From f15956469a17eb07450be07e63784963fc7d5b21 Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Thu, 10 Sep 2026 21:36:00 +0000 Subject: [PATCH] Matched advisory candidates (shard 2e) Base: 577c983824b680a1491c3f6b64629943617b82e4 --- advisories/BREW-hatch-CVE-2011-4617.json | 16 +-- advisories/BREW-hatch-CVE-2012-4571.json | 10 +- advisories/BREW-hatch-CVE-2012-5577.json | 10 +- advisories/BREW-hatch-CVE-2012-5578.json | 10 +- advisories/BREW-hatch-CVE-2015-8557.json | 16 +-- advisories/BREW-hatch-CVE-2021-20270.json | 16 +-- advisories/BREW-hatch-CVE-2021-27291.json | 16 +-- advisories/BREW-hatch-CVE-2022-40896.json | 16 +-- advisories/BREW-hatch-CVE-2023-26302.json | 10 +- advisories/BREW-hatch-CVE-2023-26303.json | 10 +- advisories/BREW-hatch-CVE-2024-3651.json | 16 +-- advisories/BREW-hatch-CVE-2024-53899.json | 16 +-- advisories/BREW-hatch-CVE-2025-43859.json | 10 +- advisories/BREW-hatch-CVE-2025-68146.json | 16 +-- advisories/BREW-hatch-CVE-2026-22701.json | 16 +-- advisories/BREW-hatch-CVE-2026-22702.json | 16 +-- advisories/BREW-hatch-CVE-2026-23949.json | 10 +- advisories/BREW-hatch-CVE-2026-4539.json | 16 +-- advisories/BREW-hatch-CVE-2026-45409.json | 16 +-- advisories/BREW-hatch-CVE-2026-7246.json | 8 +- advisories/BREW-hatch-CVE-2026-84378.json | 93 ++++++++++++++++++ advisories/BREW-hatch-CVE-2026-84379.json | 89 +++++++++++++++++ advisories/BREW-hatch-CVE-2026-84380.json | 89 +++++++++++++++++ advisories/BREW-hatch-CVE-2026-84381.json | 98 +++++++++++++++++++ advisories/BREW-hatch-CVE-2026-84382.json | 89 +++++++++++++++++ advisories/BREW-iocextract-CVE-2014-1829.json | 10 +- advisories/BREW-iocextract-CVE-2014-1830.json | 10 +- advisories/BREW-iocextract-CVE-2015-2296.json | 10 +- advisories/BREW-iocextract-CVE-2016-9015.json | 10 +- .../BREW-iocextract-CVE-2018-18074.json | 10 +- .../BREW-iocextract-CVE-2018-20060.json | 10 +- .../BREW-iocextract-CVE-2018-25091.json | 10 +- .../BREW-iocextract-CVE-2019-11236.json | 10 +- .../BREW-iocextract-CVE-2019-11324.json | 10 +- .../BREW-iocextract-CVE-2020-26137.json | 10 +- advisories/BREW-iocextract-CVE-2020-7212.json | 10 +- .../BREW-iocextract-CVE-2021-28363.json | 10 +- .../BREW-iocextract-CVE-2021-33503.json | 10 +- .../BREW-iocextract-CVE-2023-32681.json | 10 +- .../BREW-iocextract-CVE-2023-43804.json | 10 +- .../BREW-iocextract-CVE-2023-45803.json | 10 +- .../BREW-iocextract-CVE-2024-35195.json | 10 +- advisories/BREW-iocextract-CVE-2024-3651.json | 10 +- .../BREW-iocextract-CVE-2024-37891.json | 10 +- .../BREW-iocextract-CVE-2024-47081.json | 10 +- .../BREW-iocextract-CVE-2025-50181.json | 10 +- .../BREW-iocextract-CVE-2025-50182.json | 10 +- .../BREW-iocextract-CVE-2025-66418.json | 10 +- .../BREW-iocextract-CVE-2025-66471.json | 10 +- .../BREW-iocextract-CVE-2026-21441.json | 10 +- .../BREW-iocextract-CVE-2026-25645.json | 10 +- .../BREW-iocextract-CVE-2026-44431.json | 10 +- .../BREW-iocextract-CVE-2026-44432.json | 10 +- .../BREW-iocextract-CVE-2026-45409.json | 10 +- advisories/BREW-mkdocs-CVE-2014-0012.json | 10 +- advisories/BREW-mkdocs-CVE-2014-1402.json | 10 +- advisories/BREW-mkdocs-CVE-2016-10745.json | 10 +- advisories/BREW-mkdocs-CVE-2017-18342.json | 10 +- advisories/BREW-mkdocs-CVE-2019-10906.json | 10 +- advisories/BREW-mkdocs-CVE-2019-20477.json | 10 +- advisories/BREW-mkdocs-CVE-2020-14343.json | 10 +- advisories/BREW-mkdocs-CVE-2020-1747.json | 10 +- advisories/BREW-mkdocs-CVE-2020-28493.json | 10 +- advisories/BREW-mkdocs-CVE-2021-40978.json | 9 +- advisories/BREW-mkdocs-CVE-2024-22195.json | 10 +- advisories/BREW-mkdocs-CVE-2024-34064.json | 10 +- advisories/BREW-mkdocs-CVE-2024-56201.json | 10 +- advisories/BREW-mkdocs-CVE-2024-56326.json | 10 +- advisories/BREW-mkdocs-CVE-2025-27516.json | 10 +- advisories/BREW-mkdocs-CVE-2025-69534.json | 10 +- .../BREW-pass-import-CVE-2014-1829.json | 10 +- .../BREW-pass-import-CVE-2014-1830.json | 10 +- .../BREW-pass-import-CVE-2015-2296.json | 10 +- .../BREW-pass-import-CVE-2016-9015.json | 10 +- .../BREW-pass-import-CVE-2017-18342.json | 10 +- .../BREW-pass-import-CVE-2018-18074.json | 10 +- .../BREW-pass-import-CVE-2018-20060.json | 10 +- .../BREW-pass-import-CVE-2018-25091.json | 10 +- .../BREW-pass-import-CVE-2019-11236.json | 10 +- .../BREW-pass-import-CVE-2019-11324.json | 10 +- .../BREW-pass-import-CVE-2019-20477.json | 10 +- .../BREW-pass-import-CVE-2020-14343.json | 10 +- .../BREW-pass-import-CVE-2020-1747.json | 10 +- .../BREW-pass-import-CVE-2020-26137.json | 10 +- .../BREW-pass-import-CVE-2020-7212.json | 10 +- .../BREW-pass-import-CVE-2021-28363.json | 10 +- .../BREW-pass-import-CVE-2021-33503.json | 10 +- .../BREW-pass-import-CVE-2023-32681.json | 10 +- .../BREW-pass-import-CVE-2023-43804.json | 10 +- .../BREW-pass-import-CVE-2023-45803.json | 10 +- .../BREW-pass-import-CVE-2024-35195.json | 10 +- .../BREW-pass-import-CVE-2024-3651.json | 10 +- .../BREW-pass-import-CVE-2024-37891.json | 10 +- .../BREW-pass-import-CVE-2024-47081.json | 10 +- .../BREW-pass-import-CVE-2025-50181.json | 10 +- .../BREW-pass-import-CVE-2025-50182.json | 10 +- .../BREW-pass-import-CVE-2025-66418.json | 10 +- .../BREW-pass-import-CVE-2025-66471.json | 10 +- .../BREW-pass-import-CVE-2026-21441.json | 10 +- .../BREW-pass-import-CVE-2026-25645.json | 10 +- .../BREW-pass-import-CVE-2026-44431.json | 10 +- .../BREW-pass-import-CVE-2026-44432.json | 10 +- .../BREW-pass-import-CVE-2026-45409.json | 10 +- 103 files changed, 595 insertions(+), 912 deletions(-) create mode 100644 advisories/BREW-hatch-CVE-2026-84378.json create mode 100644 advisories/BREW-hatch-CVE-2026-84379.json create mode 100644 advisories/BREW-hatch-CVE-2026-84380.json create mode 100644 advisories/BREW-hatch-CVE-2026-84381.json create mode 100644 advisories/BREW-hatch-CVE-2026-84382.json diff --git a/advisories/BREW-hatch-CVE-2011-4617.json b/advisories/BREW-hatch-CVE-2011-4617.json index e2a01aef450..23e1f9b1baf 100644 --- a/advisories/BREW-hatch-CVE-2011-4617.json +++ b/advisories/BREW-hatch-CVE-2011-4617.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2011-4617", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-3jhc-wjqf-5f2c", "CVE-2011-4617", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5", "resource": "virtualenv", - "resource_purl": "pkg:pypi/virtualenv@21.7.4" + "resource_purl": "pkg:pypi/virtualenv@21.7.8" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.4", - "key": "pkg:pypi/virtualenv@21.7.4", - "resource": "virtualenv" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "21.7.4", - "key": "pkg:pypi/virtualenv@21.7.4", + "subject_version": "21.7.8", + "key": "pkg:pypi/virtualenv@21.7.8", "resource": "virtualenv" } ] diff --git a/advisories/BREW-hatch-CVE-2012-4571.json b/advisories/BREW-hatch-CVE-2012-4571.json index 3cfca310870..3f706584dd3 100644 --- a/advisories/BREW-hatch-CVE-2012-4571.json +++ b/advisories/BREW-hatch-CVE-2012-4571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2012-4571", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-p3h7-3c45-qj4v", "CVE-2012-4571", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2012-5577.json b/advisories/BREW-hatch-CVE-2012-5577.json index b4197996851..8a791a5b727 100644 --- a/advisories/BREW-hatch-CVE-2012-5577.json +++ b/advisories/BREW-hatch-CVE-2012-5577.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2012-5577", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-p86x-652p-6385", "CVE-2012-5577", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2012-5578.json b/advisories/BREW-hatch-CVE-2012-5578.json index 0ea41a924a3..599a1b057e1 100644 --- a/advisories/BREW-hatch-CVE-2012-5578.json +++ b/advisories/BREW-hatch-CVE-2012-5578.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2012-5578", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-8867-vpm3-g98g", "CVE-2012-5578", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "keyring", - "subject_version": "25.7.0", - "key": "pkg:pypi/keyring@25.7.0", - "resource": "keyring" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2015-8557.json b/advisories/BREW-hatch-CVE-2015-8557.json index e7e209ea3e1..fbef4457fe1 100644 --- a/advisories/BREW-hatch-CVE-2015-8557.json +++ b/advisories/BREW-hatch-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2015-8557", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hatch-CVE-2021-20270.json b/advisories/BREW-hatch-CVE-2021-20270.json index 502f6e3bf54..6076b54544b 100644 --- a/advisories/BREW-hatch-CVE-2021-20270.json +++ b/advisories/BREW-hatch-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2021-20270", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hatch-CVE-2021-27291.json b/advisories/BREW-hatch-CVE-2021-27291.json index e3aa6974b60..1084f0d2798 100644 --- a/advisories/BREW-hatch-CVE-2021-27291.json +++ b/advisories/BREW-hatch-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2021-27291", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hatch-CVE-2022-40896.json b/advisories/BREW-hatch-CVE-2022-40896.json index 5d7114d20af..ab36ed3af6b 100644 --- a/advisories/BREW-hatch-CVE-2022-40896.json +++ b/advisories/BREW-hatch-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2022-40896", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hatch-CVE-2023-26302.json b/advisories/BREW-hatch-CVE-2023-26302.json index 9c9ba5f17c6..0666c57b827 100644 --- a/advisories/BREW-hatch-CVE-2023-26302.json +++ b/advisories/BREW-hatch-CVE-2023-26302.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2023-26302", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-jrwr-5x3p-hvc3", "CVE-2023-26302", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2023-26303.json b/advisories/BREW-hatch-CVE-2023-26303.json index a16e0436447..772adeb883e 100644 --- a/advisories/BREW-hatch-CVE-2023-26303.json +++ b/advisories/BREW-hatch-CVE-2023-26303.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2023-26303", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-vrjv-mxr7-vjf8", "CVE-2023-26303", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown-it-py", - "subject_version": "4.2.0", - "key": "pkg:pypi/markdown-it-py@4.2.0", - "resource": "markdown-it-py" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2024-3651.json b/advisories/BREW-hatch-CVE-2024-3651.json index 1731da81856..64cf5a040f2 100644 --- a/advisories/BREW-hatch-CVE-2024-3651.json +++ b/advisories/BREW-hatch-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2024-3651", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.7", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-hatch-CVE-2024-53899.json b/advisories/BREW-hatch-CVE-2024-53899.json index 1771c415c22..2fac9349518 100644 --- a/advisories/BREW-hatch-CVE-2024-53899.json +++ b/advisories/BREW-hatch-CVE-2024-53899.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2024-53899", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-rqc4-2hc7-8c8v", "BIT-virtualenv-2024-53899", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "20.26.6", "resource": "virtualenv", - "resource_purl": "pkg:pypi/virtualenv@21.7.4" + "resource_purl": "pkg:pypi/virtualenv@21.7.8" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.4", - "key": "pkg:pypi/virtualenv@21.7.4", - "resource": "virtualenv" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "21.7.4", - "key": "pkg:pypi/virtualenv@21.7.4", + "subject_version": "21.7.8", + "key": "pkg:pypi/virtualenv@21.7.8", "resource": "virtualenv" } ] diff --git a/advisories/BREW-hatch-CVE-2025-43859.json b/advisories/BREW-hatch-CVE-2025-43859.json index c9e9e832669..c72b4836423 100644 --- a/advisories/BREW-hatch-CVE-2025-43859.json +++ b/advisories/BREW-hatch-CVE-2025-43859.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2025-43859", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:25:29Z", "upstream": [ "GHSA-vqfr-h8mv-ghfj", "CVE-2025-43859", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "h11", - "subject_version": "0.16.0", - "key": "pkg:pypi/h11@0.16.0", - "resource": "h11" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2025-68146.json b/advisories/BREW-hatch-CVE-2025-68146.json index d2a05cc9efb..91ad16018f5 100644 --- a/advisories/BREW-hatch-CVE-2025-68146.json +++ b/advisories/BREW-hatch-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2025-68146", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:25:29Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.2" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-hatch-CVE-2026-22701.json b/advisories/BREW-hatch-CVE-2026-22701.json index 3cfd9ba48d5..c94b345ccab 100644 --- a/advisories/BREW-hatch-CVE-2026-22701.json +++ b/advisories/BREW-hatch-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2026-22701", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:25:29Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.2" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", - "resource": "filelock" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "filelock", - "subject_version": "3.32.2", - "key": "pkg:pypi/filelock@3.32.2", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-hatch-CVE-2026-22702.json b/advisories/BREW-hatch-CVE-2026-22702.json index dbb54f33d32..1f23c6e4e83 100644 --- a/advisories/BREW-hatch-CVE-2026-22702.json +++ b/advisories/BREW-hatch-CVE-2026-22702.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2026-22702", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-597g-3phw-6986", "BIT-virtualenv-2026-22702", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "20.36.1", "resource": "virtualenv", - "resource_purl": "pkg:pypi/virtualenv@21.7.4" + "resource_purl": "pkg:pypi/virtualenv@21.7.8" } } ], @@ -47,16 +47,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "virtualenv", - "subject_version": "21.7.4", - "key": "pkg:pypi/virtualenv@21.7.4", - "resource": "virtualenv" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "virtualenv", - "subject_version": "21.7.4", - "key": "pkg:pypi/virtualenv@21.7.4", + "subject_version": "21.7.8", + "key": "pkg:pypi/virtualenv@21.7.8", "resource": "virtualenv" } ] diff --git a/advisories/BREW-hatch-CVE-2026-23949.json b/advisories/BREW-hatch-CVE-2026-23949.json index b0cce2061b3..758791fa67e 100644 --- a/advisories/BREW-hatch-CVE-2026-23949.json +++ b/advisories/BREW-hatch-CVE-2026-23949.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2026-23949", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-58pv-8j8x-9vj2", "CVE-2026-23949", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jaraco-context", - "subject_version": "6.1.2", - "key": "pkg:pypi/jaraco-context@6.1.2", - "resource": "jaraco-context" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-hatch-CVE-2026-4539.json b/advisories/BREW-hatch-CVE-2026-4539.json index 2bbec73e6d7..5ece6c23c05 100644 --- a/advisories/BREW-hatch-CVE-2026-4539.json +++ b/advisories/BREW-hatch-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2026-4539", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", - "resource": "pygments" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-hatch-CVE-2026-45409.json b/advisories/BREW-hatch-CVE-2026-45409.json index 64b66a692d8..64216470340 100644 --- a/advisories/BREW-hatch-CVE-2026-45409.json +++ b/advisories/BREW-hatch-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2026-45409", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:26:02Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15", "resource": "idna", - "resource_purl": "pkg:pypi/idna@3.18" + "resource_purl": "pkg:pypi/idna@3.19" } } ], @@ -46,16 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", - "resource": "idna" - }, - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.18", - "key": "pkg:pypi/idna@3.18", + "subject_version": "3.19", + "key": "pkg:pypi/idna@3.19", "resource": "idna" } ] diff --git a/advisories/BREW-hatch-CVE-2026-7246.json b/advisories/BREW-hatch-CVE-2026-7246.json index 3ad3922fe74..88deb0b9a4b 100644 --- a/advisories/BREW-hatch-CVE-2026-7246.json +++ b/advisories/BREW-hatch-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-hatch-CVE-2026-7246", "published": "2026-08-13T16:56:21Z", - "modified": "2026-08-13T16:56:21Z", + "modified": "2026-09-10T19:25:29Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-hatch-CVE-2026-84378.json b/advisories/BREW-hatch-CVE-2026-84378.json new file mode 100644 index 00000000000..38ee38bed56 --- /dev/null +++ b/advisories/BREW-hatch-CVE-2026-84378.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-hatch-CVE-2026-84378", + "published": "2026-09-10T19:26:02Z", + "modified": "2026-09-10T19:26:02Z", + "upstream": [ + "GHSA-f2fp-rgf2-35cp", + "CVE-2026-84378", + "PYSEC-2026-3847" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "hatch", + "purl": "pkg:brew/hatch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.17.1" + }, + { + "fixed": "1.18.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service", + "details": "### Summary\n\nHTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit this behavior to consume excessive client CPU.\n\n### Details\n\nBefore version 2.10.0, HTTPX2 combined the complete pending SSE line with each newly received chunk and then scanned the combined text for line separators. If an SSE server sends a long line as many small chunks without a line separator, every chunk causes all previously received text to be copied and scanned again. For `n` fixed-size chunks, this results in O(n²) processing.\n\nThe behavior affects both `httpx2.Client.sse()` and `httpx2.AsyncClient.sse()`. Other response APIs do not use the SSE parsing path.\n\n### Impact\n\nApplications that consume SSE from an attacker-controlled or compromised endpoint can experience excessive CPU usage. A crafted stream can block a synchronous worker or the asynchronous event loop that is consuming it, degrading availability for other work in that process. Confidentiality and integrity are not affected.\n\n### Mitigation\n\nUpgrade to HTTPX2 2.10.0 or later. SSE parsing now accumulates incomplete line fragments and combines them only when necessary, making processing linear in the amount of received data. HTTPX2 2.10.0 also limits buffered SSE events to 1 MiB by default through `max_event_size`.\n\nIf upgrading is not immediately possible, only consume SSE from trusted endpoints and enforce an external size or time budget on the stream.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-f2fp-rgf2-35cp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84378" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1071" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1117" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-hatch-CVE-2026-84379.json b/advisories/BREW-hatch-CVE-2026-84379.json new file mode 100644 index 00000000000..aba1ae9502d --- /dev/null +++ b/advisories/BREW-hatch-CVE-2026-84379.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-hatch-CVE-2026-84379", + "published": "2026-09-10T19:26:02Z", + "modified": "2026-09-10T19:26:02Z", + "upstream": [ + "GHSA-h4x7-gw46-3wm6", + "CVE-2026-84379", + "PYSEC-2026-3848" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "hatch", + "purl": "pkg:brew/hatch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.17.0" + }, + { + "fixed": "1.18.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers", + "details": "### Summary\n\nHTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF characters to terminate a multipart part header and inject additional part headers or end the part header block early.\n\n### Details\n\nThe three-element file tuple accepts `(filename, content, content_type)`, and the four-element form accepts `(filename, content, content_type, headers)`. `FileField.render_headers()` interpolates the supplied header names and values between CRLF delimiters without validating them.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"https://example.com/upload\",\n headers={\"Content-Type\": \"multipart/form-data; boundary=BOUNDARY\"},\n files={\n \"file\": (\n \"safe.txt\",\n b\"payload\",\n \"text/plain\\r\\nX-Injected: true\",\n )\n },\n)\n\nprint(request.read().decode())\n```\n\nThe generated body contains an attacker-injected part header:\n\n```text\n--BOUNDARY\nContent-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"\nContent-Type: text/plain\nX-Injected: true\n\npayload\n--BOUNDARY--\n```\n\nThe same issue affects names and values in the custom header mapping from the four-element tuple.\n\nField names and filenames are serialized through a separate escaping path and do not permit CRLF header injection.\n\n### Impact\n\nApplications are affected when they pass attacker-controlled upload metadata into the per-file `content_type` or custom `headers` arguments. The receiving server interprets injected lines as genuine multipart part headers. Depending on how that server validates and processes uploads, this can alter part semantics or bypass checks based on part headers.\n\nThis does not split the outer HTTP request: the injected headers are contained within the multipart body. The concrete security impact therefore depends on the downstream multipart parser and application behavior.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions reject forbidden control characters in multipart part header names and values and raise `ValueError` before serializing the request.\n\nIf upgrading is not immediately possible, applications should validate custom multipart header names as HTTP field-name tokens. They should reject NUL, CR, LF, other C0 controls except horizontal tab, and DEL in per-file content types and custom header values before passing them to HTTPX2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-h4x7-gw46-3wm6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84379" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1142" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-hatch-CVE-2026-84380.json b/advisories/BREW-hatch-CVE-2026-84380.json new file mode 100644 index 00000000000..a8465368212 --- /dev/null +++ b/advisories/BREW-hatch-CVE-2026-84380.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-hatch-CVE-2026-84380", + "published": "2026-09-10T19:26:02Z", + "modified": "2026-09-10T19:26:02Z", + "upstream": [ + "GHSA-pf96-p4fj-6566", + "CVE-2026-84380", + "PYSEC-2026-3849" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "hatch", + "purl": "pkg:brew/hatch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.17.0" + }, + { + "fixed": "1.18.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.11.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated", + "details": "### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n \"POST\",\n \"http://example.com/\",\n headers={\"Transfer-Encoding\": \"chunked\"},\n content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84380" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1137" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.11.0" + } + ] +} diff --git a/advisories/BREW-hatch-CVE-2026-84381.json b/advisories/BREW-hatch-CVE-2026-84381.json new file mode 100644 index 00000000000..2119137ac26 --- /dev/null +++ b/advisories/BREW-hatch-CVE-2026-84381.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-hatch-CVE-2026-84381", + "published": "2026-09-10T19:26:01Z", + "modified": "2026-09-10T19:26:01Z", + "upstream": [ + "GHSA-7mj9-2mp8-4m2p", + "CVE-2026-84381", + "PYSEC-2026-3844", + "PYSEC-2026-3845" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "hatch", + "purl": "pkg:brew/hatch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.17.0" + }, + { + "fixed": "1.18.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.10.0", + "resource": "httpcore2", + "resource_purl": "pkg:pypi/httpcore2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpcore2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpcore2@2.12.0", + "resource": "httpcore2" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies", + "details": "### Summary\n\nhttpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.\n\nThe transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.\n\n### Details\n\nThe synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.\n\nFor example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:\n\n```python\nimport httpx2\n\nwith httpx2.Client(proxy=\"socks5://proxy.example:1080\") as client:\n with client.websocket(\n \"wss://service.example/private?token=query-secret\",\n headers={\"Authorization\": \"Bearer header-secret\"},\n cookies={\"session\": \"cookie-secret\"},\n ) as websocket:\n websocket.send_text(\"private message\")\n```\n\nOn affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:\n\n```text\nGET /private?token=query-secret HTTP/1.1\nHost: service.example\nAuthorization: Bearer header-secret\nCookie: session=cookie-secret\n```\n\nBefore HTTPX2 `2.6.0`, the same underlying httpcore2 behavior could be reached by integrations constructing a WebSocket upgrade request through the low-level transport API, but HTTPX2 did not yet provide its native WebSocket client API.\n\nA normal secure WebSocket server will usually reject these plaintext bytes because it expects a TLS ClientHello. However, a malicious or compromised SOCKS proxy can accept the SOCKS connection, observe the plaintext handshake, return a forged `101 Switching Protocols` response, and then read or modify WebSocket frames in both directions. An observer between the proxy and destination may also read the plaintext traffic.\n\nRFC 6455 requires a client using a secure WebSocket connection to perform the TLS handshake before sending the WebSocket opening handshake. A `wss` URI promises confidentiality, integrity, and endpoint authentication through TLS.\n\n### Impact\n\nAn attacker able to control or observe the SOCKS proxy path can obtain URL query parameters, authorization headers, cookies, and application messages that the caller expected TLS to protect. Because no TLS handshake occurs, certificate verification also does not occur, allowing an attacker controlling the proxy to impersonate the WebSocket server and inject or alter messages.\n\nOnly `wss://` connections routed through a SOCKS5 proxy are affected. Direct `wss://` connections and ordinary `https://` requests through SOCKS already start TLS correctly.\n\n### Mitigation\n\nUpgrade HTTPX2 and httpcore2 to `2.10.0` or later. Patched versions start TLS for both `https` and `wss` origins in the synchronous and asynchronous SOCKS5 connection paths.\n\nIf upgrading is not immediately possible, do not route `wss://` connections through a SOCKS proxy. Use a direct secure WebSocket connection or another transport that performs and verifies TLS to the WebSocket origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-7mj9-2mp8-4m2p" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84381" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1104" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/fb008dd700b761d955210d9692475c3e2f379453" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.10.0" + } + ] +} diff --git a/advisories/BREW-hatch-CVE-2026-84382.json b/advisories/BREW-hatch-CVE-2026-84382.json new file mode 100644 index 00000000000..64017ef8fae --- /dev/null +++ b/advisories/BREW-hatch-CVE-2026-84382.json @@ -0,0 +1,89 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-hatch-CVE-2026-84382", + "published": "2026-09-10T19:26:01Z", + "modified": "2026-09-10T19:26:01Z", + "upstream": [ + "GHSA-8xx6-hgc6-gc2m", + "CVE-2026-84382", + "PYSEC-2026-3846" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "hatch", + "purl": "pkg:brew/hatch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.17.0" + }, + { + "fixed": "1.18.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "2.12.0", + "resource": "httpx2", + "resource_purl": "pkg:pypi/httpx2@2.12.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "httpx2", + "subject_version": "2.12.0", + "key": "pkg:pypi/httpx2@2.12.0", + "resource": "httpx2" + } + ] + }, + "summary": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)", + "details": "### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84382" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/pull/1126" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pydantic/httpx2" + }, + { + "type": "WEB", + "url": "https://github.com/pydantic/httpx2/releases/tag/v2.12.0" + } + ] +} diff --git a/advisories/BREW-iocextract-CVE-2014-1829.json b/advisories/BREW-iocextract-CVE-2014-1829.json index da4a00c1a15..2fb89d598e2 100644 --- a/advisories/BREW-iocextract-CVE-2014-1829.json +++ b/advisories/BREW-iocextract-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2014-1829", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2014-1830.json b/advisories/BREW-iocextract-CVE-2014-1830.json index 8d588781fb2..605319fb01b 100644 --- a/advisories/BREW-iocextract-CVE-2014-1830.json +++ b/advisories/BREW-iocextract-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2014-1830", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2015-2296.json b/advisories/BREW-iocextract-CVE-2015-2296.json index e8df7a7eac4..f2b85a57f9e 100644 --- a/advisories/BREW-iocextract-CVE-2015-2296.json +++ b/advisories/BREW-iocextract-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2015-2296", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2016-9015.json b/advisories/BREW-iocextract-CVE-2016-9015.json index 5470567d8c9..efecc261786 100644 --- a/advisories/BREW-iocextract-CVE-2016-9015.json +++ b/advisories/BREW-iocextract-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2016-9015", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2018-18074.json b/advisories/BREW-iocextract-CVE-2018-18074.json index 05e1b43d8d1..9a332551156 100644 --- a/advisories/BREW-iocextract-CVE-2018-18074.json +++ b/advisories/BREW-iocextract-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2018-18074", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2018-20060.json b/advisories/BREW-iocextract-CVE-2018-20060.json index 618eb49707f..4a1fd6e6562 100644 --- a/advisories/BREW-iocextract-CVE-2018-20060.json +++ b/advisories/BREW-iocextract-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2018-20060", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2018-25091.json b/advisories/BREW-iocextract-CVE-2018-25091.json index cc9d57714a8..36af5d158ac 100644 --- a/advisories/BREW-iocextract-CVE-2018-25091.json +++ b/advisories/BREW-iocextract-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2018-25091", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2019-11236.json b/advisories/BREW-iocextract-CVE-2019-11236.json index 0eacb314b66..67834d2b602 100644 --- a/advisories/BREW-iocextract-CVE-2019-11236.json +++ b/advisories/BREW-iocextract-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2019-11236", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2019-11324.json b/advisories/BREW-iocextract-CVE-2019-11324.json index d1dea4445ed..8d26797b094 100644 --- a/advisories/BREW-iocextract-CVE-2019-11324.json +++ b/advisories/BREW-iocextract-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2019-11324", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2020-26137.json b/advisories/BREW-iocextract-CVE-2020-26137.json index 3e99d2d013e..0904862a98b 100644 --- a/advisories/BREW-iocextract-CVE-2020-26137.json +++ b/advisories/BREW-iocextract-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2020-26137", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2020-7212.json b/advisories/BREW-iocextract-CVE-2020-7212.json index 335ec89d42d..d708a0a2902 100644 --- a/advisories/BREW-iocextract-CVE-2020-7212.json +++ b/advisories/BREW-iocextract-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2020-7212", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2021-28363.json b/advisories/BREW-iocextract-CVE-2021-28363.json index 6296f21533d..1845f623ac1 100644 --- a/advisories/BREW-iocextract-CVE-2021-28363.json +++ b/advisories/BREW-iocextract-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2021-28363", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2021-33503.json b/advisories/BREW-iocextract-CVE-2021-33503.json index 1d209bfc697..00a94eca6a1 100644 --- a/advisories/BREW-iocextract-CVE-2021-33503.json +++ b/advisories/BREW-iocextract-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2021-33503", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2023-32681.json b/advisories/BREW-iocextract-CVE-2023-32681.json index efb3fc82f96..5b0472f1a57 100644 --- a/advisories/BREW-iocextract-CVE-2023-32681.json +++ b/advisories/BREW-iocextract-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2023-32681", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2023-43804.json b/advisories/BREW-iocextract-CVE-2023-43804.json index 7f3601dd4ac..14c423fb770 100644 --- a/advisories/BREW-iocextract-CVE-2023-43804.json +++ b/advisories/BREW-iocextract-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2023-43804", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2023-45803.json b/advisories/BREW-iocextract-CVE-2023-45803.json index 5c5cc681064..3965f74653e 100644 --- a/advisories/BREW-iocextract-CVE-2023-45803.json +++ b/advisories/BREW-iocextract-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2023-45803", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2024-35195.json b/advisories/BREW-iocextract-CVE-2024-35195.json index e0dbd153f0b..76d866323fc 100644 --- a/advisories/BREW-iocextract-CVE-2024-35195.json +++ b/advisories/BREW-iocextract-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2024-35195", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2024-3651.json b/advisories/BREW-iocextract-CVE-2024-3651.json index 30f2307fef9..65deb48553e 100644 --- a/advisories/BREW-iocextract-CVE-2024-3651.json +++ b/advisories/BREW-iocextract-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2024-3651", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.15", - "key": "pkg:pypi/idna@3.15", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2024-37891.json b/advisories/BREW-iocextract-CVE-2024-37891.json index 4bddb5c6a5f..0629a074644 100644 --- a/advisories/BREW-iocextract-CVE-2024-37891.json +++ b/advisories/BREW-iocextract-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2024-37891", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2024-47081.json b/advisories/BREW-iocextract-CVE-2024-47081.json index 71afbd7d9f0..32de730a491 100644 --- a/advisories/BREW-iocextract-CVE-2024-47081.json +++ b/advisories/BREW-iocextract-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2024-47081", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2025-50181.json b/advisories/BREW-iocextract-CVE-2025-50181.json index 0583e83c32b..858021e1671 100644 --- a/advisories/BREW-iocextract-CVE-2025-50181.json +++ b/advisories/BREW-iocextract-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2025-50181", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2025-50182.json b/advisories/BREW-iocextract-CVE-2025-50182.json index 4cc4c6d1583..beb3402537b 100644 --- a/advisories/BREW-iocextract-CVE-2025-50182.json +++ b/advisories/BREW-iocextract-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2025-50182", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2025-66418.json b/advisories/BREW-iocextract-CVE-2025-66418.json index 80e4dbe07d2..413eed99001 100644 --- a/advisories/BREW-iocextract-CVE-2025-66418.json +++ b/advisories/BREW-iocextract-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2025-66418", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2025-66471.json b/advisories/BREW-iocextract-CVE-2025-66471.json index 6394cad8004..d08a49cce88 100644 --- a/advisories/BREW-iocextract-CVE-2025-66471.json +++ b/advisories/BREW-iocextract-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2025-66471", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2026-21441.json b/advisories/BREW-iocextract-CVE-2026-21441.json index 8cb7c12c150..5fcf12c5749 100644 --- a/advisories/BREW-iocextract-CVE-2026-21441.json +++ b/advisories/BREW-iocextract-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2026-21441", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2026-25645.json b/advisories/BREW-iocextract-CVE-2026-25645.json index e67147668c1..69bb167af9f 100644 --- a/advisories/BREW-iocextract-CVE-2026-25645.json +++ b/advisories/BREW-iocextract-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2026-25645", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.2", - "key": "pkg:pypi/requests@2.34.2", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2026-44431.json b/advisories/BREW-iocextract-CVE-2026-44431.json index f000e0fb3ba..11fe642e6a2 100644 --- a/advisories/BREW-iocextract-CVE-2026-44431.json +++ b/advisories/BREW-iocextract-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2026-44431", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2026-44432.json b/advisories/BREW-iocextract-CVE-2026-44432.json index 3dd5826f3f7..be80296fd26 100644 --- a/advisories/BREW-iocextract-CVE-2026-44432.json +++ b/advisories/BREW-iocextract-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2026-44432", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-iocextract-CVE-2026-45409.json b/advisories/BREW-iocextract-CVE-2026-45409.json index 5240ce902ae..691788b05ae 100644 --- a/advisories/BREW-iocextract-CVE-2026-45409.json +++ b/advisories/BREW-iocextract-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-iocextract-CVE-2026-45409", "published": "2026-08-13T16:59:59Z", - "modified": "2026-08-13T16:59:59Z", + "modified": "2026-09-10T19:32:16Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.15", - "key": "pkg:pypi/idna@3.15", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2014-0012.json b/advisories/BREW-mkdocs-CVE-2014-0012.json index 68271c51809..5e826ad910d 100644 --- a/advisories/BREW-mkdocs-CVE-2014-0012.json +++ b/advisories/BREW-mkdocs-CVE-2014-0012.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2014-0012", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-fqh9-2qgg-h84h", "CVE-2014-0012", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2014-1402.json b/advisories/BREW-mkdocs-CVE-2014-1402.json index 13925a085f1..71a09c75988 100644 --- a/advisories/BREW-mkdocs-CVE-2014-1402.json +++ b/advisories/BREW-mkdocs-CVE-2014-1402.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2014-1402", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-8r7q-cvjq-x353", "CVE-2014-1402", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2016-10745.json b/advisories/BREW-mkdocs-CVE-2016-10745.json index ffa550c840c..3318a4bb091 100644 --- a/advisories/BREW-mkdocs-CVE-2016-10745.json +++ b/advisories/BREW-mkdocs-CVE-2016-10745.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2016-10745", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-hj2j-77xm-mc5v", "CVE-2016-10745", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2017-18342.json b/advisories/BREW-mkdocs-CVE-2017-18342.json index 3dd2e372750..b147817ba5f 100644 --- a/advisories/BREW-mkdocs-CVE-2017-18342.json +++ b/advisories/BREW-mkdocs-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2017-18342", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2019-10906.json b/advisories/BREW-mkdocs-CVE-2019-10906.json index 31894c30b39..8a0169c7316 100644 --- a/advisories/BREW-mkdocs-CVE-2019-10906.json +++ b/advisories/BREW-mkdocs-CVE-2019-10906.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2019-10906", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:00Z", "upstream": [ "GHSA-462w-v97r-4m45", "CVE-2019-10906", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2019-20477.json b/advisories/BREW-mkdocs-CVE-2019-20477.json index 6a0f6d1fd87..0d4257555b0 100644 --- a/advisories/BREW-mkdocs-CVE-2019-20477.json +++ b/advisories/BREW-mkdocs-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2019-20477", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2020-14343.json b/advisories/BREW-mkdocs-CVE-2020-14343.json index 0e15173a289..d8a338c7932 100644 --- a/advisories/BREW-mkdocs-CVE-2020-14343.json +++ b/advisories/BREW-mkdocs-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2020-14343", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2020-1747.json b/advisories/BREW-mkdocs-CVE-2020-1747.json index 75160c3d496..e27d7685117 100644 --- a/advisories/BREW-mkdocs-CVE-2020-1747.json +++ b/advisories/BREW-mkdocs-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2020-1747", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2020-28493.json b/advisories/BREW-mkdocs-CVE-2020-28493.json index 6343689d73c..b3f130c052f 100644 --- a/advisories/BREW-mkdocs-CVE-2020-28493.json +++ b/advisories/BREW-mkdocs-CVE-2020-28493.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2020-28493", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-g3rq-g295-4j3m", "CVE-2020-28493", @@ -43,14 +43,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2021-40978.json b/advisories/BREW-mkdocs-CVE-2021-40978.json index 9127446fe9e..112f5619597 100644 --- a/advisories/BREW-mkdocs-CVE-2021-40978.json +++ b/advisories/BREW-mkdocs-CVE-2021-40978.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2021-40978", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:00Z", "upstream": [ "GHSA-qh9q-34h6-hcv9", "CVE-2021-40978", @@ -40,13 +40,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "mkdocs", - "subject_version": "1.6.1", - "key": "pkg:pypi/mkdocs@1.6.1" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2024-22195.json b/advisories/BREW-mkdocs-CVE-2024-22195.json index 5d77d4521bb..83c731e3d54 100644 --- a/advisories/BREW-mkdocs-CVE-2024-22195.json +++ b/advisories/BREW-mkdocs-CVE-2024-22195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2024-22195", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-h5c8-rqwp-cp95", "CVE-2024-22195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2024-34064.json b/advisories/BREW-mkdocs-CVE-2024-34064.json index 801aabe6550..53adc049257 100644 --- a/advisories/BREW-mkdocs-CVE-2024-34064.json +++ b/advisories/BREW-mkdocs-CVE-2024-34064.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2024-34064", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-h75v-3vvj-5mfj", "CVE-2024-34064", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2024-56201.json b/advisories/BREW-mkdocs-CVE-2024-56201.json index fa99ef90428..2b0540642fb 100644 --- a/advisories/BREW-mkdocs-CVE-2024-56201.json +++ b/advisories/BREW-mkdocs-CVE-2024-56201.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2024-56201", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-gmj6-6f8f-6699", "CVE-2024-56201", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2024-56326.json b/advisories/BREW-mkdocs-CVE-2024-56326.json index e4c3e7c3a8d..4714ef1cd05 100644 --- a/advisories/BREW-mkdocs-CVE-2024-56326.json +++ b/advisories/BREW-mkdocs-CVE-2024-56326.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2024-56326", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-q2x7-8rv6-6q7h", "CVE-2024-56326", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2025-27516.json b/advisories/BREW-mkdocs-CVE-2025-27516.json index 8f86bb4ca57..7f9744fc0c4 100644 --- a/advisories/BREW-mkdocs-CVE-2025-27516.json +++ b/advisories/BREW-mkdocs-CVE-2025-27516.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2025-27516", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-cpwx-vrp4-4pq7", "CVE-2025-27516", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "jinja2", - "subject_version": "3.1.6", - "key": "pkg:pypi/jinja2@3.1.6", - "resource": "jinja2" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-CVE-2025-69534.json b/advisories/BREW-mkdocs-CVE-2025-69534.json index 30f95b74a77..3ebce7c89d8 100644 --- a/advisories/BREW-mkdocs-CVE-2025-69534.json +++ b/advisories/BREW-mkdocs-CVE-2025-69534.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mkdocs-CVE-2025-69534", "published": "2026-08-13T17:14:17Z", - "modified": "2026-08-13T17:14:17Z", + "modified": "2026-09-10T19:59:01Z", "upstream": [ "GHSA-5wmx-573v-2qwq", "CVE-2025-69534", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "markdown", - "subject_version": "3.10.2", - "key": "pkg:pypi/markdown@3.10.2", - "resource": "markdown" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2014-1829.json b/advisories/BREW-pass-import-CVE-2014-1829.json index 1bf2a8bb5a5..6dc580cb909 100644 --- a/advisories/BREW-pass-import-CVE-2014-1829.json +++ b/advisories/BREW-pass-import-CVE-2014-1829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2014-1829", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-cfj3-7x9c-4p3h", "CVE-2014-1829", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2014-1830.json b/advisories/BREW-pass-import-CVE-2014-1830.json index 17c9cd7478d..e75e8eae216 100644 --- a/advisories/BREW-pass-import-CVE-2014-1830.json +++ b/advisories/BREW-pass-import-CVE-2014-1830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2014-1830", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-652x-xj99-gmcc", "CVE-2014-1830", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2015-2296.json b/advisories/BREW-pass-import-CVE-2015-2296.json index 29092233e40..c9dad5d4b99 100644 --- a/advisories/BREW-pass-import-CVE-2015-2296.json +++ b/advisories/BREW-pass-import-CVE-2015-2296.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2015-2296", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-pg2w-x9wp-vw92", "CVE-2015-2296", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2016-9015.json b/advisories/BREW-pass-import-CVE-2016-9015.json index 7dc698e935a..3df93942790 100644 --- a/advisories/BREW-pass-import-CVE-2016-9015.json +++ b/advisories/BREW-pass-import-CVE-2016-9015.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2016-9015", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-v4w5-p2hg-8fh6", "CVE-2016-9015", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2017-18342.json b/advisories/BREW-pass-import-CVE-2017-18342.json index c8222228787..e8e5abd626f 100644 --- a/advisories/BREW-pass-import-CVE-2017-18342.json +++ b/advisories/BREW-pass-import-CVE-2017-18342.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2017-18342", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-rprw-h62v-c2w7", "CVE-2017-18342", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2018-18074.json b/advisories/BREW-pass-import-CVE-2018-18074.json index 2107180afa0..a089a5f4ac4 100644 --- a/advisories/BREW-pass-import-CVE-2018-18074.json +++ b/advisories/BREW-pass-import-CVE-2018-18074.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2018-18074", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-x84v-xcm2-53pg", "CVE-2018-18074", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2018-20060.json b/advisories/BREW-pass-import-CVE-2018-20060.json index db2f1bee7e6..52735376c51 100644 --- a/advisories/BREW-pass-import-CVE-2018-20060.json +++ b/advisories/BREW-pass-import-CVE-2018-20060.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2018-20060", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-www2-v7xj-xrc6", "CVE-2018-20060", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2018-25091.json b/advisories/BREW-pass-import-CVE-2018-25091.json index e5d31068731..7b97b621005 100644 --- a/advisories/BREW-pass-import-CVE-2018-25091.json +++ b/advisories/BREW-pass-import-CVE-2018-25091.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2018-25091", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-gwvm-45gx-3cf8", "CVE-2018-25091", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2019-11236.json b/advisories/BREW-pass-import-CVE-2019-11236.json index c4037b4fe10..d7899a659b0 100644 --- a/advisories/BREW-pass-import-CVE-2019-11236.json +++ b/advisories/BREW-pass-import-CVE-2019-11236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2019-11236", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-r64q-w8jr-g9qp", "CVE-2019-11236", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2019-11324.json b/advisories/BREW-pass-import-CVE-2019-11324.json index 882325cd17f..8c48694383b 100644 --- a/advisories/BREW-pass-import-CVE-2019-11324.json +++ b/advisories/BREW-pass-import-CVE-2019-11324.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2019-11324", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-mh33-7rrq-662w", "CVE-2019-11324", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2019-20477.json b/advisories/BREW-pass-import-CVE-2019-20477.json index 2fad3c2ab01..d0ac9dd0c18 100644 --- a/advisories/BREW-pass-import-CVE-2019-20477.json +++ b/advisories/BREW-pass-import-CVE-2019-20477.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2019-20477", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-3pqx-4fqf-j49f", "CVE-2019-20477", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2020-14343.json b/advisories/BREW-pass-import-CVE-2020-14343.json index aca5ebf309c..6fdafb3002c 100644 --- a/advisories/BREW-pass-import-CVE-2020-14343.json +++ b/advisories/BREW-pass-import-CVE-2020-14343.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2020-14343", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-8q59-q68h-6hv4", "CVE-2020-14343", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2020-1747.json b/advisories/BREW-pass-import-CVE-2020-1747.json index d80d3a347b8..82737fbeecd 100644 --- a/advisories/BREW-pass-import-CVE-2020-1747.json +++ b/advisories/BREW-pass-import-CVE-2020-1747.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2020-1747", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-6757-jp84-gxfx", "CVE-2020-1747", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "pyyaml", - "subject_version": "6.0.3", - "key": "pkg:pypi/pyyaml@6.0.3", - "resource": "pyyaml" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2020-26137.json b/advisories/BREW-pass-import-CVE-2020-26137.json index 125a9ccd543..50d2d457c90 100644 --- a/advisories/BREW-pass-import-CVE-2020-26137.json +++ b/advisories/BREW-pass-import-CVE-2020-26137.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2020-26137", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-wqvq-5m8c-6g24", "CVE-2020-26137", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2020-7212.json b/advisories/BREW-pass-import-CVE-2020-7212.json index 1bf85f2d5e8..608b9a7f1ba 100644 --- a/advisories/BREW-pass-import-CVE-2020-7212.json +++ b/advisories/BREW-pass-import-CVE-2020-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2020-7212", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-hmv2-79q8-fv6g", "CVE-2020-7212", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2021-28363.json b/advisories/BREW-pass-import-CVE-2021-28363.json index 393255ad893..4153b8e6c8f 100644 --- a/advisories/BREW-pass-import-CVE-2021-28363.json +++ b/advisories/BREW-pass-import-CVE-2021-28363.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2021-28363", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-5phf-pp7p-vc2r", "CVE-2021-28363", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2021-33503.json b/advisories/BREW-pass-import-CVE-2021-33503.json index 054da5b3895..586dbe153d5 100644 --- a/advisories/BREW-pass-import-CVE-2021-33503.json +++ b/advisories/BREW-pass-import-CVE-2021-33503.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2021-33503", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-q2q7-5pp4-w6pg", "CVE-2021-33503", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2023-32681.json b/advisories/BREW-pass-import-CVE-2023-32681.json index 096cfc09bbf..b8dc33cb303 100644 --- a/advisories/BREW-pass-import-CVE-2023-32681.json +++ b/advisories/BREW-pass-import-CVE-2023-32681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2023-32681", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-j8r2-6x86-q33q", "CVE-2023-32681", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2023-43804.json b/advisories/BREW-pass-import-CVE-2023-43804.json index 0c0c6b5ca35..393b372d66d 100644 --- a/advisories/BREW-pass-import-CVE-2023-43804.json +++ b/advisories/BREW-pass-import-CVE-2023-43804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2023-43804", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-v845-jxx5-vc9f", "CVE-2023-43804", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2023-45803.json b/advisories/BREW-pass-import-CVE-2023-45803.json index 5006c1ca84e..6f457e7cee0 100644 --- a/advisories/BREW-pass-import-CVE-2023-45803.json +++ b/advisories/BREW-pass-import-CVE-2023-45803.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2023-45803", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-g4mx-q9vg-27p4", "CVE-2023-45803", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2024-35195.json b/advisories/BREW-pass-import-CVE-2024-35195.json index c6aac868328..3b7608b71be 100644 --- a/advisories/BREW-pass-import-CVE-2024-35195.json +++ b/advisories/BREW-pass-import-CVE-2024-35195.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2024-35195", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-9wx4-h78v-vm56", "CVE-2024-35195", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2024-3651.json b/advisories/BREW-pass-import-CVE-2024-3651.json index 10e945b8d1f..12864d86ca6 100644 --- a/advisories/BREW-pass-import-CVE-2024-3651.json +++ b/advisories/BREW-pass-import-CVE-2024-3651.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2024-3651", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-jjg7-2v4v-x38h", "CVE-2024-3651", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.15", - "key": "pkg:pypi/idna@3.15", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2024-37891.json b/advisories/BREW-pass-import-CVE-2024-37891.json index c9f2d76a1ed..5f75a778839 100644 --- a/advisories/BREW-pass-import-CVE-2024-37891.json +++ b/advisories/BREW-pass-import-CVE-2024-37891.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2024-37891", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-34jh-p97f-mpxf", "CVE-2024-37891", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2024-47081.json b/advisories/BREW-pass-import-CVE-2024-47081.json index 2f73f32a7b4..37a430d4d58 100644 --- a/advisories/BREW-pass-import-CVE-2024-47081.json +++ b/advisories/BREW-pass-import-CVE-2024-47081.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2024-47081", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-9hjg-9r4m-mvj7", "CVE-2024-47081", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2025-50181.json b/advisories/BREW-pass-import-CVE-2025-50181.json index e3239971194..adcefd27638 100644 --- a/advisories/BREW-pass-import-CVE-2025-50181.json +++ b/advisories/BREW-pass-import-CVE-2025-50181.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2025-50181", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-pq67-6m6q-mj2v", "CVE-2025-50181", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2025-50182.json b/advisories/BREW-pass-import-CVE-2025-50182.json index dc6453de29e..985c75d0ec4 100644 --- a/advisories/BREW-pass-import-CVE-2025-50182.json +++ b/advisories/BREW-pass-import-CVE-2025-50182.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2025-50182", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-48p4-8xcf-vxj5", "CVE-2025-50182", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2025-66418.json b/advisories/BREW-pass-import-CVE-2025-66418.json index 044cfe7418f..72656c60c20 100644 --- a/advisories/BREW-pass-import-CVE-2025-66418.json +++ b/advisories/BREW-pass-import-CVE-2025-66418.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2025-66418", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-gm62-xv2j-4w53", "CVE-2025-66418", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2025-66471.json b/advisories/BREW-pass-import-CVE-2025-66471.json index 79fcdf8ab71..b272ec99ff8 100644 --- a/advisories/BREW-pass-import-CVE-2025-66471.json +++ b/advisories/BREW-pass-import-CVE-2025-66471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2025-66471", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-2xpw-w6gg-jr37", "CVE-2025-66471", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2026-21441.json b/advisories/BREW-pass-import-CVE-2026-21441.json index ea0c7c93a28..5c4694cb7eb 100644 --- a/advisories/BREW-pass-import-CVE-2026-21441.json +++ b/advisories/BREW-pass-import-CVE-2026-21441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2026-21441", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-38jv-5279-wg99", "CVE-2026-21441", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2026-25645.json b/advisories/BREW-pass-import-CVE-2026-25645.json index 74dc8036ede..40d2e197bc4 100644 --- a/advisories/BREW-pass-import-CVE-2026-25645.json +++ b/advisories/BREW-pass-import-CVE-2026-25645.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2026-25645", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-gc5v-m9x4-r6x2", "CVE-2026-25645", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "requests", - "subject_version": "2.34.0", - "key": "pkg:pypi/requests@2.34.0", - "resource": "requests" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2026-44431.json b/advisories/BREW-pass-import-CVE-2026-44431.json index cc6fcc7f9a6..41496b109dc 100644 --- a/advisories/BREW-pass-import-CVE-2026-44431.json +++ b/advisories/BREW-pass-import-CVE-2026-44431.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2026-44431", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-qccp-gfcp-xxvc", "CVE-2026-44431", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2026-44432.json b/advisories/BREW-pass-import-CVE-2026-44432.json index 760b0710a34..b1d9aea3ce1 100644 --- a/advisories/BREW-pass-import-CVE-2026-44432.json +++ b/advisories/BREW-pass-import-CVE-2026-44432.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2026-44432", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-mf9v-mfxr-j63j", "CVE-2026-44432", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "urllib3", - "subject_version": "2.7.0", - "key": "pkg:pypi/urllib3@2.7.0", - "resource": "urllib3" - }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pass-import-CVE-2026-45409.json b/advisories/BREW-pass-import-CVE-2026-45409.json index 6c37c481b41..ebdb8918e9f 100644 --- a/advisories/BREW-pass-import-CVE-2026-45409.json +++ b/advisories/BREW-pass-import-CVE-2026-45409.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-pass-import-CVE-2026-45409", "published": "2026-08-13T17:25:33Z", - "modified": "2026-08-13T17:25:33Z", + "modified": "2026-09-10T20:21:28Z", "upstream": [ "GHSA-65pc-fj4g-8rjx", "CVE-2026-45409", @@ -42,14 +42,6 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ - { - "strategy": "registry", - "ecosystem": "PyPI", - "name": "idna", - "subject_version": "3.15", - "key": "pkg:pypi/idna@3.15", - "resource": "idna" - }, { "strategy": "registry", "ecosystem": "PyPI",