/zoneinfo/Pacific/Chuuk",
"usr/share/zoneinfo/Pacific/Easter",
"usr/share/zoneinfo/Pacific/Efate",
"usr/share/zoneinfo/Pacific/Enderbury",
"usr/share/zoneinfo/Pacific/Fakaofo",
"usr/share/zoneinfo/Pacific/Fiji",
"usr/share/zoneinfo/Pacific/Funafuti",
"usr/share/zoneinfo/Pacific/Galapagos",
"usr/share/zoneinfo/Pacific/Gambier",
"usr/share/zoneinfo/Pacific/Guadalcanal",
"usr/share/zoneinfo/Pacific/Guam",
"usr/share/zoneinfo/Pacific/Honolulu",
"usr/share/zoneinfo/Pacific/Johnston",
"usr/share/zoneinfo/Pacific/Kanton",
"usr/share/zoneinfo/Pacific/Kiritimati",
"usr/share/zoneinfo/Pacific/Kosrae",
"usr/share/zoneinfo/Pacific/Kwajalein",
"usr/share/zoneinfo/Pacific/Majuro",
"usr/share/zoneinfo/Pacific/Marquesas",
"usr/share/zoneinfo/Pacific/Midway",
"usr/share/zoneinfo/Pacific/Nauru",
"usr/share/zoneinfo/Pacific/Niue",
"usr/share/zoneinfo/Pacific/Norfolk",
"usr/share/zoneinfo/Pacific/Noumea",
"usr/share/zoneinfo/Pacific/Pago_Pago",
"usr/share/zoneinfo/Pacific/Palau",
"usr/share/zoneinfo/Pacific/Pitcairn",
"usr/share/zoneinfo/Pacific/Pohnpei",
"usr/share/zoneinfo/Pacific/Ponape",
"usr/share/zoneinfo/Pacific/Port_Moresby",
"usr/share/zoneinfo/Pacific/Rarotonga",
"usr/share/zoneinfo/Pacific/Saipan",
"usr/share/zoneinfo/Pacific/Samoa",
"usr/share/zoneinfo/Pacific/Tahiti",
"usr/share/zoneinfo/Pacific/Tarawa",
"usr/share/zoneinfo/Pacific/Tongatapu",
"usr/share/zoneinfo/Pacific/Truk",
"usr/share/zoneinfo/Pacific/Wake",
"usr/share/zoneinfo/Pacific/Wallis",
"usr/share/zoneinfo/Pacific/Yap",
"usr/share/zoneinfo/US/Alaska",
"usr/share/zoneinfo/US/Aleutian",
"usr/share/zoneinfo/US/Arizona",
"usr/share/zoneinfo/US/Central",
"usr/share/zoneinfo/US/East-Indiana",
"usr/share/zoneinfo/US/Eastern",
"usr/share/zoneinfo/US/Hawaii",
"usr/share/zoneinfo/US/Indiana-Starke",
"usr/share/zoneinfo/US/Michigan",
"usr/share/zoneinfo/US/Mountain",
"usr/share/zoneinfo/US/Pacific",
"usr/share/zoneinfo/US/Samoa"
],
"AnalyzedBy": "apk"
},
{
"ID": "xz-libs@5.8.3-r0",
"Name": "xz-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/xz-libs@5.8.3-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "1ae658a5f132a091"
},
"Version": "5.8.3-r0",
"Arch": "x86_64",
"SrcName": "xz",
"SrcVersion": "5.8.3-r0",
"Licenses": [
"GPL-2.0-or-later",
"0BSD",
"Public-Domain",
"LGPL-2.1-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:4c92c5be0c5bef404e93c880eba9037a9b147347",
"InstalledFiles": [
"usr/lib/liblzma.so.5",
"usr/lib/liblzma.so.5.8.3"
],
"AnalyzedBy": "apk"
},
{
"ID": "zlib@1.3.2-r0",
"Name": "zlib",
"Identifier": {
"PURL": "pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "e37054a2982d6c16"
},
"Version": "1.3.2-r0",
"Arch": "x86_64",
"SrcName": "zlib",
"SrcVersion": "1.3.2-r0",
"Licenses": [
"Zlib"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"Digest": "sha1:dd4c3d102acaef2a71a1495951d55fabc8680613",
"InstalledFiles": [
"usr/lib/libz.so.1",
"usr/lib/libz.so.1.3.2"
],
"AnalyzedBy": "apk"
},
{
"ID": "zstd@1.5.7-r2",
"Name": "zstd",
"Identifier": {
"PURL": "pkg:apk/alpine/zstd@1.5.7-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "71f39af918e4d14c"
},
"Version": "1.5.7-r2",
"Arch": "x86_64",
"SrcName": "zstd",
"SrcVersion": "1.5.7-r2",
"Licenses": [
"BSD-3-Clause",
"GPL-2.0-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"libgcc@15.2.0-r5",
"libstdc++@15.2.0-r5",
"musl@1.2.6-r2",
"zstd-libs@1.5.7-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:ff3000882c17e89e5e13c020554b5bccc1bfd4df",
"InstalledFiles": [
"usr/bin/pzstd",
"usr/bin/unzstd",
"usr/bin/zstd",
"usr/bin/zstdcat",
"usr/bin/zstdgrep",
"usr/bin/zstdless",
"usr/bin/zstdmt"
],
"AnalyzedBy": "apk"
},
{
"ID": "zstd-libs@1.5.7-r2",
"Name": "zstd-libs",
"Identifier": {
"PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.24.1",
"UID": "b33716e8bc222f1f"
},
"Version": "1.5.7-r2",
"Arch": "x86_64",
"SrcName": "zstd",
"SrcVersion": "1.5.7-r2",
"Licenses": [
"BSD-3-Clause",
"GPL-2.0-or-later"
],
"Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
"DependsOn": [
"musl@1.2.6-r2"
],
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"Digest": "sha1:9569ce3a97c4109e8e53ddde9f3e1bd272613540",
"InstalledFiles": [
"usr/lib/libzstd.so.1",
"usr/lib/libzstd.so.1.5.7"
],
"AnalyzedBy": "apk"
}
],
"Vulnerabilities": [
{
"VulnerabilityID": "CVE-2026-14456",
"PkgID": "libcrypto3@3.5.7-r0",
"PkgName": "libcrypto3",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "9ce2cdb3f0bf014b"
},
"InstalledVersion": "3.5.7-r0",
"FixedVersion": "3.5.8-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:66effbd554e6873981bdd52ae60692654faf106690b53c78751499d91ea7a8d6",
"Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server",
"Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"amazon": 3,
"photon": 3,
"redhat": 3,
"ubuntu": 2
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"http://www.openwall.com/lists/oss-security/2026/08/13/4",
"https://access.redhat.com/security/cve/CVE-2026-14456",
"https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9",
"https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b",
"https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139",
"https://nvd.nist.gov/vuln/detail/CVE-2026-14456",
"https://openssl-library.org/news/secadv/20260813.txt",
"https://ubuntu.com/security/notices/USN-8678-1",
"https://www.cve.org/CVERecord?id=CVE-2026-14456"
],
"PublishedDate": "2026-08-13T15:19:31.82Z",
"LastModifiedDate": "2026-08-28T19:46:29.323Z"
},
{
"VulnerabilityID": "CVE-2026-14456",
"PkgID": "libssl3@3.5.7-r0",
"PkgName": "libssl3",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "a25152af95b643e0"
},
"InstalledVersion": "3.5.7-r0",
"FixedVersion": "3.5.8-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4",
"DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:bd686aaa2ece4a82e1ad494f4a7598bb66d77b700c2133b3ab3ab8585d4e7ca9",
"Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server",
"Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"amazon": 3,
"photon": 3,
"redhat": 3,
"ubuntu": 2
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"http://www.openwall.com/lists/oss-security/2026/08/13/4",
"https://access.redhat.com/security/cve/CVE-2026-14456",
"https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9",
"https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b",
"https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139",
"https://nvd.nist.gov/vuln/detail/CVE-2026-14456",
"https://openssl-library.org/news/secadv/20260813.txt",
"https://ubuntu.com/security/notices/USN-8678-1",
"https://www.cve.org/CVERecord?id=CVE-2026-14456"
],
"PublishedDate": "2026-08-13T15:19:31.82Z",
"LastModifiedDate": "2026-08-28T19:46:29.323Z"
},
{
"VulnerabilityID": "CVE-2026-53612",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53612",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:81113f5360d14790e635b7331d78d5ed14e9be40a6e43bf022263dda73ce75b0",
"Title": "util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes",
"Description": "A flaw was found in util-linux. When an /etc/fstab entry uses the user option together with X-mount.owner, X-mount.group, or X-mount.mode, mount(8) changes ownership or permissions on the mount target after mounting without re-verifying the path. A local unprivileged user can exploit this Time-of-Check-Time-of-Use (TOCTOU) window by swapping the target directory, redirecting the ownership/permission change to an arbitrary file and potentially escalating privileges to root.",
"Severity": "HIGH",
"VendorSeverity": {
"redhat": 3,
"ubuntu": 2
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7
}
},
"References": [
"https://access.redhat.com/security/cve/CVE-2026-53612",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh",
"https://nvd.nist.gov/vuln/detail/CVE-2026-53612",
"https://ubuntu.com/security/notices/USN-8702-1",
"https://www.cve.org/CVERecord?id=CVE-2026-53612"
]
},
{
"VulnerabilityID": "CVE-2026-53613",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53613",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:54e037da093c8c174ad0e2d784253fc9a9814e055fd0549ad80221defddd87a1",
"Title": "util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path",
"Description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.",
"Severity": "HIGH",
"VendorSeverity": {
"redhat": 3,
"ubuntu": 2
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7
}
},
"References": [
"https://access.redhat.com/security/cve/CVE-2026-53613",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g",
"https://nvd.nist.gov/vuln/detail/CVE-2026-53613",
"https://ubuntu.com/security/notices/USN-8702-1",
"https://www.cve.org/CVERecord?id=CVE-2026-53613"
]
},
{
"VulnerabilityID": "CVE-2026-53614",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53614",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:dece0b29d6edc204a95c04c1c1f0eeeec1528eccf524218f803681d69aafe7d5",
"Title": "util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2",
"Description": "A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root.",
"Severity": "HIGH",
"VendorSeverity": {
"redhat": 3,
"ubuntu": 2
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7
}
},
"References": [
"https://access.redhat.com/security/cve/CVE-2026-53614",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-67r7-8m5w-22wx",
"https://nvd.nist.gov/vuln/detail/CVE-2026-53614",
"https://ubuntu.com/security/notices/USN-8702-1",
"https://www.cve.org/CVERecord?id=CVE-2026-53614"
]
},
{
"VulnerabilityID": "CVE-2026-76642",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:c142dcd00764dca9205218728a4d9d7f698986302926f2816106eaa9bbae8774",
"Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks",
"Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.",
"Severity": "HIGH",
"CweIDs": [
"CWE-390"
],
"VendorSeverity": {
"redhat": 3
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7.8
}
},
"References": [
"https://access.redhat.com/security/cve/CVE-2026-76642",
"https://github.com/util-linux/util-linux",
"https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476",
"https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892",
"https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a",
"https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc",
"https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f",
"https://nvd.nist.gov/vuln/detail/CVE-2026-76642",
"https://www.cve.org/CVERecord?id=CVE-2026-76642",
"https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"
],
"PublishedDate": "2026-09-03T13:06:08.44Z",
"LastModifiedDate": "2026-09-03T15:17:33.49Z"
},
{
"VulnerabilityID": "CVE-2026-78408",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r1",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:c639fbde964fa844de700c2d7a0665d771dcc8ee4a143560cc0c74f12355cbc6",
"Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority",
"Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.",
"Severity": "HIGH",
"CweIDs": [
"CWE-775"
],
"VendorSeverity": {
"redhat": 3
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H",
"V3Score": 7.9
}
},
"References": [
"http://www.openwall.com/lists/oss-security/2026/09/05/2",
"https://access.redhat.com/errata/RHSA-2026:63162",
"https://access.redhat.com/security/cve/CVE-2026-78408",
"https://bugzilla.redhat.com/show_bug.cgi?id=2522497",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj",
"https://nvd.nist.gov/vuln/detail/CVE-2026-78408",
"https://www.cve.org/CVERecord?id=CVE-2026-78408"
],
"PublishedDate": "2026-09-02T16:17:23.687Z",
"LastModifiedDate": "2026-09-05T14:17:23.727Z"
},
{
"VulnerabilityID": "CVE-2026-78409",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:e1ecbe00c3f557417e81e566a983e8869f8972ee1499e6de061810bffa516dc2",
"Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks",
"Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.",
"Severity": "HIGH",
"CweIDs": [
"CWE-59"
],
"VendorSeverity": {
"redhat": 3
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:63162",
"https://access.redhat.com/security/cve/CVE-2026-78409",
"https://bugzilla.redhat.com/show_bug.cgi?id=2522607",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv",
"https://nvd.nist.gov/vuln/detail/CVE-2026-78409",
"https://www.cve.org/CVERecord?id=CVE-2026-78409"
],
"PublishedDate": "2026-09-02T16:17:23.833Z",
"LastModifiedDate": "2026-09-03T18:12:56.407Z"
},
{
"VulnerabilityID": "CVE-2026-78410",
"PkgID": "libuuid@2.42.1-r0",
"PkgName": "libuuid",
"PkgIdentifier": {
"PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1",
"UID": "61e289a52fcab6f6"
},
"InstalledVersion": "2.42.1-r0",
"FixedVersion": "2.42.3-r0",
"Status": "fixed",
"Layer": {
"Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80",
"DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410",
"DataSource": {
"ID": "alpine",
"Name": "Alpine Secdb",
"URL": "https://secdb.alpinelinux.org/"
},
"Fingerprint": "sha256:0916dc51e28a7f0613d801b5b47f1f387bfaa9a446dd75898a4903017e142f5c",
"Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection",
"Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.",
"Severity": "HIGH",
"CweIDs": [
"CWE-367"
],
"VendorSeverity": {
"redhat": 3
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7.8
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:63162",
"https://access.redhat.com/security/cve/CVE-2026-78410",
"https://bugzilla.redhat.com/show_bug.cgi?id=2522684",
"https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m",
"https://nvd.nist.gov/vuln/detail/CVE-2026-78410",
"https://www.cve.org/CVERecord?id=CVE-2026-78410"
],
"PublishedDate": "2026-09-02T16:17:23.983Z",
"LastModifiedDate": "2026-09-04T19:17:27.567Z"
}
]
},
{
"Target": "usr/local/bin/gosu",
"Class": "lang-pkgs",
"Type": "gobinary",
"Packages": [
{
"ID": "github.com/tianon/gosu@v1.19.0",
"Name": "github.com/tianon/gosu",
"Identifier": {
"PURL": "pkg:golang/github.com/tianon/gosu@v1.19.0",
"UID": "1057a82ec313601"
},
"Version": "v1.19.0",
"Relationship": "root",
"DependsOn": [
"github.com/moby/sys/user@v0.1.0",
"golang.org/x/sys@v0.1.0",
"stdlib@v1.24.6"
],
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"AnalyzedBy": "gobinary"
},
{
"ID": "stdlib@v1.24.6",
"Name": "stdlib",
"Identifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"Version": "v1.24.6",
"Relationship": "direct",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"AnalyzedBy": "gobinary"
},
{
"ID": "github.com/moby/sys/user@v0.1.0",
"Name": "github.com/moby/sys/user",
"Identifier": {
"PURL": "pkg:golang/github.com/moby/sys/user@v0.1.0",
"UID": "cfd815b74e215fdf"
},
"Version": "v0.1.0",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"AnalyzedBy": "gobinary"
},
{
"ID": "golang.org/x/sys@v0.1.0",
"Name": "golang.org/x/sys",
"Identifier": {
"PURL": "pkg:golang/golang.org/x/sys@v0.1.0",
"UID": "11ab2e48c80f8e7d"
},
"Version": "v0.1.0",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"AnalyzedBy": "gobinary"
}
],
"Vulnerabilities": [
{
"VulnerabilityID": "CVE-2025-68121",
"VendorIDs": [
"GO-2026-4337"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:85e5aa144410093742432b138a09862fced9579b0f57deb4cbdd217755d26e54",
"Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption",
"Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.",
"Severity": "CRITICAL",
"CweIDs": [
"CWE-295"
],
"VendorSeverity": {
"alma": 3,
"amazon": 2,
"azure": 2,
"bitnami": 4,
"cbl-mariner": 2,
"nvd": 4,
"oracle-oval": 3,
"photon": 4,
"redhat": 2,
"rocky": 3,
"ubuntu": 2
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"V3Score": 9.1
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"V3Score": 10
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"V3Score": 7.4
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:4177",
"https://access.redhat.com/security/cve/CVE-2025-68121",
"https://bugzilla.redhat.com/2434432",
"https://bugzilla.redhat.com/2437111",
"https://bugzilla.redhat.com/show_bug.cgi?id=2434432",
"https://bugzilla.redhat.com/show_bug.cgi?id=2437111",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121",
"https://errata.almalinux.org/9/ALSA-2026-4177.html",
"https://errata.rockylinux.org/RLSA-2026:4177",
"https://github.com/golang/go/issues/77113",
"https://go.dev/cl/737700",
"https://go.dev/issue/77217",
"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk",
"https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc",
"https://linux.oracle.com/cve/CVE-2025-68121.html",
"https://linux.oracle.com/errata/ELSA-2026-5146.html",
"https://nvd.nist.gov/vuln/detail/CVE-2025-68121",
"https://pkg.go.dev/vuln/GO-2026-4337",
"https://www.cve.org/CVERecord?id=CVE-2025-68121"
],
"PublishedDate": "2026-02-05T18:16:10.857Z",
"LastModifiedDate": "2026-06-17T09:58:33.833Z"
},
{
"VulnerabilityID": "CVE-2025-61726",
"VendorIDs": [
"GO-2026-4341"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.24.12, 1.25.6",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:376f163e2679190aec7e2c2067f0d65ec348cf7c5697676194fffc9ae4598d32",
"Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url",
"Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"alma": 3,
"amazon": 2,
"azure": 2,
"bitnami": 3,
"cbl-mariner": 2,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:10096",
"https://access.redhat.com/errata/RHSA-2026:10104",
"https://access.redhat.com/errata/RHSA-2026:10184",
"https://access.redhat.com/errata/RHSA-2026:10225",
"https://access.redhat.com/errata/RHSA-2026:10250",
"https://access.redhat.com/errata/RHSA-2026:11408",
"https://access.redhat.com/errata/RHSA-2026:11414",
"https://access.redhat.com/errata/RHSA-2026:11747",
"https://access.redhat.com/errata/RHSA-2026:11749",
"https://access.redhat.com/errata/RHSA-2026:12028",
"https://access.redhat.com/errata/RHSA-2026:12029",
"https://access.redhat.com/errata/RHSA-2026:12030",
"https://access.redhat.com/errata/RHSA-2026:12031",
"https://access.redhat.com/errata/RHSA-2026:12032",
"https://access.redhat.com/errata/RHSA-2026:12033",
"https://access.redhat.com/errata/RHSA-2026:12279",
"https://access.redhat.com/errata/RHSA-2026:12282",
"https://access.redhat.com/errata/RHSA-2026:13542",
"https://access.redhat.com/errata/RHSA-2026:13548",
"https://access.redhat.com/errata/RHSA-2026:13571",
"https://access.redhat.com/errata/RHSA-2026:14100",
"https://access.redhat.com/errata/RHSA-2026:14774",
"https://access.redhat.com/errata/RHSA-2026:14868",
"https://access.redhat.com/errata/RHSA-2026:14879",
"https://access.redhat.com/errata/RHSA-2026:15091",
"https://access.redhat.com/errata/RHSA-2026:15984",
"https://access.redhat.com/errata/RHSA-2026:16102",
"https://access.redhat.com/errata/RHSA-2026:16696",
"https://access.redhat.com/errata/RHSA-2026:17040",
"https://access.redhat.com/errata/RHSA-2026:17084",
"https://access.redhat.com/errata/RHSA-2026:17446",
"https://access.redhat.com/errata/RHSA-2026:17460",
"https://access.redhat.com/errata/RHSA-2026:17463",
"https://access.redhat.com/errata/RHSA-2026:17468",
"https://access.redhat.com/errata/RHSA-2026:17595",
"https://access.redhat.com/errata/RHSA-2026:17598",
"https://access.redhat.com/errata/RHSA-2026:18913",
"https://access.redhat.com/errata/RHSA-2026:19013",
"https://access.redhat.com/errata/RHSA-2026:19132",
"https://access.redhat.com/errata/RHSA-2026:19375",
"https://access.redhat.com/errata/RHSA-2026:19634",
"https://access.redhat.com/errata/RHSA-2026:19712",
"https://access.redhat.com/errata/RHSA-2026:20041",
"https://access.redhat.com/errata/RHSA-2026:21017",
"https://access.redhat.com/errata/RHSA-2026:21657",
"https://access.redhat.com/errata/RHSA-2026:21691",
"https://access.redhat.com/errata/RHSA-2026:22450",
"https://access.redhat.com/errata/RHSA-2026:22627",
"https://access.redhat.com/errata/RHSA-2026:22714",
"https://access.redhat.com/errata/RHSA-2026:22937",
"https://access.redhat.com/errata/RHSA-2026:23228",
"https://access.redhat.com/errata/RHSA-2026:23361",
"https://access.redhat.com/errata/RHSA-2026:24977",
"https://access.redhat.com/errata/RHSA-2026:25089",
"https://access.redhat.com/errata/RHSA-2026:25127",
"https://access.redhat.com/errata/RHSA-2026:25248",
"https://access.redhat.com/errata/RHSA-2026:25250",
"https://access.redhat.com/errata/RHSA-2026:25251",
"https://access.redhat.com/errata/RHSA-2026:25252",
"https://access.redhat.com/errata/RHSA-2026:25253",
"https://access.redhat.com/errata/RHSA-2026:26420",
"https://access.redhat.com/errata/RHSA-2026:26527",
"https://access.redhat.com/errata/RHSA-2026:26541",
"https://access.redhat.com/errata/RHSA-2026:26636",
"https://access.redhat.com/errata/RHSA-2026:2681",
"https://access.redhat.com/errata/RHSA-2026:2706",
"https://access.redhat.com/errata/RHSA-2026:2708",
"https://access.redhat.com/errata/RHSA-2026:2709",
"https://access.redhat.com/errata/RHSA-2026:2754",
"https://access.redhat.com/errata/RHSA-2026:28047",
"https://access.redhat.com/errata/RHSA-2026:2844",
"https://access.redhat.com/errata/RHSA-2026:28441",
"https://access.redhat.com/errata/RHSA-2026:28886",
"https://access.redhat.com/errata/RHSA-2026:28961",
"https://access.redhat.com/errata/RHSA-2026:2914",
"https://access.redhat.com/errata/RHSA-2026:2920",
"https://access.redhat.com/errata/RHSA-2026:3035",
"https://access.redhat.com/errata/RHSA-2026:3040",
"https://access.redhat.com/errata/RHSA-2026:3089",
"https://access.redhat.com/errata/RHSA-2026:3092",
"https://access.redhat.com/errata/RHSA-2026:3184",
"https://access.redhat.com/errata/RHSA-2026:3186",
"https://access.redhat.com/errata/RHSA-2026:3187",
"https://access.redhat.com/errata/RHSA-2026:3188",
"https://access.redhat.com/errata/RHSA-2026:3192",
"https://access.redhat.com/errata/RHSA-2026:3193",
"https://access.redhat.com/errata/RHSA-2026:3291",
"https://access.redhat.com/errata/RHSA-2026:3296",
"https://access.redhat.com/errata/RHSA-2026:3297",
"https://access.redhat.com/errata/RHSA-2026:3298",
"https://access.redhat.com/errata/RHSA-2026:3336",
"https://access.redhat.com/errata/RHSA-2026:3337",
"https://access.redhat.com/errata/RHSA-2026:3340",
"https://access.redhat.com/errata/RHSA-2026:3341",
"https://access.redhat.com/errata/RHSA-2026:3343",
"https://access.redhat.com/errata/RHSA-2026:3391",
"https://access.redhat.com/errata/RHSA-2026:3416",
"https://access.redhat.com/errata/RHSA-2026:3427",
"https://access.redhat.com/errata/RHSA-2026:3459",
"https://access.redhat.com/errata/RHSA-2026:3468",
"https://access.redhat.com/errata/RHSA-2026:3469",
"https://access.redhat.com/errata/RHSA-2026:3470",
"https://access.redhat.com/errata/RHSA-2026:3471",
"https://access.redhat.com/errata/RHSA-2026:3472",
"https://access.redhat.com/errata/RHSA-2026:3473",
"https://access.redhat.com/errata/RHSA-2026:3489",
"https://access.redhat.com/errata/RHSA-2026:3506",
"https://access.redhat.com/errata/RHSA-2026:3556",
"https://access.redhat.com/errata/RHSA-2026:3559",
"https://access.redhat.com/errata/RHSA-2026:3668",
"https://access.redhat.com/errata/RHSA-2026:3669",
"https://access.redhat.com/errata/RHSA-2026:36873",
"https://access.redhat.com/errata/RHSA-2026:36882",
"https://access.redhat.com/errata/RHSA-2026:3699",
"https://access.redhat.com/errata/RHSA-2026:3713",
"https://access.redhat.com/errata/RHSA-2026:37275",
"https://access.redhat.com/errata/RHSA-2026:3752",
"https://access.redhat.com/errata/RHSA-2026:3753",
"https://access.redhat.com/errata/RHSA-2026:3782",
"https://access.redhat.com/errata/RHSA-2026:3812",
"https://access.redhat.com/errata/RHSA-2026:3813",
"https://access.redhat.com/errata/RHSA-2026:3814",
"https://access.redhat.com/errata/RHSA-2026:3815",
"https://access.redhat.com/errata/RHSA-2026:3816",
"https://access.redhat.com/errata/RHSA-2026:3817",
"https://access.redhat.com/errata/RHSA-2026:3818",
"https://access.redhat.com/errata/RHSA-2026:3820",
"https://access.redhat.com/errata/RHSA-2026:3821",
"https://access.redhat.com/errata/RHSA-2026:3822",
"https://access.redhat.com/errata/RHSA-2026:3831",
"https://access.redhat.com/errata/RHSA-2026:3833",
"https://access.redhat.com/errata/RHSA-2026:3835",
"https://access.redhat.com/errata/RHSA-2026:3836",
"https://access.redhat.com/errata/RHSA-2026:3838",
"https://access.redhat.com/errata/RHSA-2026:3839",
"https://access.redhat.com/errata/RHSA-2026:3840",
"https://access.redhat.com/errata/RHSA-2026:3841",
"https://access.redhat.com/errata/RHSA-2026:3843",
"https://access.redhat.com/errata/RHSA-2026:3854",
"https://access.redhat.com/errata/RHSA-2026:3855",
"https://access.redhat.com/errata/RHSA-2026:3856",
"https://access.redhat.com/errata/RHSA-2026:3864",
"https://access.redhat.com/errata/RHSA-2026:3869",
"https://access.redhat.com/errata/RHSA-2026:3874",
"https://access.redhat.com/errata/RHSA-2026:3875",
"https://access.redhat.com/errata/RHSA-2026:3879",
"https://access.redhat.com/errata/RHSA-2026:3880",
"https://access.redhat.com/errata/RHSA-2026:3884",
"https://access.redhat.com/errata/RHSA-2026:3898",
"https://access.redhat.com/errata/RHSA-2026:3905",
"https://access.redhat.com/errata/RHSA-2026:3906",
"https://access.redhat.com/errata/RHSA-2026:3928",
"https://access.redhat.com/errata/RHSA-2026:3929",
"https://access.redhat.com/errata/RHSA-2026:3930",
"https://access.redhat.com/errata/RHSA-2026:3931",
"https://access.redhat.com/errata/RHSA-2026:3932",
"https://access.redhat.com/errata/RHSA-2026:3958",
"https://access.redhat.com/errata/RHSA-2026:3959",
"https://access.redhat.com/errata/RHSA-2026:3960",
"https://access.redhat.com/errata/RHSA-2026:3970",
"https://access.redhat.com/errata/RHSA-2026:3971",
"https://access.redhat.com/errata/RHSA-2026:3972",
"https://access.redhat.com/errata/RHSA-2026:3973",
"https://access.redhat.com/errata/RHSA-2026:3974",
"https://access.redhat.com/errata/RHSA-2026:3977",
"https://access.redhat.com/errata/RHSA-2026:39810",
"https://access.redhat.com/errata/RHSA-2026:3985",
"https://access.redhat.com/errata/RHSA-2026:40924",
"https://access.redhat.com/errata/RHSA-2026:4164",
"https://access.redhat.com/errata/RHSA-2026:4166",
"https://access.redhat.com/errata/RHSA-2026:4170",
"https://access.redhat.com/errata/RHSA-2026:4174",
"https://access.redhat.com/errata/RHSA-2026:4177",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:41941",
"https://access.redhat.com/errata/RHSA-2026:4211",
"https://access.redhat.com/errata/RHSA-2026:4220",
"https://access.redhat.com/errata/RHSA-2026:4256",
"https://access.redhat.com/errata/RHSA-2026:4264",
"https://access.redhat.com/errata/RHSA-2026:4267",
"https://access.redhat.com/errata/RHSA-2026:4270",
"https://access.redhat.com/errata/RHSA-2026:4276",
"https://access.redhat.com/errata/RHSA-2026:4434",
"https://access.redhat.com/errata/RHSA-2026:4435",
"https://access.redhat.com/errata/RHSA-2026:4460",
"https://access.redhat.com/errata/RHSA-2026:4466",
"https://access.redhat.com/errata/RHSA-2026:4467",
"https://access.redhat.com/errata/RHSA-2026:4498",
"https://access.redhat.com/errata/RHSA-2026:4500",
"https://access.redhat.com/errata/RHSA-2026:4510",
"https://access.redhat.com/errata/RHSA-2026:4511",
"https://access.redhat.com/errata/RHSA-2026:4672",
"https://access.redhat.com/errata/RHSA-2026:46903",
"https://access.redhat.com/errata/RHSA-2026:4753",
"https://access.redhat.com/errata/RHSA-2026:4892",
"https://access.redhat.com/errata/RHSA-2026:4901",
"https://access.redhat.com/errata/RHSA-2026:4907",
"https://access.redhat.com/errata/RHSA-2026:4939",
"https://access.redhat.com/errata/RHSA-2026:4942",
"https://access.redhat.com/errata/RHSA-2026:4943",
"https://access.redhat.com/errata/RHSA-2026:4952",
"https://access.redhat.com/errata/RHSA-2026:49944",
"https://access.redhat.com/errata/RHSA-2026:5022",
"https://access.redhat.com/errata/RHSA-2026:5030",
"https://access.redhat.com/errata/RHSA-2026:5031",
"https://access.redhat.com/errata/RHSA-2026:5076",
"https://access.redhat.com/errata/RHSA-2026:5077",
"https://access.redhat.com/errata/RHSA-2026:5078",
"https://access.redhat.com/errata/RHSA-2026:5079",
"https://access.redhat.com/errata/RHSA-2026:51033",
"https://access.redhat.com/errata/RHSA-2026:5110",
"https://access.redhat.com/errata/RHSA-2026:51288",
"https://access.redhat.com/errata/RHSA-2026:5129",
"https://access.redhat.com/errata/RHSA-2026:5130",
"https://access.redhat.com/errata/RHSA-2026:5131",
"https://access.redhat.com/errata/RHSA-2026:5132",
"https://access.redhat.com/errata/RHSA-2026:5145",
"https://access.redhat.com/errata/RHSA-2026:5146",
"https://access.redhat.com/errata/RHSA-2026:5168",
"https://access.redhat.com/errata/RHSA-2026:5327",
"https://access.redhat.com/errata/RHSA-2026:5394",
"https://access.redhat.com/errata/RHSA-2026:5439",
"https://access.redhat.com/errata/RHSA-2026:5444",
"https://access.redhat.com/errata/RHSA-2026:5447",
"https://access.redhat.com/errata/RHSA-2026:5452",
"https://access.redhat.com/errata/RHSA-2026:5461",
"https://access.redhat.com/errata/RHSA-2026:5463",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:5533",
"https://access.redhat.com/errata/RHSA-2026:5544",
"https://access.redhat.com/errata/RHSA-2026:5549",
"https://access.redhat.com/errata/RHSA-2026:5636",
"https://access.redhat.com/errata/RHSA-2026:56366",
"https://access.redhat.com/errata/RHSA-2026:56431",
"https://access.redhat.com/errata/RHSA-2026:5645",
"https://access.redhat.com/errata/RHSA-2026:5649",
"https://access.redhat.com/errata/RHSA-2026:5665",
"https://access.redhat.com/errata/RHSA-2026:57013",
"https://access.redhat.com/errata/RHSA-2026:5807",
"https://access.redhat.com/errata/RHSA-2026:5851",
"https://access.redhat.com/errata/RHSA-2026:5852",
"https://access.redhat.com/errata/RHSA-2026:5853",
"https://access.redhat.com/errata/RHSA-2026:5948",
"https://access.redhat.com/errata/RHSA-2026:5950",
"https://access.redhat.com/errata/RHSA-2026:5952",
"https://access.redhat.com/errata/RHSA-2026:5968",
"https://access.redhat.com/errata/RHSA-2026:6184",
"https://access.redhat.com/errata/RHSA-2026:6192",
"https://access.redhat.com/errata/RHSA-2026:6226",
"https://access.redhat.com/errata/RHSA-2026:6251",
"https://access.redhat.com/errata/RHSA-2026:6277",
"https://access.redhat.com/errata/RHSA-2026:6278",
"https://access.redhat.com/errata/RHSA-2026:6428",
"https://access.redhat.com/errata/RHSA-2026:6429",
"https://access.redhat.com/errata/RHSA-2026:6497",
"https://access.redhat.com/errata/RHSA-2026:6554",
"https://access.redhat.com/errata/RHSA-2026:6564",
"https://access.redhat.com/errata/RHSA-2026:6567",
"https://access.redhat.com/errata/RHSA-2026:6568",
"https://access.redhat.com/errata/RHSA-2026:66401",
"https://access.redhat.com/errata/RHSA-2026:7052",
"https://access.redhat.com/errata/RHSA-2026:7249",
"https://access.redhat.com/errata/RHSA-2026:7291",
"https://access.redhat.com/errata/RHSA-2026:7385",
"https://access.redhat.com/errata/RHSA-2026:7676",
"https://access.redhat.com/errata/RHSA-2026:7854",
"https://access.redhat.com/errata/RHSA-2026:7942",
"https://access.redhat.com/errata/RHSA-2026:8151",
"https://access.redhat.com/errata/RHSA-2026:8167",
"https://access.redhat.com/errata/RHSA-2026:8218",
"https://access.redhat.com/errata/RHSA-2026:8229",
"https://access.redhat.com/errata/RHSA-2026:8337",
"https://access.redhat.com/errata/RHSA-2026:8338",
"https://access.redhat.com/errata/RHSA-2026:8431",
"https://access.redhat.com/errata/RHSA-2026:8433",
"https://access.redhat.com/errata/RHSA-2026:8483",
"https://access.redhat.com/errata/RHSA-2026:9097",
"https://access.redhat.com/errata/RHSA-2026:9098",
"https://access.redhat.com/errata/RHSA-2026:9108",
"https://access.redhat.com/errata/RHSA-2026:9109",
"https://access.redhat.com/errata/RHSA-2026:9848",
"https://access.redhat.com/security/cve/CVE-2025-61726",
"https://bugzilla.redhat.com/2434432",
"https://bugzilla.redhat.com/2437111",
"https://bugzilla.redhat.com/show_bug.cgi?id=2434432",
"https://bugzilla.redhat.com/show_bug.cgi?id=2437111",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121",
"https://errata.almalinux.org/9/ALSA-2026-4177.html",
"https://errata.rockylinux.org/RLSA-2026:4177",
"https://go.dev/cl/736712",
"https://go.dev/issue/77101",
"https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc",
"https://linux.oracle.com/cve/CVE-2025-61726.html",
"https://linux.oracle.com/errata/ELSA-2026-5146.html",
"https://nvd.nist.gov/vuln/detail/CVE-2025-61726",
"https://pkg.go.dev/vuln/GO-2026-4341",
"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json",
"https://www.cve.org/CVERecord?id=CVE-2025-61726"
],
"PublishedDate": "2026-01-28T20:16:09.713Z",
"LastModifiedDate": "2026-09-11T13:16:49.81Z"
},
{
"VulnerabilityID": "CVE-2025-61729",
"VendorIDs": [
"GO-2025-4155"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.24.11, 1.25.5",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:d7e5e7734c69cbd7621f0b90b22f75df51bbf1668935979fe9f2f86054824576",
"Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate",
"Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.",
"Severity": "HIGH",
"CweIDs": [
"CWE-295"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"azure": 3,
"bitnami": 3,
"cbl-mariner": 1,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:3928",
"https://access.redhat.com/security/cve/CVE-2025-61729",
"https://bugzilla.redhat.com/2418462",
"https://bugzilla.redhat.com/2434432",
"https://bugzilla.redhat.com/2437111",
"https://bugzilla.redhat.com/show_bug.cgi?id=2418462",
"https://bugzilla.redhat.com/show_bug.cgi?id=2434432",
"https://bugzilla.redhat.com/show_bug.cgi?id=2437111",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121",
"https://errata.almalinux.org/9/ALSA-2026-3928.html",
"https://errata.rockylinux.org/RLSA-2026:3928",
"https://go.dev/cl/725920",
"https://go.dev/issue/76445",
"https://groups.google.com/g/golang-announce/c/8FJoBkPddm4",
"https://linux.oracle.com/cve/CVE-2025-61729.html",
"https://linux.oracle.com/errata/ELSA-2026-5146.html",
"https://nvd.nist.gov/vuln/detail/CVE-2025-61729",
"https://pkg.go.dev/vuln/GO-2025-4155",
"https://www.cve.org/CVERecord?id=CVE-2025-61729"
],
"PublishedDate": "2025-12-02T19:15:51.447Z",
"LastModifiedDate": "2026-06-17T09:50:48.507Z"
},
{
"VulnerabilityID": "CVE-2026-25679",
"VendorIDs": [
"GO-2026-4601"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.8, 1.26.1",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:56e02f7cd346e0e23b77d3b151ceb12bd4d1daf93a5328ceceea0634ece1a7ac",
"Title": "net/url: Incorrect parsing of IPv6 host literals in net/url",
"Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.",
"Severity": "HIGH",
"CweIDs": [
"CWE-425",
"CWE-1286"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"azure": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:10065",
"https://access.redhat.com/errata/RHSA-2026:10125",
"https://access.redhat.com/errata/RHSA-2026:10133",
"https://access.redhat.com/errata/RHSA-2026:10140",
"https://access.redhat.com/errata/RHSA-2026:10141",
"https://access.redhat.com/errata/RHSA-2026:10158",
"https://access.redhat.com/errata/RHSA-2026:10169",
"https://access.redhat.com/errata/RHSA-2026:10175",
"https://access.redhat.com/errata/RHSA-2026:10184",
"https://access.redhat.com/errata/RHSA-2026:10225",
"https://access.redhat.com/errata/RHSA-2026:10250",
"https://access.redhat.com/errata/RHSA-2026:10701",
"https://access.redhat.com/errata/RHSA-2026:10712",
"https://access.redhat.com/errata/RHSA-2026:10929",
"https://access.redhat.com/errata/RHSA-2026:11217",
"https://access.redhat.com/errata/RHSA-2026:11375",
"https://access.redhat.com/errata/RHSA-2026:11412",
"https://access.redhat.com/errata/RHSA-2026:11413",
"https://access.redhat.com/errata/RHSA-2026:11686",
"https://access.redhat.com/errata/RHSA-2026:11688",
"https://access.redhat.com/errata/RHSA-2026:11747",
"https://access.redhat.com/errata/RHSA-2026:11749",
"https://access.redhat.com/errata/RHSA-2026:11768",
"https://access.redhat.com/errata/RHSA-2026:11800",
"https://access.redhat.com/errata/RHSA-2026:11856",
"https://access.redhat.com/errata/RHSA-2026:11916",
"https://access.redhat.com/errata/RHSA-2026:11996",
"https://access.redhat.com/errata/RHSA-2026:12028",
"https://access.redhat.com/errata/RHSA-2026:12029",
"https://access.redhat.com/errata/RHSA-2026:12030",
"https://access.redhat.com/errata/RHSA-2026:12031",
"https://access.redhat.com/errata/RHSA-2026:12032",
"https://access.redhat.com/errata/RHSA-2026:12033",
"https://access.redhat.com/errata/RHSA-2026:12282",
"https://access.redhat.com/errata/RHSA-2026:13508",
"https://access.redhat.com/errata/RHSA-2026:13512",
"https://access.redhat.com/errata/RHSA-2026:13545",
"https://access.redhat.com/errata/RHSA-2026:13642",
"https://access.redhat.com/errata/RHSA-2026:13643",
"https://access.redhat.com/errata/RHSA-2026:13671",
"https://access.redhat.com/errata/RHSA-2026:13791",
"https://access.redhat.com/errata/RHSA-2026:13829",
"https://access.redhat.com/errata/RHSA-2026:14020",
"https://access.redhat.com/errata/RHSA-2026:14100",
"https://access.redhat.com/errata/RHSA-2026:14774",
"https://access.redhat.com/errata/RHSA-2026:14868",
"https://access.redhat.com/errata/RHSA-2026:14879",
"https://access.redhat.com/errata/RHSA-2026:15091",
"https://access.redhat.com/errata/RHSA-2026:16102",
"https://access.redhat.com/errata/RHSA-2026:16696",
"https://access.redhat.com/errata/RHSA-2026:16874",
"https://access.redhat.com/errata/RHSA-2026:16875",
"https://access.redhat.com/errata/RHSA-2026:17040",
"https://access.redhat.com/errata/RHSA-2026:17084",
"https://access.redhat.com/errata/RHSA-2026:17287",
"https://access.redhat.com/errata/RHSA-2026:17598",
"https://access.redhat.com/errata/RHSA-2026:19017",
"https://access.redhat.com/errata/RHSA-2026:19022",
"https://access.redhat.com/errata/RHSA-2026:19026",
"https://access.redhat.com/errata/RHSA-2026:19027",
"https://access.redhat.com/errata/RHSA-2026:19031",
"https://access.redhat.com/errata/RHSA-2026:19032",
"https://access.redhat.com/errata/RHSA-2026:19049",
"https://access.redhat.com/errata/RHSA-2026:19055",
"https://access.redhat.com/errata/RHSA-2026:19126",
"https://access.redhat.com/errata/RHSA-2026:19128",
"https://access.redhat.com/errata/RHSA-2026:19132",
"https://access.redhat.com/errata/RHSA-2026:19133",
"https://access.redhat.com/errata/RHSA-2026:19135",
"https://access.redhat.com/errata/RHSA-2026:19181",
"https://access.redhat.com/errata/RHSA-2026:19184",
"https://access.redhat.com/errata/RHSA-2026:19185",
"https://access.redhat.com/errata/RHSA-2026:19207",
"https://access.redhat.com/errata/RHSA-2026:19350",
"https://access.redhat.com/errata/RHSA-2026:19353",
"https://access.redhat.com/errata/RHSA-2026:19375",
"https://access.redhat.com/errata/RHSA-2026:19475",
"https://access.redhat.com/errata/RHSA-2026:19634",
"https://access.redhat.com/errata/RHSA-2026:19719",
"https://access.redhat.com/errata/RHSA-2026:19720",
"https://access.redhat.com/errata/RHSA-2026:19721",
"https://access.redhat.com/errata/RHSA-2026:19750",
"https://access.redhat.com/errata/RHSA-2026:20041",
"https://access.redhat.com/errata/RHSA-2026:20088",
"https://access.redhat.com/errata/RHSA-2026:20581",
"https://access.redhat.com/errata/RHSA-2026:20582",
"https://access.redhat.com/errata/RHSA-2026:20584",
"https://access.redhat.com/errata/RHSA-2026:20889",
"https://access.redhat.com/errata/RHSA-2026:21017",
"https://access.redhat.com/errata/RHSA-2026:21655",
"https://access.redhat.com/errata/RHSA-2026:21657",
"https://access.redhat.com/errata/RHSA-2026:21691",
"https://access.redhat.com/errata/RHSA-2026:21696",
"https://access.redhat.com/errata/RHSA-2026:21769",
"https://access.redhat.com/errata/RHSA-2026:22347",
"https://access.redhat.com/errata/RHSA-2026:22423",
"https://access.redhat.com/errata/RHSA-2026:22450",
"https://access.redhat.com/errata/RHSA-2026:22627",
"https://access.redhat.com/errata/RHSA-2026:22714",
"https://access.redhat.com/errata/RHSA-2026:22733",
"https://access.redhat.com/errata/RHSA-2026:22862",
"https://access.redhat.com/errata/RHSA-2026:22937",
"https://access.redhat.com/errata/RHSA-2026:23228",
"https://access.redhat.com/errata/RHSA-2026:23345",
"https://access.redhat.com/errata/RHSA-2026:24386",
"https://access.redhat.com/errata/RHSA-2026:24853",
"https://access.redhat.com/errata/RHSA-2026:25043",
"https://access.redhat.com/errata/RHSA-2026:25127",
"https://access.redhat.com/errata/RHSA-2026:25180",
"https://access.redhat.com/errata/RHSA-2026:25248",
"https://access.redhat.com/errata/RHSA-2026:25250",
"https://access.redhat.com/errata/RHSA-2026:25251",
"https://access.redhat.com/errata/RHSA-2026:25252",
"https://access.redhat.com/errata/RHSA-2026:25253",
"https://access.redhat.com/errata/RHSA-2026:26445",
"https://access.redhat.com/errata/RHSA-2026:26527",
"https://access.redhat.com/errata/RHSA-2026:26541",
"https://access.redhat.com/errata/RHSA-2026:26568",
"https://access.redhat.com/errata/RHSA-2026:26585",
"https://access.redhat.com/errata/RHSA-2026:26636",
"https://access.redhat.com/errata/RHSA-2026:27076",
"https://access.redhat.com/errata/RHSA-2026:28047",
"https://access.redhat.com/errata/RHSA-2026:28441",
"https://access.redhat.com/errata/RHSA-2026:28886",
"https://access.redhat.com/errata/RHSA-2026:28893",
"https://access.redhat.com/errata/RHSA-2026:28961",
"https://access.redhat.com/errata/RHSA-2026:29035",
"https://access.redhat.com/errata/RHSA-2026:29195",
"https://access.redhat.com/errata/RHSA-2026:29455",
"https://access.redhat.com/errata/RHSA-2026:29702",
"https://access.redhat.com/errata/RHSA-2026:29703",
"https://access.redhat.com/errata/RHSA-2026:29854",
"https://access.redhat.com/errata/RHSA-2026:33722",
"https://access.redhat.com/errata/RHSA-2026:34097",
"https://access.redhat.com/errata/RHSA-2026:34365",
"https://access.redhat.com/errata/RHSA-2026:36317",
"https://access.redhat.com/errata/RHSA-2026:36319",
"https://access.redhat.com/errata/RHSA-2026:36651",
"https://access.redhat.com/errata/RHSA-2026:36796",
"https://access.redhat.com/errata/RHSA-2026:39810",
"https://access.redhat.com/errata/RHSA-2026:40118",
"https://access.redhat.com/errata/RHSA-2026:40945",
"https://access.redhat.com/errata/RHSA-2026:41019",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:42150",
"https://access.redhat.com/errata/RHSA-2026:42151",
"https://access.redhat.com/errata/RHSA-2026:48036",
"https://access.redhat.com/errata/RHSA-2026:49944",
"https://access.redhat.com/errata/RHSA-2026:5110",
"https://access.redhat.com/errata/RHSA-2026:51288",
"https://access.redhat.com/errata/RHSA-2026:52389",
"https://access.redhat.com/errata/RHSA-2026:52390",
"https://access.redhat.com/errata/RHSA-2026:52391",
"https://access.redhat.com/errata/RHSA-2026:54191",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:5549",
"https://access.redhat.com/errata/RHSA-2026:56785",
"https://access.redhat.com/errata/RHSA-2026:56852",
"https://access.redhat.com/errata/RHSA-2026:56910",
"https://access.redhat.com/errata/RHSA-2026:57482",
"https://access.redhat.com/errata/RHSA-2026:5941",
"https://access.redhat.com/errata/RHSA-2026:5942",
"https://access.redhat.com/errata/RHSA-2026:5943",
"https://access.redhat.com/errata/RHSA-2026:5944",
"https://access.redhat.com/errata/RHSA-2026:59830",
"https://access.redhat.com/errata/RHSA-2026:60018",
"https://access.redhat.com/errata/RHSA-2026:6341",
"https://access.redhat.com/errata/RHSA-2026:6344",
"https://access.redhat.com/errata/RHSA-2026:6382",
"https://access.redhat.com/errata/RHSA-2026:6383",
"https://access.redhat.com/errata/RHSA-2026:6388",
"https://access.redhat.com/errata/RHSA-2026:6564",
"https://access.redhat.com/errata/RHSA-2026:66401",
"https://access.redhat.com/errata/RHSA-2026:6720",
"https://access.redhat.com/errata/RHSA-2026:6802",
"https://access.redhat.com/errata/RHSA-2026:6949",
"https://access.redhat.com/errata/RHSA-2026:7005",
"https://access.redhat.com/errata/RHSA-2026:7009",
"https://access.redhat.com/errata/RHSA-2026:7011",
"https://access.redhat.com/errata/RHSA-2026:7259",
"https://access.redhat.com/errata/RHSA-2026:7291",
"https://access.redhat.com/errata/RHSA-2026:7315",
"https://access.redhat.com/errata/RHSA-2026:7328",
"https://access.redhat.com/errata/RHSA-2026:7385",
"https://access.redhat.com/errata/RHSA-2026:7665",
"https://access.redhat.com/errata/RHSA-2026:7669",
"https://access.redhat.com/errata/RHSA-2026:7674",
"https://access.redhat.com/errata/RHSA-2026:7833",
"https://access.redhat.com/errata/RHSA-2026:7834",
"https://access.redhat.com/errata/RHSA-2026:7876",
"https://access.redhat.com/errata/RHSA-2026:7877",
"https://access.redhat.com/errata/RHSA-2026:7878",
"https://access.redhat.com/errata/RHSA-2026:7879",
"https://access.redhat.com/errata/RHSA-2026:7883",
"https://access.redhat.com/errata/RHSA-2026:7992",
"https://access.redhat.com/errata/RHSA-2026:8151",
"https://access.redhat.com/errata/RHSA-2026:8167",
"https://access.redhat.com/errata/RHSA-2026:8314",
"https://access.redhat.com/errata/RHSA-2026:8322",
"https://access.redhat.com/errata/RHSA-2026:8324",
"https://access.redhat.com/errata/RHSA-2026:8337",
"https://access.redhat.com/errata/RHSA-2026:8338",
"https://access.redhat.com/errata/RHSA-2026:8433",
"https://access.redhat.com/errata/RHSA-2026:8434",
"https://access.redhat.com/errata/RHSA-2026:8456",
"https://access.redhat.com/errata/RHSA-2026:8483",
"https://access.redhat.com/errata/RHSA-2026:8484",
"https://access.redhat.com/errata/RHSA-2026:8490",
"https://access.redhat.com/errata/RHSA-2026:8491",
"https://access.redhat.com/errata/RHSA-2026:8493",
"https://access.redhat.com/errata/RHSA-2026:8840",
"https://access.redhat.com/errata/RHSA-2026:8841",
"https://access.redhat.com/errata/RHSA-2026:8842",
"https://access.redhat.com/errata/RHSA-2026:8845",
"https://access.redhat.com/errata/RHSA-2026:8847",
"https://access.redhat.com/errata/RHSA-2026:8848",
"https://access.redhat.com/errata/RHSA-2026:8849",
"https://access.redhat.com/errata/RHSA-2026:8851",
"https://access.redhat.com/errata/RHSA-2026:8852",
"https://access.redhat.com/errata/RHSA-2026:8853",
"https://access.redhat.com/errata/RHSA-2026:8855",
"https://access.redhat.com/errata/RHSA-2026:8856",
"https://access.redhat.com/errata/RHSA-2026:8860",
"https://access.redhat.com/errata/RHSA-2026:8877",
"https://access.redhat.com/errata/RHSA-2026:8878",
"https://access.redhat.com/errata/RHSA-2026:8879",
"https://access.redhat.com/errata/RHSA-2026:8881",
"https://access.redhat.com/errata/RHSA-2026:8882",
"https://access.redhat.com/errata/RHSA-2026:8930",
"https://access.redhat.com/errata/RHSA-2026:8931",
"https://access.redhat.com/errata/RHSA-2026:8949",
"https://access.redhat.com/errata/RHSA-2026:9043",
"https://access.redhat.com/errata/RHSA-2026:9044",
"https://access.redhat.com/errata/RHSA-2026:9052",
"https://access.redhat.com/errata/RHSA-2026:9090",
"https://access.redhat.com/errata/RHSA-2026:9093",
"https://access.redhat.com/errata/RHSA-2026:9094",
"https://access.redhat.com/errata/RHSA-2026:9097",
"https://access.redhat.com/errata/RHSA-2026:9098",
"https://access.redhat.com/errata/RHSA-2026:9108",
"https://access.redhat.com/errata/RHSA-2026:9109",
"https://access.redhat.com/errata/RHSA-2026:9385",
"https://access.redhat.com/errata/RHSA-2026:9434",
"https://access.redhat.com/errata/RHSA-2026:9435",
"https://access.redhat.com/errata/RHSA-2026:9436",
"https://access.redhat.com/errata/RHSA-2026:9439",
"https://access.redhat.com/errata/RHSA-2026:9440",
"https://access.redhat.com/errata/RHSA-2026:9448",
"https://access.redhat.com/errata/RHSA-2026:9453",
"https://access.redhat.com/errata/RHSA-2026:9461",
"https://access.redhat.com/errata/RHSA-2026:9695",
"https://access.redhat.com/errata/RHSA-2026:9742",
"https://access.redhat.com/errata/RHSA-2026:9872",
"https://access.redhat.com/security/cve/CVE-2026-25679",
"https://bugzilla.redhat.com/2445356",
"https://bugzilla.redhat.com/show_bug.cgi?id=2445356",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679",
"https://errata.almalinux.org/9/ALSA-2026-9044.html",
"https://errata.rockylinux.org/RLSA-2026:9044",
"https://go.dev/cl/752180",
"https://go.dev/issue/77578",
"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk",
"https://linux.oracle.com/cve/CVE-2026-25679.html",
"https://linux.oracle.com/errata/ELSA-2026-9044.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-25679",
"https://pkg.go.dev/vuln/GO-2026-4601",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json",
"https://www.cve.org/CVERecord?id=CVE-2026-25679"
],
"PublishedDate": "2026-03-06T22:16:00.72Z",
"LastModifiedDate": "2026-09-11T13:17:13.637Z"
},
{
"VulnerabilityID": "CVE-2026-27145",
"VendorIDs": [
"GO-2026-5037"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.11, 1.26.4",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:3a7c09b1d1aae4c56ea7871cfa8b82a1887516521bbe983e8dcf0a1b590fb325",
"Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries",
"Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.",
"Severity": "HIGH",
"CweIDs": [
"CWE-606"
],
"VendorSeverity": {
"alma": 3,
"amazon": 2,
"azure": 2,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:23262",
"https://access.redhat.com/errata/RHSA-2026:23264",
"https://access.redhat.com/errata/RHSA-2026:29980",
"https://access.redhat.com/errata/RHSA-2026:29981",
"https://access.redhat.com/errata/RHSA-2026:33574",
"https://access.redhat.com/errata/RHSA-2026:34357",
"https://access.redhat.com/errata/RHSA-2026:34359",
"https://access.redhat.com/errata/RHSA-2026:35832",
"https://access.redhat.com/errata/RHSA-2026:36317",
"https://access.redhat.com/errata/RHSA-2026:36648",
"https://access.redhat.com/errata/RHSA-2026:36797",
"https://access.redhat.com/errata/RHSA-2026:38995",
"https://access.redhat.com/errata/RHSA-2026:39005",
"https://access.redhat.com/errata/RHSA-2026:39573",
"https://access.redhat.com/errata/RHSA-2026:39879",
"https://access.redhat.com/errata/RHSA-2026:41030",
"https://access.redhat.com/errata/RHSA-2026:41036",
"https://access.redhat.com/errata/RHSA-2026:41930",
"https://access.redhat.com/errata/RHSA-2026:42043",
"https://access.redhat.com/errata/RHSA-2026:42047",
"https://access.redhat.com/errata/RHSA-2026:42049",
"https://access.redhat.com/errata/RHSA-2026:42050",
"https://access.redhat.com/errata/RHSA-2026:42051",
"https://access.redhat.com/errata/RHSA-2026:42079",
"https://access.redhat.com/errata/RHSA-2026:42080",
"https://access.redhat.com/errata/RHSA-2026:42082",
"https://access.redhat.com/errata/RHSA-2026:42142",
"https://access.redhat.com/errata/RHSA-2026:42150",
"https://access.redhat.com/errata/RHSA-2026:42151",
"https://access.redhat.com/errata/RHSA-2026:42240",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:42946",
"https://access.redhat.com/errata/RHSA-2026:44622",
"https://access.redhat.com/errata/RHSA-2026:46394",
"https://access.redhat.com/errata/RHSA-2026:46395",
"https://access.redhat.com/errata/RHSA-2026:47149",
"https://access.redhat.com/errata/RHSA-2026:47735",
"https://access.redhat.com/errata/RHSA-2026:47737",
"https://access.redhat.com/errata/RHSA-2026:49702",
"https://access.redhat.com/errata/RHSA-2026:49703",
"https://access.redhat.com/errata/RHSA-2026:49705",
"https://access.redhat.com/errata/RHSA-2026:49712",
"https://access.redhat.com/errata/RHSA-2026:49729",
"https://access.redhat.com/errata/RHSA-2026:49744",
"https://access.redhat.com/errata/RHSA-2026:49765",
"https://access.redhat.com/errata/RHSA-2026:49770",
"https://access.redhat.com/errata/RHSA-2026:50205",
"https://access.redhat.com/errata/RHSA-2026:50319",
"https://access.redhat.com/errata/RHSA-2026:51057",
"https://access.redhat.com/errata/RHSA-2026:51187",
"https://access.redhat.com/errata/RHSA-2026:52946",
"https://access.redhat.com/errata/RHSA-2026:53374",
"https://access.redhat.com/errata/RHSA-2026:53412",
"https://access.redhat.com/errata/RHSA-2026:53413",
"https://access.redhat.com/errata/RHSA-2026:53415",
"https://access.redhat.com/errata/RHSA-2026:53416",
"https://access.redhat.com/errata/RHSA-2026:53530",
"https://access.redhat.com/errata/RHSA-2026:54168",
"https://access.redhat.com/errata/RHSA-2026:54401",
"https://access.redhat.com/errata/RHSA-2026:54427",
"https://access.redhat.com/errata/RHSA-2026:54432",
"https://access.redhat.com/errata/RHSA-2026:54435",
"https://access.redhat.com/errata/RHSA-2026:54441",
"https://access.redhat.com/errata/RHSA-2026:54500",
"https://access.redhat.com/errata/RHSA-2026:54525",
"https://access.redhat.com/errata/RHSA-2026:54531",
"https://access.redhat.com/errata/RHSA-2026:54603",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:55899",
"https://access.redhat.com/errata/RHSA-2026:57194",
"https://access.redhat.com/errata/RHSA-2026:57482",
"https://access.redhat.com/errata/RHSA-2026:57488",
"https://access.redhat.com/errata/RHSA-2026:57649",
"https://access.redhat.com/errata/RHSA-2026:59556",
"https://access.redhat.com/errata/RHSA-2026:59557",
"https://access.redhat.com/errata/RHSA-2026:59558",
"https://access.redhat.com/errata/RHSA-2026:59559",
"https://access.redhat.com/errata/RHSA-2026:59579",
"https://access.redhat.com/errata/RHSA-2026:59593",
"https://access.redhat.com/errata/RHSA-2026:60025",
"https://access.redhat.com/errata/RHSA-2026:60315",
"https://access.redhat.com/errata/RHSA-2026:60354",
"https://access.redhat.com/errata/RHSA-2026:60386",
"https://access.redhat.com/errata/RHSA-2026:60387",
"https://access.redhat.com/errata/RHSA-2026:60388",
"https://access.redhat.com/errata/RHSA-2026:60390",
"https://access.redhat.com/errata/RHSA-2026:60391",
"https://access.redhat.com/errata/RHSA-2026:61253",
"https://access.redhat.com/errata/RHSA-2026:61314",
"https://access.redhat.com/errata/RHSA-2026:63016",
"https://access.redhat.com/errata/RHSA-2026:66022",
"https://access.redhat.com/security/cve/CVE-2026-27145",
"https://bugzilla.redhat.com/2445356",
"https://bugzilla.redhat.com/2484207",
"https://bugzilla.redhat.com/show_bug.cgi?id=2445356",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484207",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145",
"https://errata.almalinux.org/9/ALSA-2026-36317.html",
"https://errata.rockylinux.org/RLSA-2026:36317",
"https://go.dev/cl/783621",
"https://go.dev/issue/79694",
"https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw",
"https://linux.oracle.com/cve/CVE-2026-27145.html",
"https://linux.oracle.com/errata/ELSA-2026-46395.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-27145",
"https://pkg.go.dev/vuln/GO-2026-5037",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json",
"https://www.cve.org/CVERecord?id=CVE-2026-27145"
],
"PublishedDate": "2026-06-02T23:16:35.57Z",
"LastModifiedDate": "2026-09-11T13:17:23.34Z"
},
{
"VulnerabilityID": "CVE-2026-32280",
"VendorIDs": [
"GO-2026-4947"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.9, 1.26.2",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:410ae40aee7fb35c67628e5cd49f29fceb7608c091a712b76b32aa59d9e10eac",
"Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building",
"Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3,
"ubuntu": 2
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:10217",
"https://access.redhat.com/errata/RHSA-2026:10219",
"https://access.redhat.com/errata/RHSA-2026:10704",
"https://access.redhat.com/errata/RHSA-2026:11507",
"https://access.redhat.com/errata/RHSA-2026:11514",
"https://access.redhat.com/errata/RHSA-2026:11688",
"https://access.redhat.com/errata/RHSA-2026:13545",
"https://access.redhat.com/errata/RHSA-2026:13791",
"https://access.redhat.com/errata/RHSA-2026:13826",
"https://access.redhat.com/errata/RHSA-2026:13829",
"https://access.redhat.com/errata/RHSA-2026:14020",
"https://access.redhat.com/errata/RHSA-2026:14162",
"https://access.redhat.com/errata/RHSA-2026:14200",
"https://access.redhat.com/errata/RHSA-2026:14391",
"https://access.redhat.com/errata/RHSA-2026:15980",
"https://access.redhat.com/errata/RHSA-2026:16021",
"https://access.redhat.com/errata/RHSA-2026:16024",
"https://access.redhat.com/errata/RHSA-2026:16101",
"https://access.redhat.com/errata/RHSA-2026:16476",
"https://access.redhat.com/errata/RHSA-2026:16477",
"https://access.redhat.com/errata/RHSA-2026:16505",
"https://access.redhat.com/errata/RHSA-2026:16508",
"https://access.redhat.com/errata/RHSA-2026:16532",
"https://access.redhat.com/errata/RHSA-2026:16534",
"https://access.redhat.com/errata/RHSA-2026:16535",
"https://access.redhat.com/errata/RHSA-2026:16537",
"https://access.redhat.com/errata/RHSA-2026:16542",
"https://access.redhat.com/errata/RHSA-2026:16874",
"https://access.redhat.com/errata/RHSA-2026:16875",
"https://access.redhat.com/errata/RHSA-2026:17084",
"https://access.redhat.com/errata/RHSA-2026:17287",
"https://access.redhat.com/errata/RHSA-2026:18027",
"https://access.redhat.com/errata/RHSA-2026:18032",
"https://access.redhat.com/errata/RHSA-2026:19133",
"https://access.redhat.com/errata/RHSA-2026:19135",
"https://access.redhat.com/errata/RHSA-2026:19144",
"https://access.redhat.com/errata/RHSA-2026:19350",
"https://access.redhat.com/errata/RHSA-2026:19353",
"https://access.redhat.com/errata/RHSA-2026:19375",
"https://access.redhat.com/errata/RHSA-2026:19450",
"https://access.redhat.com/errata/RHSA-2026:19550",
"https://access.redhat.com/errata/RHSA-2026:19634",
"https://access.redhat.com/errata/RHSA-2026:19714",
"https://access.redhat.com/errata/RHSA-2026:19715",
"https://access.redhat.com/errata/RHSA-2026:19719",
"https://access.redhat.com/errata/RHSA-2026:19720",
"https://access.redhat.com/errata/RHSA-2026:19721",
"https://access.redhat.com/errata/RHSA-2026:19722",
"https://access.redhat.com/errata/RHSA-2026:19750",
"https://access.redhat.com/errata/RHSA-2026:19839",
"https://access.redhat.com/errata/RHSA-2026:20556",
"https://access.redhat.com/errata/RHSA-2026:20569",
"https://access.redhat.com/errata/RHSA-2026:20570",
"https://access.redhat.com/errata/RHSA-2026:20571",
"https://access.redhat.com/errata/RHSA-2026:20607",
"https://access.redhat.com/errata/RHSA-2026:20608",
"https://access.redhat.com/errata/RHSA-2026:20609",
"https://access.redhat.com/errata/RHSA-2026:20889",
"https://access.redhat.com/errata/RHSA-2026:21017",
"https://access.redhat.com/errata/RHSA-2026:21338",
"https://access.redhat.com/errata/RHSA-2026:21655",
"https://access.redhat.com/errata/RHSA-2026:21769",
"https://access.redhat.com/errata/RHSA-2026:21772",
"https://access.redhat.com/errata/RHSA-2026:22130",
"https://access.redhat.com/errata/RHSA-2026:22141",
"https://access.redhat.com/errata/RHSA-2026:22258",
"https://access.redhat.com/errata/RHSA-2026:22260",
"https://access.redhat.com/errata/RHSA-2026:22268",
"https://access.redhat.com/errata/RHSA-2026:22309",
"https://access.redhat.com/errata/RHSA-2026:22347",
"https://access.redhat.com/errata/RHSA-2026:22415",
"https://access.redhat.com/errata/RHSA-2026:22422",
"https://access.redhat.com/errata/RHSA-2026:22465",
"https://access.redhat.com/errata/RHSA-2026:22485",
"https://access.redhat.com/errata/RHSA-2026:22709",
"https://access.redhat.com/errata/RHSA-2026:22713",
"https://access.redhat.com/errata/RHSA-2026:22840",
"https://access.redhat.com/errata/RHSA-2026:22862",
"https://access.redhat.com/errata/RHSA-2026:22958",
"https://access.redhat.com/errata/RHSA-2026:22959",
"https://access.redhat.com/errata/RHSA-2026:22960",
"https://access.redhat.com/errata/RHSA-2026:22961",
"https://access.redhat.com/errata/RHSA-2026:22962",
"https://access.redhat.com/errata/RHSA-2026:23102",
"https://access.redhat.com/errata/RHSA-2026:23103",
"https://access.redhat.com/errata/RHSA-2026:23244",
"https://access.redhat.com/errata/RHSA-2026:23345",
"https://access.redhat.com/errata/RHSA-2026:23361",
"https://access.redhat.com/errata/RHSA-2026:24337",
"https://access.redhat.com/errata/RHSA-2026:24359",
"https://access.redhat.com/errata/RHSA-2026:24470",
"https://access.redhat.com/errata/RHSA-2026:24478",
"https://access.redhat.com/errata/RHSA-2026:24716",
"https://access.redhat.com/errata/RHSA-2026:24761",
"https://access.redhat.com/errata/RHSA-2026:24762",
"https://access.redhat.com/errata/RHSA-2026:24853",
"https://access.redhat.com/errata/RHSA-2026:24977",
"https://access.redhat.com/errata/RHSA-2026:25089",
"https://access.redhat.com/errata/RHSA-2026:25127",
"https://access.redhat.com/errata/RHSA-2026:25180",
"https://access.redhat.com/errata/RHSA-2026:25248",
"https://access.redhat.com/errata/RHSA-2026:25250",
"https://access.redhat.com/errata/RHSA-2026:25251",
"https://access.redhat.com/errata/RHSA-2026:25252",
"https://access.redhat.com/errata/RHSA-2026:25253",
"https://access.redhat.com/errata/RHSA-2026:26447",
"https://access.redhat.com/errata/RHSA-2026:26568",
"https://access.redhat.com/errata/RHSA-2026:26571",
"https://access.redhat.com/errata/RHSA-2026:26585",
"https://access.redhat.com/errata/RHSA-2026:26636",
"https://access.redhat.com/errata/RHSA-2026:27076",
"https://access.redhat.com/errata/RHSA-2026:28038",
"https://access.redhat.com/errata/RHSA-2026:28047",
"https://access.redhat.com/errata/RHSA-2026:28074",
"https://access.redhat.com/errata/RHSA-2026:28196",
"https://access.redhat.com/errata/RHSA-2026:28198",
"https://access.redhat.com/errata/RHSA-2026:28441",
"https://access.redhat.com/errata/RHSA-2026:28886",
"https://access.redhat.com/errata/RHSA-2026:28961",
"https://access.redhat.com/errata/RHSA-2026:29035",
"https://access.redhat.com/errata/RHSA-2026:29195",
"https://access.redhat.com/errata/RHSA-2026:29455",
"https://access.redhat.com/errata/RHSA-2026:29702",
"https://access.redhat.com/errata/RHSA-2026:29703",
"https://access.redhat.com/errata/RHSA-2026:29854",
"https://access.redhat.com/errata/RHSA-2026:33722",
"https://access.redhat.com/errata/RHSA-2026:34097",
"https://access.redhat.com/errata/RHSA-2026:34192",
"https://access.redhat.com/errata/RHSA-2026:34196",
"https://access.redhat.com/errata/RHSA-2026:34197",
"https://access.redhat.com/errata/RHSA-2026:34365",
"https://access.redhat.com/errata/RHSA-2026:36319",
"https://access.redhat.com/errata/RHSA-2026:36625",
"https://access.redhat.com/errata/RHSA-2026:36651",
"https://access.redhat.com/errata/RHSA-2026:36796",
"https://access.redhat.com/errata/RHSA-2026:39810",
"https://access.redhat.com/errata/RHSA-2026:39894",
"https://access.redhat.com/errata/RHSA-2026:40118",
"https://access.redhat.com/errata/RHSA-2026:40945",
"https://access.redhat.com/errata/RHSA-2026:41019",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:42043",
"https://access.redhat.com/errata/RHSA-2026:42047",
"https://access.redhat.com/errata/RHSA-2026:42049",
"https://access.redhat.com/errata/RHSA-2026:42050",
"https://access.redhat.com/errata/RHSA-2026:42051",
"https://access.redhat.com/errata/RHSA-2026:47712",
"https://access.redhat.com/errata/RHSA-2026:47714",
"https://access.redhat.com/errata/RHSA-2026:47716",
"https://access.redhat.com/errata/RHSA-2026:47719",
"https://access.redhat.com/errata/RHSA-2026:47721",
"https://access.redhat.com/errata/RHSA-2026:47722",
"https://access.redhat.com/errata/RHSA-2026:47910",
"https://access.redhat.com/errata/RHSA-2026:47952",
"https://access.redhat.com/errata/RHSA-2026:48036",
"https://access.redhat.com/errata/RHSA-2026:48790",
"https://access.redhat.com/errata/RHSA-2026:49509",
"https://access.redhat.com/errata/RHSA-2026:49526",
"https://access.redhat.com/errata/RHSA-2026:49600",
"https://access.redhat.com/errata/RHSA-2026:49838",
"https://access.redhat.com/errata/RHSA-2026:49944",
"https://access.redhat.com/errata/RHSA-2026:51033",
"https://access.redhat.com/errata/RHSA-2026:51288",
"https://access.redhat.com/errata/RHSA-2026:54191",
"https://access.redhat.com/errata/RHSA-2026:54603",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:56785",
"https://access.redhat.com/errata/RHSA-2026:56789",
"https://access.redhat.com/errata/RHSA-2026:56852",
"https://access.redhat.com/errata/RHSA-2026:56855",
"https://access.redhat.com/errata/RHSA-2026:56910",
"https://access.redhat.com/errata/RHSA-2026:56912",
"https://access.redhat.com/errata/RHSA-2026:56913",
"https://access.redhat.com/errata/RHSA-2026:57409",
"https://access.redhat.com/errata/RHSA-2026:57482",
"https://access.redhat.com/errata/RHSA-2026:57488",
"https://access.redhat.com/errata/RHSA-2026:59830",
"https://access.redhat.com/errata/RHSA-2026:59833",
"https://access.redhat.com/errata/RHSA-2026:59834",
"https://access.redhat.com/errata/RHSA-2026:60018",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:61685",
"https://access.redhat.com/errata/RHSA-2026:61906",
"https://access.redhat.com/errata/RHSA-2026:61907",
"https://access.redhat.com/errata/RHSA-2026:65534",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/errata/RHSA-2026:66401",
"https://access.redhat.com/errata/RHSA-2026:9385",
"https://access.redhat.com/security/cve/CVE-2026-32280",
"https://bugzilla.redhat.com/2456333",
"https://bugzilla.redhat.com/2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-49838.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/758320",
"https://go.dev/issue/78282",
"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
"https://linux.oracle.com/cve/CVE-2026-32280.html",
"https://linux.oracle.com/errata/ELSA-2026-65886-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-32280",
"https://pkg.go.dev/vuln/GO-2026-4947",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json",
"https://www.cve.org/CVERecord?id=CVE-2026-32280"
],
"PublishedDate": "2026-04-08T02:16:03.247Z",
"LastModifiedDate": "2026-09-11T13:17:25.78Z"
},
{
"VulnerabilityID": "CVE-2026-32281",
"VendorIDs": [
"GO-2026-4946"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.9, 1.26.2",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:3947214e46925b7bcc5973fb91791daf2df731a64d5664c98c3670ffb6aef6e8",
"Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation",
"Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.",
"Severity": "HIGH",
"CweIDs": [
"CWE-295"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"nvd": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 2,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 5.9
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:49838",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/security/cve/CVE-2026-32281",
"https://bugzilla.redhat.com/2456333",
"https://bugzilla.redhat.com/2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-49838.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/758061",
"https://go.dev/issue/78281",
"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
"https://linux.oracle.com/cve/CVE-2026-32281.html",
"https://linux.oracle.com/errata/ELSA-2026-65886-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-32281",
"https://pkg.go.dev/vuln/GO-2026-4946",
"https://www.cve.org/CVERecord?id=CVE-2026-32281"
],
"PublishedDate": "2026-04-08T02:16:03.35Z",
"LastModifiedDate": "2026-07-25T10:10:00.167Z"
},
{
"VulnerabilityID": "CVE-2026-32283",
"VendorIDs": [
"GO-2026-4870"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.9, 1.26.2",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:965802bb9463307b15770c73fae0a2f95f237afbd1db40c33004e4bc4f732115",
"Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages",
"Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770",
"CWE-764"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"nvd": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:10217",
"https://access.redhat.com/errata/RHSA-2026:10219",
"https://access.redhat.com/errata/RHSA-2026:10704",
"https://access.redhat.com/errata/RHSA-2026:11507",
"https://access.redhat.com/errata/RHSA-2026:11514",
"https://access.redhat.com/errata/RHSA-2026:11704",
"https://access.redhat.com/errata/RHSA-2026:11711",
"https://access.redhat.com/errata/RHSA-2026:11712",
"https://access.redhat.com/errata/RHSA-2026:11863",
"https://access.redhat.com/errata/RHSA-2026:11881",
"https://access.redhat.com/errata/RHSA-2026:14162",
"https://access.redhat.com/errata/RHSA-2026:14200",
"https://access.redhat.com/errata/RHSA-2026:14391",
"https://access.redhat.com/errata/RHSA-2026:15980",
"https://access.redhat.com/errata/RHSA-2026:16021",
"https://access.redhat.com/errata/RHSA-2026:16024",
"https://access.redhat.com/errata/RHSA-2026:16101",
"https://access.redhat.com/errata/RHSA-2026:16102",
"https://access.redhat.com/errata/RHSA-2026:16875",
"https://access.redhat.com/errata/RHSA-2026:17075",
"https://access.redhat.com/errata/RHSA-2026:17084",
"https://access.redhat.com/errata/RHSA-2026:17287",
"https://access.redhat.com/errata/RHSA-2026:18027",
"https://access.redhat.com/errata/RHSA-2026:18032",
"https://access.redhat.com/errata/RHSA-2026:19126",
"https://access.redhat.com/errata/RHSA-2026:19132",
"https://access.redhat.com/errata/RHSA-2026:19133",
"https://access.redhat.com/errata/RHSA-2026:19134",
"https://access.redhat.com/errata/RHSA-2026:19135",
"https://access.redhat.com/errata/RHSA-2026:19136",
"https://access.redhat.com/errata/RHSA-2026:19137",
"https://access.redhat.com/errata/RHSA-2026:19139",
"https://access.redhat.com/errata/RHSA-2026:19144",
"https://access.redhat.com/errata/RHSA-2026:19156",
"https://access.redhat.com/errata/RHSA-2026:19350",
"https://access.redhat.com/errata/RHSA-2026:19351",
"https://access.redhat.com/errata/RHSA-2026:19352",
"https://access.redhat.com/errata/RHSA-2026:19353",
"https://access.redhat.com/errata/RHSA-2026:19369",
"https://access.redhat.com/errata/RHSA-2026:19450",
"https://access.redhat.com/errata/RHSA-2026:19550",
"https://access.redhat.com/errata/RHSA-2026:19634",
"https://access.redhat.com/errata/RHSA-2026:19714",
"https://access.redhat.com/errata/RHSA-2026:19715",
"https://access.redhat.com/errata/RHSA-2026:19719",
"https://access.redhat.com/errata/RHSA-2026:19720",
"https://access.redhat.com/errata/RHSA-2026:19721",
"https://access.redhat.com/errata/RHSA-2026:19722",
"https://access.redhat.com/errata/RHSA-2026:19750",
"https://access.redhat.com/errata/RHSA-2026:19839",
"https://access.redhat.com/errata/RHSA-2026:20556",
"https://access.redhat.com/errata/RHSA-2026:20569",
"https://access.redhat.com/errata/RHSA-2026:20570",
"https://access.redhat.com/errata/RHSA-2026:20571",
"https://access.redhat.com/errata/RHSA-2026:20607",
"https://access.redhat.com/errata/RHSA-2026:20608",
"https://access.redhat.com/errata/RHSA-2026:20609",
"https://access.redhat.com/errata/RHSA-2026:21769",
"https://access.redhat.com/errata/RHSA-2026:22347",
"https://access.redhat.com/errata/RHSA-2026:22423",
"https://access.redhat.com/errata/RHSA-2026:22450",
"https://access.redhat.com/errata/RHSA-2026:22485",
"https://access.redhat.com/errata/RHSA-2026:22709",
"https://access.redhat.com/errata/RHSA-2026:22713",
"https://access.redhat.com/errata/RHSA-2026:22714",
"https://access.redhat.com/errata/RHSA-2026:22937",
"https://access.redhat.com/errata/RHSA-2026:23102",
"https://access.redhat.com/errata/RHSA-2026:23103",
"https://access.redhat.com/errata/RHSA-2026:23228",
"https://access.redhat.com/errata/RHSA-2026:23345",
"https://access.redhat.com/errata/RHSA-2026:24337",
"https://access.redhat.com/errata/RHSA-2026:24470",
"https://access.redhat.com/errata/RHSA-2026:24761",
"https://access.redhat.com/errata/RHSA-2026:24762",
"https://access.redhat.com/errata/RHSA-2026:25248",
"https://access.redhat.com/errata/RHSA-2026:25250",
"https://access.redhat.com/errata/RHSA-2026:25251",
"https://access.redhat.com/errata/RHSA-2026:25252",
"https://access.redhat.com/errata/RHSA-2026:26447",
"https://access.redhat.com/errata/RHSA-2026:26571",
"https://access.redhat.com/errata/RHSA-2026:26636",
"https://access.redhat.com/errata/RHSA-2026:27076",
"https://access.redhat.com/errata/RHSA-2026:28038",
"https://access.redhat.com/errata/RHSA-2026:28047",
"https://access.redhat.com/errata/RHSA-2026:28074",
"https://access.redhat.com/errata/RHSA-2026:29035",
"https://access.redhat.com/errata/RHSA-2026:29195",
"https://access.redhat.com/errata/RHSA-2026:29455",
"https://access.redhat.com/errata/RHSA-2026:29703",
"https://access.redhat.com/errata/RHSA-2026:33722",
"https://access.redhat.com/errata/RHSA-2026:34192",
"https://access.redhat.com/errata/RHSA-2026:34196",
"https://access.redhat.com/errata/RHSA-2026:34197",
"https://access.redhat.com/errata/RHSA-2026:34365",
"https://access.redhat.com/errata/RHSA-2026:36796",
"https://access.redhat.com/errata/RHSA-2026:39810",
"https://access.redhat.com/errata/RHSA-2026:41019",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:47712",
"https://access.redhat.com/errata/RHSA-2026:47714",
"https://access.redhat.com/errata/RHSA-2026:47716",
"https://access.redhat.com/errata/RHSA-2026:47719",
"https://access.redhat.com/errata/RHSA-2026:47721",
"https://access.redhat.com/errata/RHSA-2026:47722",
"https://access.redhat.com/errata/RHSA-2026:47910",
"https://access.redhat.com/errata/RHSA-2026:48036",
"https://access.redhat.com/errata/RHSA-2026:48790",
"https://access.redhat.com/errata/RHSA-2026:49509",
"https://access.redhat.com/errata/RHSA-2026:49600",
"https://access.redhat.com/errata/RHSA-2026:49944",
"https://access.redhat.com/errata/RHSA-2026:51288",
"https://access.redhat.com/errata/RHSA-2026:54191",
"https://access.redhat.com/errata/RHSA-2026:54435",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:55898",
"https://access.redhat.com/errata/RHSA-2026:55900",
"https://access.redhat.com/errata/RHSA-2026:55901",
"https://access.redhat.com/errata/RHSA-2026:55902",
"https://access.redhat.com/errata/RHSA-2026:55903",
"https://access.redhat.com/errata/RHSA-2026:56910",
"https://access.redhat.com/errata/RHSA-2026:57409",
"https://access.redhat.com/errata/RHSA-2026:57801",
"https://access.redhat.com/errata/RHSA-2026:57802",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:65126",
"https://access.redhat.com/errata/RHSA-2026:65343",
"https://access.redhat.com/errata/RHSA-2026:65514",
"https://access.redhat.com/errata/RHSA-2026:66022",
"https://access.redhat.com/errata/RHSA-2026:66084",
"https://access.redhat.com/errata/RHSA-2026:66401",
"https://access.redhat.com/errata/RHSA-2026:66523",
"https://access.redhat.com/errata/RHSA-2026:7291",
"https://access.redhat.com/errata/RHSA-2026:7385",
"https://access.redhat.com/security/cve/CVE-2026-32283",
"https://bugzilla.redhat.com/2445356",
"https://bugzilla.redhat.com/2456333",
"https://bugzilla.redhat.com/2456338",
"https://bugzilla.redhat.com/2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2445356",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456338",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283",
"https://errata.almalinux.org/9/ALSA-2026-29703.html",
"https://errata.rockylinux.org/RLSA-2026:29703",
"https://go.dev/cl/763767",
"https://go.dev/issue/78334",
"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
"https://linux.oracle.com/cve/CVE-2026-32283.html",
"https://linux.oracle.com/errata/ELSA-2026-48790.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-32283",
"https://pkg.go.dev/vuln/GO-2026-4870",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json",
"https://www.cve.org/CVERecord?id=CVE-2026-32283"
],
"PublishedDate": "2026-04-08T02:16:03.58Z",
"LastModifiedDate": "2026-09-11T13:17:28.143Z"
},
{
"VulnerabilityID": "CVE-2026-33811",
"VendorIDs": [
"GO-2026-4981"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.10, 1.26.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:004312b4e1707e898ddf8ceb2af30341987542cfd2599ecdf4ee230992ae6179",
"Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME",
"Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.",
"Severity": "HIGH",
"CweIDs": [
"CWE-415",
"CWE-1341"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"nvd": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:22112",
"https://access.redhat.com/errata/RHSA-2026:22120",
"https://access.redhat.com/errata/RHSA-2026:22121",
"https://access.redhat.com/errata/RHSA-2026:23262",
"https://access.redhat.com/errata/RHSA-2026:23264",
"https://access.redhat.com/errata/RHSA-2026:33120",
"https://access.redhat.com/errata/RHSA-2026:33123",
"https://access.redhat.com/errata/RHSA-2026:33142",
"https://access.redhat.com/errata/RHSA-2026:33150",
"https://access.redhat.com/errata/RHSA-2026:33574",
"https://access.redhat.com/errata/RHSA-2026:34357",
"https://access.redhat.com/errata/RHSA-2026:34359",
"https://access.redhat.com/errata/RHSA-2026:34364",
"https://access.redhat.com/errata/RHSA-2026:35832",
"https://access.redhat.com/errata/RHSA-2026:35993",
"https://access.redhat.com/errata/RHSA-2026:35994",
"https://access.redhat.com/errata/RHSA-2026:35995",
"https://access.redhat.com/errata/RHSA-2026:36207",
"https://access.redhat.com/errata/RHSA-2026:36319",
"https://access.redhat.com/errata/RHSA-2026:36617",
"https://access.redhat.com/errata/RHSA-2026:36625",
"https://access.redhat.com/errata/RHSA-2026:36648",
"https://access.redhat.com/errata/RHSA-2026:36651",
"https://access.redhat.com/errata/RHSA-2026:36776",
"https://access.redhat.com/errata/RHSA-2026:36796",
"https://access.redhat.com/errata/RHSA-2026:36797",
"https://access.redhat.com/errata/RHSA-2026:38504",
"https://access.redhat.com/errata/RHSA-2026:39266",
"https://access.redhat.com/errata/RHSA-2026:39272",
"https://access.redhat.com/errata/RHSA-2026:39319",
"https://access.redhat.com/errata/RHSA-2026:39573",
"https://access.redhat.com/errata/RHSA-2026:39810",
"https://access.redhat.com/errata/RHSA-2026:40118",
"https://access.redhat.com/errata/RHSA-2026:40119",
"https://access.redhat.com/errata/RHSA-2026:40945",
"https://access.redhat.com/errata/RHSA-2026:41019",
"https://access.redhat.com/errata/RHSA-2026:41030",
"https://access.redhat.com/errata/RHSA-2026:41055",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:42043",
"https://access.redhat.com/errata/RHSA-2026:42047",
"https://access.redhat.com/errata/RHSA-2026:42048",
"https://access.redhat.com/errata/RHSA-2026:42049",
"https://access.redhat.com/errata/RHSA-2026:42050",
"https://access.redhat.com/errata/RHSA-2026:42051",
"https://access.redhat.com/errata/RHSA-2026:42078",
"https://access.redhat.com/errata/RHSA-2026:42079",
"https://access.redhat.com/errata/RHSA-2026:42082",
"https://access.redhat.com/errata/RHSA-2026:42132",
"https://access.redhat.com/errata/RHSA-2026:42150",
"https://access.redhat.com/errata/RHSA-2026:42151",
"https://access.redhat.com/errata/RHSA-2026:42240",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:42852",
"https://access.redhat.com/errata/RHSA-2026:42946",
"https://access.redhat.com/errata/RHSA-2026:43038",
"https://access.redhat.com/errata/RHSA-2026:43692",
"https://access.redhat.com/errata/RHSA-2026:44622",
"https://access.redhat.com/errata/RHSA-2026:46885",
"https://access.redhat.com/errata/RHSA-2026:47149",
"https://access.redhat.com/errata/RHSA-2026:47735",
"https://access.redhat.com/errata/RHSA-2026:47952",
"https://access.redhat.com/errata/RHSA-2026:48151",
"https://access.redhat.com/errata/RHSA-2026:49702",
"https://access.redhat.com/errata/RHSA-2026:49703",
"https://access.redhat.com/errata/RHSA-2026:49712",
"https://access.redhat.com/errata/RHSA-2026:50205",
"https://access.redhat.com/errata/RHSA-2026:50300",
"https://access.redhat.com/errata/RHSA-2026:50319",
"https://access.redhat.com/errata/RHSA-2026:50336",
"https://access.redhat.com/errata/RHSA-2026:50843",
"https://access.redhat.com/errata/RHSA-2026:51033",
"https://access.redhat.com/errata/RHSA-2026:51057",
"https://access.redhat.com/errata/RHSA-2026:51187",
"https://access.redhat.com/errata/RHSA-2026:51194",
"https://access.redhat.com/errata/RHSA-2026:51341",
"https://access.redhat.com/errata/RHSA-2026:53412",
"https://access.redhat.com/errata/RHSA-2026:53413",
"https://access.redhat.com/errata/RHSA-2026:53415",
"https://access.redhat.com/errata/RHSA-2026:53530",
"https://access.redhat.com/errata/RHSA-2026:54168",
"https://access.redhat.com/errata/RHSA-2026:54191",
"https://access.redhat.com/errata/RHSA-2026:54274",
"https://access.redhat.com/errata/RHSA-2026:54283",
"https://access.redhat.com/errata/RHSA-2026:54284",
"https://access.redhat.com/errata/RHSA-2026:54285",
"https://access.redhat.com/errata/RHSA-2026:54286",
"https://access.redhat.com/errata/RHSA-2026:54287",
"https://access.redhat.com/errata/RHSA-2026:54435",
"https://access.redhat.com/errata/RHSA-2026:54441",
"https://access.redhat.com/errata/RHSA-2026:54500",
"https://access.redhat.com/errata/RHSA-2026:54552",
"https://access.redhat.com/errata/RHSA-2026:54556",
"https://access.redhat.com/errata/RHSA-2026:54584",
"https://access.redhat.com/errata/RHSA-2026:54602",
"https://access.redhat.com/errata/RHSA-2026:54603",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:56340",
"https://access.redhat.com/errata/RHSA-2026:56785",
"https://access.redhat.com/errata/RHSA-2026:56789",
"https://access.redhat.com/errata/RHSA-2026:56790",
"https://access.redhat.com/errata/RHSA-2026:56852",
"https://access.redhat.com/errata/RHSA-2026:56855",
"https://access.redhat.com/errata/RHSA-2026:56910",
"https://access.redhat.com/errata/RHSA-2026:56912",
"https://access.redhat.com/errata/RHSA-2026:56913",
"https://access.redhat.com/errata/RHSA-2026:57191",
"https://access.redhat.com/errata/RHSA-2026:57194",
"https://access.redhat.com/errata/RHSA-2026:57482",
"https://access.redhat.com/errata/RHSA-2026:57488",
"https://access.redhat.com/errata/RHSA-2026:57649",
"https://access.redhat.com/errata/RHSA-2026:59467",
"https://access.redhat.com/errata/RHSA-2026:59559",
"https://access.redhat.com/errata/RHSA-2026:60018",
"https://access.redhat.com/errata/RHSA-2026:60025",
"https://access.redhat.com/errata/RHSA-2026:60302",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:61253",
"https://access.redhat.com/errata/RHSA-2026:61313",
"https://access.redhat.com/errata/RHSA-2026:65126",
"https://access.redhat.com/errata/RHSA-2026:65534",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/errata/RHSA-2026:66022",
"https://access.redhat.com/security/cve/CVE-2026-33811",
"https://bugzilla.redhat.com/2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-39319.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/767860",
"https://go.dev/issue/78803",
"https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
"https://linux.oracle.com/cve/CVE-2026-33811.html",
"https://linux.oracle.com/errata/ELSA-2026-65886-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-33811",
"https://pkg.go.dev/vuln/GO-2026-4981",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json",
"https://www.cve.org/CVERecord?id=CVE-2026-33811"
],
"PublishedDate": "2026-05-07T20:16:42.77Z",
"LastModifiedDate": "2026-09-11T13:17:36.897Z"
},
{
"VulnerabilityID": "CVE-2026-33814",
"VendorIDs": [
"GO-2026-4918"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.10, 1.26.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:4a7b8118d6015a5713995ff44a1b2afc1358fbdf564b3deb943a8be585211fe2",
"Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame",
"Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.",
"Severity": "HIGH",
"CweIDs": [
"CWE-835",
"CWE-606"
],
"VendorSeverity": {
"amazon": 3,
"azure": 2,
"bitnami": 3,
"nvd": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3,
"ubuntu": 2
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:22112",
"https://access.redhat.com/errata/RHSA-2026:22120",
"https://access.redhat.com/errata/RHSA-2026:22121",
"https://access.redhat.com/errata/RHSA-2026:23262",
"https://access.redhat.com/errata/RHSA-2026:23264",
"https://access.redhat.com/errata/RHSA-2026:33120",
"https://access.redhat.com/errata/RHSA-2026:33123",
"https://access.redhat.com/errata/RHSA-2026:33142",
"https://access.redhat.com/errata/RHSA-2026:33150",
"https://access.redhat.com/errata/RHSA-2026:34342",
"https://access.redhat.com/errata/RHSA-2026:37387",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:43692",
"https://access.redhat.com/errata/RHSA-2026:49702",
"https://access.redhat.com/errata/RHSA-2026:49712",
"https://access.redhat.com/errata/RHSA-2026:50205",
"https://access.redhat.com/errata/RHSA-2026:54274",
"https://access.redhat.com/errata/RHSA-2026:54283",
"https://access.redhat.com/errata/RHSA-2026:54284",
"https://access.redhat.com/errata/RHSA-2026:54285",
"https://access.redhat.com/errata/RHSA-2026:54286",
"https://access.redhat.com/errata/RHSA-2026:54287",
"https://access.redhat.com/errata/RHSA-2026:56854",
"https://access.redhat.com/errata/RHSA-2026:56912",
"https://access.redhat.com/errata/RHSA-2026:57191",
"https://access.redhat.com/errata/RHSA-2026:57194",
"https://access.redhat.com/errata/RHSA-2026:57365",
"https://access.redhat.com/errata/RHSA-2026:57367",
"https://access.redhat.com/errata/RHSA-2026:57408",
"https://access.redhat.com/errata/RHSA-2026:57545",
"https://access.redhat.com/errata/RHSA-2026:57649",
"https://access.redhat.com/errata/RHSA-2026:57845",
"https://access.redhat.com/errata/RHSA-2026:59833",
"https://access.redhat.com/errata/RHSA-2026:60023",
"https://access.redhat.com/errata/RHSA-2026:60025",
"https://access.redhat.com/errata/RHSA-2026:60441",
"https://access.redhat.com/errata/RHSA-2026:60442",
"https://access.redhat.com/errata/RHSA-2026:60446",
"https://access.redhat.com/errata/RHSA-2026:60447",
"https://access.redhat.com/errata/RHSA-2026:60454",
"https://access.redhat.com/errata/RHSA-2026:60477",
"https://access.redhat.com/errata/RHSA-2026:60478",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:60668",
"https://access.redhat.com/errata/RHSA-2026:61253",
"https://access.redhat.com/errata/RHSA-2026:62550",
"https://access.redhat.com/errata/RHSA-2026:62551",
"https://access.redhat.com/errata/RHSA-2026:63046",
"https://access.redhat.com/errata/RHSA-2026:63047",
"https://access.redhat.com/errata/RHSA-2026:63048",
"https://access.redhat.com/errata/RHSA-2026:63050",
"https://access.redhat.com/errata/RHSA-2026:63091",
"https://access.redhat.com/errata/RHSA-2026:63096",
"https://access.redhat.com/errata/RHSA-2026:63097",
"https://access.redhat.com/errata/RHSA-2026:63103",
"https://access.redhat.com/errata/RHSA-2026:63104",
"https://access.redhat.com/errata/RHSA-2026:63636",
"https://access.redhat.com/errata/RHSA-2026:63637",
"https://access.redhat.com/errata/RHSA-2026:63639",
"https://access.redhat.com/errata/RHSA-2026:65126",
"https://access.redhat.com/security/cve/CVE-2026-33814",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467810",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467811",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467813",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467823",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467825",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467826",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467827",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501",
"https://errata.rockylinux.org/RLSA-2026:22121",
"https://github.com/golang/go/issues/78476",
"https://go-review.googlesource.com/c/go/+/761581",
"https://go-review.googlesource.com/c/net/+/761640",
"https://go.dev/cl/761581",
"https://go.dev/cl/761640",
"https://go.dev/issue/78476",
"https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
"https://linux.oracle.com/cve/CVE-2026-33814.html",
"https://linux.oracle.com/errata/ELSA-2026-22121.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-33814",
"https://pkg.go.dev/vuln/GO-2026-4918",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json",
"https://ubuntu.com/security/notices/USN-8430-1",
"https://ubuntu.com/security/notices/USN-8471-1",
"https://ubuntu.com/security/notices/USN-8472-1",
"https://ubuntu.com/security/notices/USN-8473-1",
"https://www.cve.org/CVERecord?id=CVE-2026-33814"
],
"PublishedDate": "2026-05-07T20:16:42.88Z",
"LastModifiedDate": "2026-09-10T13:18:21.31Z"
},
{
"VulnerabilityID": "CVE-2026-33818",
"VendorIDs": [
"GO-2026-5972"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:21423acbb2f332d0c0700e765ddce51b45aa9858321f74ef03a70715096882c2",
"Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal",
"Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
"Severity": "HIGH",
"CweIDs": [
"CWE-400"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:66364",
"https://access.redhat.com/security/cve/CVE-2026-33818",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-66364.html",
"https://errata.rockylinux.org/RLSA-2026:66364",
"https://go.dev/cl/814980",
"https://go.dev/issue/80405",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://linux.oracle.com/cve/CVE-2026-33818.html",
"https://linux.oracle.com/errata/ELSA-2026-66364-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-33818",
"https://pkg.go.dev/vuln/GO-2026-5972",
"https://www.cve.org/CVERecord?id=CVE-2026-33818"
],
"PublishedDate": "2026-08-13T22:17:19.84Z",
"LastModifiedDate": "2026-09-03T16:37:52.17Z"
},
{
"VulnerabilityID": "CVE-2026-39820",
"VendorIDs": [
"GO-2026-4986"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.10, 1.26.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:b9afbb8ba13f7400e14d3ffe6f645c0ae91f9935214373052359edeb17762135",
"Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs",
"Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770",
"CWE-606"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"nvd": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:22112",
"https://access.redhat.com/errata/RHSA-2026:22120",
"https://access.redhat.com/errata/RHSA-2026:22121",
"https://access.redhat.com/errata/RHSA-2026:23262",
"https://access.redhat.com/errata/RHSA-2026:23264",
"https://access.redhat.com/errata/RHSA-2026:33120",
"https://access.redhat.com/errata/RHSA-2026:33123",
"https://access.redhat.com/errata/RHSA-2026:33142",
"https://access.redhat.com/errata/RHSA-2026:33150",
"https://access.redhat.com/errata/RHSA-2026:33574",
"https://access.redhat.com/errata/RHSA-2026:34364",
"https://access.redhat.com/errata/RHSA-2026:36319",
"https://access.redhat.com/errata/RHSA-2026:36625",
"https://access.redhat.com/errata/RHSA-2026:36754",
"https://access.redhat.com/errata/RHSA-2026:36797",
"https://access.redhat.com/errata/RHSA-2026:40262",
"https://access.redhat.com/errata/RHSA-2026:41031",
"https://access.redhat.com/errata/RHSA-2026:41066",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:42146",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:42796",
"https://access.redhat.com/errata/RHSA-2026:43038",
"https://access.redhat.com/errata/RHSA-2026:43052",
"https://access.redhat.com/errata/RHSA-2026:43692",
"https://access.redhat.com/errata/RHSA-2026:47952",
"https://access.redhat.com/errata/RHSA-2026:49702",
"https://access.redhat.com/errata/RHSA-2026:49712",
"https://access.redhat.com/errata/RHSA-2026:50205",
"https://access.redhat.com/errata/RHSA-2026:50300",
"https://access.redhat.com/errata/RHSA-2026:50843",
"https://access.redhat.com/errata/RHSA-2026:51033",
"https://access.redhat.com/errata/RHSA-2026:51112",
"https://access.redhat.com/errata/RHSA-2026:54274",
"https://access.redhat.com/errata/RHSA-2026:54283",
"https://access.redhat.com/errata/RHSA-2026:54284",
"https://access.redhat.com/errata/RHSA-2026:54285",
"https://access.redhat.com/errata/RHSA-2026:54286",
"https://access.redhat.com/errata/RHSA-2026:54287",
"https://access.redhat.com/errata/RHSA-2026:54531",
"https://access.redhat.com/errata/RHSA-2026:54552",
"https://access.redhat.com/errata/RHSA-2026:54555",
"https://access.redhat.com/errata/RHSA-2026:54583",
"https://access.redhat.com/errata/RHSA-2026:54602",
"https://access.redhat.com/errata/RHSA-2026:54883",
"https://access.redhat.com/errata/RHSA-2026:56340",
"https://access.redhat.com/errata/RHSA-2026:56789",
"https://access.redhat.com/errata/RHSA-2026:56852",
"https://access.redhat.com/errata/RHSA-2026:56854",
"https://access.redhat.com/errata/RHSA-2026:57194",
"https://access.redhat.com/errata/RHSA-2026:57401",
"https://access.redhat.com/errata/RHSA-2026:57482",
"https://access.redhat.com/errata/RHSA-2026:57487",
"https://access.redhat.com/errata/RHSA-2026:57649",
"https://access.redhat.com/errata/RHSA-2026:57845",
"https://access.redhat.com/errata/RHSA-2026:57914",
"https://access.redhat.com/errata/RHSA-2026:59467",
"https://access.redhat.com/errata/RHSA-2026:59830",
"https://access.redhat.com/errata/RHSA-2026:59833",
"https://access.redhat.com/errata/RHSA-2026:60018",
"https://access.redhat.com/errata/RHSA-2026:60023",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:61253",
"https://access.redhat.com/errata/RHSA-2026:62260",
"https://access.redhat.com/errata/RHSA-2026:62406",
"https://access.redhat.com/errata/RHSA-2026:62407",
"https://access.redhat.com/errata/RHSA-2026:62753",
"https://access.redhat.com/errata/RHSA-2026:62754",
"https://access.redhat.com/errata/RHSA-2026:62803",
"https://access.redhat.com/errata/RHSA-2026:63022",
"https://access.redhat.com/errata/RHSA-2026:65116",
"https://access.redhat.com/errata/RHSA-2026:65117",
"https://access.redhat.com/errata/RHSA-2026:65153",
"https://access.redhat.com/errata/RHSA-2026:65335",
"https://access.redhat.com/errata/RHSA-2026:65336",
"https://access.redhat.com/errata/RHSA-2026:65534",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/errata/RHSA-2026:65895",
"https://access.redhat.com/errata/RHSA-2026:66016",
"https://access.redhat.com/errata/RHSA-2026:66022",
"https://access.redhat.com/errata/RHSA-2026:66327",
"https://access.redhat.com/security/cve/CVE-2026-39820",
"https://bugzilla.redhat.com/2467809",
"https://bugzilla.redhat.com/2467820",
"https://bugzilla.redhat.com/2484204",
"https://bugzilla.redhat.com/2484830",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515827",
"https://bugzilla.redhat.com/2515838",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/2515840",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-65117.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/759940",
"https://go.dev/issue/78566",
"https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
"https://linux.oracle.com/cve/CVE-2026-39820.html",
"https://linux.oracle.com/errata/ELSA-2026-65895-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-39820",
"https://pkg.go.dev/vuln/GO-2026-4986",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json",
"https://www.cve.org/CVERecord?id=CVE-2026-39820"
],
"PublishedDate": "2026-05-07T20:16:43.187Z",
"LastModifiedDate": "2026-09-11T13:17:48.093Z"
},
{
"VulnerabilityID": "CVE-2026-39821",
"VendorIDs": [
"GO-2026-5026"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:2be5ddbedd46473bb90605212e4e00a96dce84ee4d0bdf8f0d9667f60eba259e",
"Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing",
"Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
"Severity": "HIGH",
"CweIDs": [
"CWE-1289"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"azure": 4,
"oracle-oval": 3,
"redhat": 3,
"rocky": 3,
"ubuntu": 2
},
"CVSS": {
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
"V3Score": 8.2
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:23262",
"https://access.redhat.com/errata/RHSA-2026:23264",
"https://access.redhat.com/errata/RHSA-2026:26546",
"https://access.redhat.com/errata/RHSA-2026:26547",
"https://access.redhat.com/errata/RHSA-2026:30650",
"https://access.redhat.com/errata/RHSA-2026:30651",
"https://access.redhat.com/errata/RHSA-2026:30853",
"https://access.redhat.com/errata/RHSA-2026:30854",
"https://access.redhat.com/errata/RHSA-2026:30855",
"https://access.redhat.com/errata/RHSA-2026:33155",
"https://access.redhat.com/errata/RHSA-2026:33160",
"https://access.redhat.com/errata/RHSA-2026:33163",
"https://access.redhat.com/errata/RHSA-2026:33173",
"https://access.redhat.com/errata/RHSA-2026:33183",
"https://access.redhat.com/errata/RHSA-2026:33524",
"https://access.redhat.com/errata/RHSA-2026:33531",
"https://access.redhat.com/errata/RHSA-2026:34342",
"https://access.redhat.com/errata/RHSA-2026:34357",
"https://access.redhat.com/errata/RHSA-2026:34359",
"https://access.redhat.com/errata/RHSA-2026:34364",
"https://access.redhat.com/errata/RHSA-2026:34789",
"https://access.redhat.com/errata/RHSA-2026:35826",
"https://access.redhat.com/errata/RHSA-2026:35827",
"https://access.redhat.com/errata/RHSA-2026:35828",
"https://access.redhat.com/errata/RHSA-2026:35829",
"https://access.redhat.com/errata/RHSA-2026:35830",
"https://access.redhat.com/errata/RHSA-2026:35831",
"https://access.redhat.com/errata/RHSA-2026:35993",
"https://access.redhat.com/errata/RHSA-2026:35994",
"https://access.redhat.com/errata/RHSA-2026:36105",
"https://access.redhat.com/errata/RHSA-2026:36167",
"https://access.redhat.com/errata/RHSA-2026:36207",
"https://access.redhat.com/errata/RHSA-2026:36648",
"https://access.redhat.com/errata/RHSA-2026:36651",
"https://access.redhat.com/errata/RHSA-2026:36796",
"https://access.redhat.com/errata/RHSA-2026:36797",
"https://access.redhat.com/errata/RHSA-2026:36808",
"https://access.redhat.com/errata/RHSA-2026:36820",
"https://access.redhat.com/errata/RHSA-2026:36883",
"https://access.redhat.com/errata/RHSA-2026:37387",
"https://access.redhat.com/errata/RHSA-2026:37435",
"https://access.redhat.com/errata/RHSA-2026:37436",
"https://access.redhat.com/errata/RHSA-2026:38995",
"https://access.redhat.com/errata/RHSA-2026:39005",
"https://access.redhat.com/errata/RHSA-2026:39573",
"https://access.redhat.com/errata/RHSA-2026:39879",
"https://access.redhat.com/errata/RHSA-2026:40118",
"https://access.redhat.com/errata/RHSA-2026:40262",
"https://access.redhat.com/errata/RHSA-2026:40945",
"https://access.redhat.com/errata/RHSA-2026:41019",
"https://access.redhat.com/errata/RHSA-2026:41030",
"https://access.redhat.com/errata/RHSA-2026:41031",
"https://access.redhat.com/errata/RHSA-2026:41036",
"https://access.redhat.com/errata/RHSA-2026:41055",
"https://access.redhat.com/errata/RHSA-2026:41066",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:41930",
"https://access.redhat.com/errata/RHSA-2026:42043",
"https://access.redhat.com/errata/RHSA-2026:42047",
"https://access.redhat.com/errata/RHSA-2026:42048",
"https://access.redhat.com/errata/RHSA-2026:42049",
"https://access.redhat.com/errata/RHSA-2026:42050",
"https://access.redhat.com/errata/RHSA-2026:42051",
"https://access.redhat.com/errata/RHSA-2026:42078",
"https://access.redhat.com/errata/RHSA-2026:42079",
"https://access.redhat.com/errata/RHSA-2026:42080",
"https://access.redhat.com/errata/RHSA-2026:42082",
"https://access.redhat.com/errata/RHSA-2026:42132",
"https://access.redhat.com/errata/RHSA-2026:42142",
"https://access.redhat.com/errata/RHSA-2026:42146",
"https://access.redhat.com/errata/RHSA-2026:42150",
"https://access.redhat.com/errata/RHSA-2026:42151",
"https://access.redhat.com/errata/RHSA-2026:42240",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:42796",
"https://access.redhat.com/errata/RHSA-2026:42852",
"https://access.redhat.com/errata/RHSA-2026:43038",
"https://access.redhat.com/errata/RHSA-2026:43052",
"https://access.redhat.com/errata/RHSA-2026:43692",
"https://access.redhat.com/errata/RHSA-2026:44622",
"https://access.redhat.com/errata/RHSA-2026:44624",
"https://access.redhat.com/errata/RHSA-2026:46395",
"https://access.redhat.com/errata/RHSA-2026:47149",
"https://access.redhat.com/errata/RHSA-2026:47735",
"https://access.redhat.com/errata/RHSA-2026:47737",
"https://access.redhat.com/errata/RHSA-2026:47952",
"https://access.redhat.com/errata/RHSA-2026:49702",
"https://access.redhat.com/errata/RHSA-2026:49712",
"https://access.redhat.com/errata/RHSA-2026:50300",
"https://access.redhat.com/errata/RHSA-2026:50843",
"https://access.redhat.com/errata/RHSA-2026:51033",
"https://access.redhat.com/errata/RHSA-2026:51112",
"https://access.redhat.com/errata/RHSA-2026:51187",
"https://access.redhat.com/errata/RHSA-2026:51194",
"https://access.redhat.com/errata/RHSA-2026:51341",
"https://access.redhat.com/errata/RHSA-2026:52826",
"https://access.redhat.com/errata/RHSA-2026:53374",
"https://access.redhat.com/errata/RHSA-2026:53412",
"https://access.redhat.com/errata/RHSA-2026:53413",
"https://access.redhat.com/errata/RHSA-2026:53415",
"https://access.redhat.com/errata/RHSA-2026:53530",
"https://access.redhat.com/errata/RHSA-2026:54191",
"https://access.redhat.com/errata/RHSA-2026:54274",
"https://access.redhat.com/errata/RHSA-2026:54283",
"https://access.redhat.com/errata/RHSA-2026:54284",
"https://access.redhat.com/errata/RHSA-2026:54285",
"https://access.redhat.com/errata/RHSA-2026:54286",
"https://access.redhat.com/errata/RHSA-2026:54287",
"https://access.redhat.com/errata/RHSA-2026:54395",
"https://access.redhat.com/errata/RHSA-2026:54401",
"https://access.redhat.com/errata/RHSA-2026:54435",
"https://access.redhat.com/errata/RHSA-2026:54441",
"https://access.redhat.com/errata/RHSA-2026:54531",
"https://access.redhat.com/errata/RHSA-2026:54580",
"https://access.redhat.com/errata/RHSA-2026:54757",
"https://access.redhat.com/errata/RHSA-2026:56143",
"https://access.redhat.com/errata/RHSA-2026:56223",
"https://access.redhat.com/errata/RHSA-2026:56340",
"https://access.redhat.com/errata/RHSA-2026:56431",
"https://access.redhat.com/errata/RHSA-2026:57194",
"https://access.redhat.com/errata/RHSA-2026:57541",
"https://access.redhat.com/errata/RHSA-2026:57649",
"https://access.redhat.com/errata/RHSA-2026:57845",
"https://access.redhat.com/errata/RHSA-2026:59546",
"https://access.redhat.com/errata/RHSA-2026:59549",
"https://access.redhat.com/errata/RHSA-2026:59562",
"https://access.redhat.com/errata/RHSA-2026:60315",
"https://access.redhat.com/errata/RHSA-2026:60354",
"https://access.redhat.com/errata/RHSA-2026:60387",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:61245",
"https://access.redhat.com/errata/RHSA-2026:61253",
"https://access.redhat.com/errata/RHSA-2026:62549",
"https://access.redhat.com/errata/RHSA-2026:63134",
"https://access.redhat.com/errata/RHSA-2026:65126",
"https://access.redhat.com/errata/RHSA-2026:65153",
"https://access.redhat.com/errata/RHSA-2026:65359",
"https://access.redhat.com/errata/RHSA-2026:65534",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/errata/RHSA-2026:66016",
"https://access.redhat.com/errata/RHSA-2026:66022",
"https://access.redhat.com/errata/RHSA-2026:66432",
"https://access.redhat.com/security/cve/CVE-2026-39821",
"https://bugzilla.redhat.com/2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-37435.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://github.com/golang/go/issues/78760",
"https://go.dev/cl/767220",
"https://go.dev/issue/78760",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8",
"https://linux.oracle.com/cve/CVE-2026-39821.html",
"https://linux.oracle.com/errata/ELSA-2026-65886-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-39821",
"https://pkg.go.dev/vuln/GO-2026-5026",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json",
"https://ubuntu.com/security/notices/USN-8416-1",
"https://www.cve.org/CVERecord?id=CVE-2026-39821"
],
"PublishedDate": "2026-05-22T16:16:20.41Z",
"LastModifiedDate": "2026-09-11T13:17:49.237Z"
},
{
"VulnerabilityID": "CVE-2026-39822",
"VendorIDs": [
"GO-2026-4970"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:096a5fae6ae18cedd89d345f861f0eafa0c46af7a8efc076cf6e3cb941ead50d",
"Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal",
"Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.",
"Severity": "HIGH",
"CweIDs": [
"CWE-61"
],
"VendorSeverity": {
"alma": 3,
"amazon": 2,
"azure": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7.8
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"V3Score": 7.8
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:38878",
"https://access.redhat.com/security/cve/CVE-2026-39822",
"https://bugzilla.redhat.com/2498152",
"https://bugzilla.redhat.com/show_bug.cgi?id=2498152",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822",
"https://errata.almalinux.org/9/ALSA-2026-38878.html",
"https://errata.rockylinux.org/RLSA-2026:38878",
"https://go.dev/cl/797880",
"https://go.dev/issue/79005",
"https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc",
"https://linux.oracle.com/cve/CVE-2026-39822.html",
"https://linux.oracle.com/errata/ELSA-2026-38995.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-39822",
"https://pkg.go.dev/vuln/GO-2026-4970",
"https://www.cve.org/CVERecord?id=CVE-2026-39822"
],
"PublishedDate": "2026-07-08T17:17:21.31Z",
"LastModifiedDate": "2026-07-13T14:54:26.317Z"
},
{
"VulnerabilityID": "CVE-2026-39836",
"VendorIDs": [
"GO-2026-4971"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.10, 1.26.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"SeveritySource": "nvd",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:fcfd0f80d772511c98e49faad20a1959e8fbfb9032322c9708d6028df332b15d",
"Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows",
"Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).",
"Severity": "HIGH",
"CweIDs": [
"CWE-476"
],
"VendorSeverity": {
"bitnami": 3,
"nvd": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 2,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"nvd": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:22121",
"https://access.redhat.com/security/cve/CVE-2026-39836",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467810",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467811",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467813",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467823",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467825",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467826",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467827",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501",
"https://errata.rockylinux.org/RLSA-2026:22121",
"https://go.dev/cl/775320",
"https://go.dev/issue/79006",
"https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
"https://linux.oracle.com/cve/CVE-2026-39836.html",
"https://linux.oracle.com/errata/ELSA-2026-22121.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-39836",
"https://pkg.go.dev/vuln/GO-2026-4971",
"https://www.cve.org/CVERecord?id=CVE-2026-39836"
],
"PublishedDate": "2026-05-07T20:16:43.593Z",
"LastModifiedDate": "2026-06-17T10:42:40.34Z"
},
{
"VulnerabilityID": "CVE-2026-42499",
"VendorIDs": [
"GO-2026-4977"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.10, 1.26.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:3812f89a5d6b0b5adc7ee5bfb034243adb69a3555dbc4af3dc29136f788ab678",
"Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing",
"Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.",
"Severity": "HIGH",
"CweIDs": [
"CWE-1046"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:17713",
"https://access.redhat.com/errata/RHSA-2026:17714",
"https://access.redhat.com/errata/RHSA-2026:22112",
"https://access.redhat.com/errata/RHSA-2026:22120",
"https://access.redhat.com/errata/RHSA-2026:22121",
"https://access.redhat.com/errata/RHSA-2026:33120",
"https://access.redhat.com/errata/RHSA-2026:33123",
"https://access.redhat.com/errata/RHSA-2026:33142",
"https://access.redhat.com/errata/RHSA-2026:33150",
"https://access.redhat.com/errata/RHSA-2026:33574",
"https://access.redhat.com/errata/RHSA-2026:34364",
"https://access.redhat.com/errata/RHSA-2026:36319",
"https://access.redhat.com/errata/RHSA-2026:36625",
"https://access.redhat.com/errata/RHSA-2026:36754",
"https://access.redhat.com/errata/RHSA-2026:36797",
"https://access.redhat.com/errata/RHSA-2026:40262",
"https://access.redhat.com/errata/RHSA-2026:41031",
"https://access.redhat.com/errata/RHSA-2026:41066",
"https://access.redhat.com/errata/RHSA-2026:41928",
"https://access.redhat.com/errata/RHSA-2026:42146",
"https://access.redhat.com/errata/RHSA-2026:42644",
"https://access.redhat.com/errata/RHSA-2026:42796",
"https://access.redhat.com/errata/RHSA-2026:43038",
"https://access.redhat.com/errata/RHSA-2026:43052",
"https://access.redhat.com/errata/RHSA-2026:43692",
"https://access.redhat.com/errata/RHSA-2026:47952",
"https://access.redhat.com/errata/RHSA-2026:49702",
"https://access.redhat.com/errata/RHSA-2026:49712",
"https://access.redhat.com/errata/RHSA-2026:50300",
"https://access.redhat.com/errata/RHSA-2026:50843",
"https://access.redhat.com/errata/RHSA-2026:51033",
"https://access.redhat.com/errata/RHSA-2026:51112",
"https://access.redhat.com/errata/RHSA-2026:54274",
"https://access.redhat.com/errata/RHSA-2026:54283",
"https://access.redhat.com/errata/RHSA-2026:54284",
"https://access.redhat.com/errata/RHSA-2026:54285",
"https://access.redhat.com/errata/RHSA-2026:54286",
"https://access.redhat.com/errata/RHSA-2026:54287",
"https://access.redhat.com/errata/RHSA-2026:54531",
"https://access.redhat.com/errata/RHSA-2026:54552",
"https://access.redhat.com/errata/RHSA-2026:54555",
"https://access.redhat.com/errata/RHSA-2026:54583",
"https://access.redhat.com/errata/RHSA-2026:54602",
"https://access.redhat.com/errata/RHSA-2026:56340",
"https://access.redhat.com/errata/RHSA-2026:56785",
"https://access.redhat.com/errata/RHSA-2026:56789",
"https://access.redhat.com/errata/RHSA-2026:56852",
"https://access.redhat.com/errata/RHSA-2026:56854",
"https://access.redhat.com/errata/RHSA-2026:56910",
"https://access.redhat.com/errata/RHSA-2026:56912",
"https://access.redhat.com/errata/RHSA-2026:57194",
"https://access.redhat.com/errata/RHSA-2026:57482",
"https://access.redhat.com/errata/RHSA-2026:57487",
"https://access.redhat.com/errata/RHSA-2026:57649",
"https://access.redhat.com/errata/RHSA-2026:57845",
"https://access.redhat.com/errata/RHSA-2026:57914",
"https://access.redhat.com/errata/RHSA-2026:59467",
"https://access.redhat.com/errata/RHSA-2026:59830",
"https://access.redhat.com/errata/RHSA-2026:59833",
"https://access.redhat.com/errata/RHSA-2026:60018",
"https://access.redhat.com/errata/RHSA-2026:60023",
"https://access.redhat.com/errata/RHSA-2026:60520",
"https://access.redhat.com/errata/RHSA-2026:61253",
"https://access.redhat.com/errata/RHSA-2026:62260",
"https://access.redhat.com/errata/RHSA-2026:62406",
"https://access.redhat.com/errata/RHSA-2026:62407",
"https://access.redhat.com/errata/RHSA-2026:62753",
"https://access.redhat.com/errata/RHSA-2026:62754",
"https://access.redhat.com/errata/RHSA-2026:62803",
"https://access.redhat.com/errata/RHSA-2026:63022",
"https://access.redhat.com/errata/RHSA-2026:63163",
"https://access.redhat.com/errata/RHSA-2026:63332",
"https://access.redhat.com/errata/RHSA-2026:63636",
"https://access.redhat.com/errata/RHSA-2026:64818",
"https://access.redhat.com/errata/RHSA-2026:65116",
"https://access.redhat.com/errata/RHSA-2026:65117",
"https://access.redhat.com/errata/RHSA-2026:65153",
"https://access.redhat.com/errata/RHSA-2026:65335",
"https://access.redhat.com/errata/RHSA-2026:65336",
"https://access.redhat.com/errata/RHSA-2026:65534",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/errata/RHSA-2026:65895",
"https://access.redhat.com/errata/RHSA-2026:66022",
"https://access.redhat.com/errata/RHSA-2026:66327",
"https://access.redhat.com/security/cve/CVE-2026-42499",
"https://bugzilla.redhat.com/2467809",
"https://bugzilla.redhat.com/2467820",
"https://bugzilla.redhat.com/2484204",
"https://bugzilla.redhat.com/2484830",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515827",
"https://bugzilla.redhat.com/2515838",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/2515840",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-65117.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/771520",
"https://go.dev/issue/78987",
"https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
"https://linux.oracle.com/cve/CVE-2026-42499.html",
"https://linux.oracle.com/errata/ELSA-2026-65895-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-42499",
"https://pkg.go.dev/vuln/GO-2026-4977",
"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json",
"https://www.cve.org/CVERecord?id=CVE-2026-42499"
],
"PublishedDate": "2026-05-07T20:16:44.54Z",
"LastModifiedDate": "2026-09-11T13:17:59.763Z"
},
{
"VulnerabilityID": "CVE-2026-42504",
"VendorIDs": [
"GO-2026-5038"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.11, 1.26.4",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:95e006aded6bebd459634358fd77bd04c5f917ae94d9c7852dfd5b9d9d631771",
"Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header",
"Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.",
"Severity": "HIGH",
"CweIDs": [
"CWE-407"
],
"VendorSeverity": {
"alma": 3,
"amazon": 2,
"azure": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:65117",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/security/cve/CVE-2026-42504",
"https://bugzilla.redhat.com/2467809",
"https://bugzilla.redhat.com/2467820",
"https://bugzilla.redhat.com/2484204",
"https://bugzilla.redhat.com/2484830",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515827",
"https://bugzilla.redhat.com/2515838",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/2515840",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-65117.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/774481",
"https://go.dev/issue/79217",
"https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw",
"https://linux.oracle.com/cve/CVE-2026-42504.html",
"https://linux.oracle.com/errata/ELSA-2026-65895-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-42504",
"https://pkg.go.dev/vuln/GO-2026-5038",
"https://www.cve.org/CVERecord?id=CVE-2026-42504"
],
"PublishedDate": "2026-06-02T23:16:37.927Z",
"LastModifiedDate": "2026-07-22T19:10:00.12Z"
},
{
"VulnerabilityID": "CVE-2026-56853",
"VendorIDs": [
"GO-2026-6089"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:1202c86987b2c2564cd2da971d0ded8ba567117b0ba4c25358e3c9ac0f2c5168",
"Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service",
"Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:65117",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/security/cve/CVE-2026-56853",
"https://bugzilla.redhat.com/2467809",
"https://bugzilla.redhat.com/2467820",
"https://bugzilla.redhat.com/2484204",
"https://bugzilla.redhat.com/2484830",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515827",
"https://bugzilla.redhat.com/2515838",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/2515840",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-65117.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/795540",
"https://go.dev/issue/80205",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://linux.oracle.com/cve/CVE-2026-56853.html",
"https://linux.oracle.com/errata/ELSA-2026-65895-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-56853",
"https://pkg.go.dev/vuln/GO-2026-6089",
"https://www.cve.org/CVERecord?id=CVE-2026-56853"
],
"PublishedDate": "2026-08-13T22:17:22.093Z",
"LastModifiedDate": "2026-09-03T16:37:52.17Z"
},
{
"VulnerabilityID": "CVE-2026-56858",
"VendorIDs": [
"GO-2026-6091"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:bc535ab86cc107c694cd6971a6b23ba96728bd03585a8d23f526abfce22ff433",
"Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input",
"Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
"Severity": "HIGH",
"CweIDs": [
"CWE-79"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 2,
"oracle-oval": 3,
"photon": 2,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"V3Score": 6.1
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"V3Score": 8.1
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:65117",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/security/cve/CVE-2026-56858",
"https://bugzilla.redhat.com/2467809",
"https://bugzilla.redhat.com/2467820",
"https://bugzilla.redhat.com/2484204",
"https://bugzilla.redhat.com/2484830",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515827",
"https://bugzilla.redhat.com/2515838",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/2515840",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-65117.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/807100",
"https://go.dev/issue/80435",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://linux.oracle.com/cve/CVE-2026-56858.html",
"https://linux.oracle.com/errata/ELSA-2026-65895-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-56858",
"https://pkg.go.dev/vuln/GO-2026-6091",
"https://www.cve.org/CVERecord?id=CVE-2026-56858"
],
"PublishedDate": "2026-08-13T22:17:22.207Z",
"LastModifiedDate": "2026-09-03T16:37:52.17Z"
},
{
"VulnerabilityID": "CVE-2026-56859",
"VendorIDs": [
"GO-2026-6088"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:ab62dc3557cb81326d275230a92ad6d0dea55e1c3efa0b4c054834941047dfed",
"Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue",
"Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:65117",
"https://access.redhat.com/errata/RHSA-2026:65886",
"https://access.redhat.com/security/cve/CVE-2026-56859",
"https://bugzilla.redhat.com/2467809",
"https://bugzilla.redhat.com/2467820",
"https://bugzilla.redhat.com/2484204",
"https://bugzilla.redhat.com/2484830",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515827",
"https://bugzilla.redhat.com/2515838",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/2515840",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456333",
"https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
"https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"https://bugzilla.redhat.com/show_bug.cgi?id=2484204",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515827",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515838",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515840",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-65117.html",
"https://errata.rockylinux.org/RLSA-2026:65886",
"https://go.dev/cl/803320",
"https://go.dev/issue/80481",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://linux.oracle.com/cve/CVE-2026-56859.html",
"https://linux.oracle.com/errata/ELSA-2026-65895-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-56859",
"https://pkg.go.dev/vuln/GO-2026-6088",
"https://www.cve.org/CVERecord?id=CVE-2026-56859"
],
"PublishedDate": "2026-08-13T22:17:22.32Z",
"LastModifiedDate": "2026-09-03T16:37:52.17Z"
},
{
"VulnerabilityID": "CVE-2026-56860",
"VendorIDs": [
"GO-2026-6218"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:5d4edc047f09241e4bc2ddff96c80d1d0c26a3143a6496a32bab6d3c0845da66",
"Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution",
"Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
"Severity": "HIGH",
"CweIDs": [
"CWE-407"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 2,
"oracle-oval": 3,
"photon": 2,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 5.9
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:66364",
"https://access.redhat.com/security/cve/CVE-2026-56860",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-66364.html",
"https://errata.rockylinux.org/RLSA-2026:66364",
"https://go.dev/cl/803681",
"https://go.dev/issue/80494",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://linux.oracle.com/cve/CVE-2026-56860.html",
"https://linux.oracle.com/errata/ELSA-2026-66364-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-56860",
"https://pkg.go.dev/vuln/GO-2026-6218",
"https://www.cve.org/CVERecord?id=CVE-2026-56860"
],
"PublishedDate": "2026-08-13T22:17:22.44Z",
"LastModifiedDate": "2026-09-03T16:37:52.17Z"
},
{
"VulnerabilityID": "CVE-2026-56862",
"VendorIDs": [
"GO-2026-6090"
],
"PkgID": "stdlib@v1.24.6",
"PkgName": "stdlib",
"PkgIdentifier": {
"PURL": "pkg:golang/stdlib@v1.24.6",
"UID": "5a9b484fa87e1a00"
},
"InstalledVersion": "v1.24.6",
"FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3",
"Status": "fixed",
"Layer": {
"Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6",
"DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58"
},
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862",
"DataSource": {
"ID": "govulndb",
"Name": "The Go Vulnerability Database",
"URL": "https://pkg.go.dev/vuln/"
},
"Fingerprint": "sha256:0334074ecb18a8ca06b9e645342012eb7692b13a5b9f2e86505ce36d27fb1064",
"Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages",
"Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
"Severity": "HIGH",
"CweIDs": [
"CWE-770"
],
"VendorSeverity": {
"alma": 3,
"amazon": 3,
"bitnami": 3,
"oracle-oval": 3,
"photon": 3,
"redhat": 3,
"rocky": 3
},
"CVSS": {
"bitnami": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
},
"redhat": {
"V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"V3Score": 7.5
}
},
"References": [
"https://access.redhat.com/errata/RHSA-2026:66364",
"https://access.redhat.com/security/cve/CVE-2026-56862",
"https://bugzilla.redhat.com/2515815",
"https://bugzilla.redhat.com/2515820",
"https://bugzilla.redhat.com/2515839",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515815",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515820",
"https://bugzilla.redhat.com/show_bug.cgi?id=2515839",
"https://creativecommons.org/licenses/by/4.0/",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860",
"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862",
"https://errata.almalinux.org/9/ALSA-2026-66364.html",
"https://errata.rockylinux.org/RLSA-2026:66364",
"https://go.dev/cl/804261",
"https://go.dev/issue/80528",
"https://groups.google.com/g/golang-announce/c/94pEornpRlI",
"https://linux.oracle.com/cve/CVE-2026-56862.html",
"https://linux.oracle.com/errata/ELSA-2026-66364-0.html",
"https://nvd.nist.gov/vuln/detail/CVE-2026-56862",
"https://pkg.go.dev/vuln/GO-2026-6090",
"https://www.cve.org/CVERecord?id=CVE-2026-56862"
],
"PublishedDate": "2026-08-13T22:17:22.55Z",
"LastModifiedDate": "2026-09-03T16:37:52.17Z"
}
]
}
]
}