{
 "schema_version": 4,
 "kind": "backlog",
 "source_commit": "8a29a842ab74",
 "source_dirty": false,
 "generated_at": "2026-09-15T17:10:08+00:00",
 "snapshot_date": "2026-09-15",
 "launched": true,
 "profile": "weekly",
 "min_age_days": 7,
 "epoch": null,
 "counts": {
  "total": 2182,
  "undated_excluded": 3,
  "epoch_excluded": 0,
  "unmeasurable_rule": 2182,
  "named": 0
 },
 "coverage": {
  "cnas_effective": 268,
  "cnas_sighted": 313,
  "cnas_own_channel": 3,
  "total_cnas": 539,
  "pct_effective": 49.7,
  "min_sightings": 3
 },
 "caveats": {
  "count_is_a_floor": true,
  "owner_is_inferred": true,
  "days_public_is_a_floor_not_lateness": true,
  "must_is_never_established": true,
  "rule_mostly_unmeasurable": true,
  "not_a_cna_scorecard": true
 },
 "degraded": true,
 "degraded_reasons": [
  "1 feed(s) stopped early, outside their configured limits"
 ],
 "limitations": [
  "ubuntu: hit the 200-page cap at 4,000 records of 78,533 (5.1%); read back to 2026-08-12, a 34-day window; the configured window opens 2023-01-01, so most of it was not read"
 ],
 "columns": [
  "cve_id",
  "state",
  "days_public",
  "hours_public",
  "public_date",
  "public_date_origin",
  "clock_known",
  "rule",
  "rule_strength",
  "rule_certainty",
  "rule_basis",
  "self_disclosed",
  "owner_nameable",
  "veto_evaluated",
  "clock_origin",
  "advisory_date",
  "advisory_days_public",
  "sources",
  "feed_count",
  "refs",
  "source_urls",
  "package",
  "ecosystem",
  "description",
  "state_verified_this_run"
 ],
 "rows": [
  {
   "cve_id": "CVE-2023-24036",
   "state": "RESERVED",
   "public_date": "2023-02-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-02-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-0316\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0316.json",
   "description": "CVE-2023-24036",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1315,
   "clock_known": true,
   "hours_public": 31560,
   "clock_origin": "advisory",
   "advisory_date": "2023-02-08",
   "advisory_days_public": 1315,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0316.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-1658",
   "state": "RESERVED",
   "public_date": "2023-04-03",
   "sources": "jvn",
   "feed_count": 1,
   "dates": {
    "jvn": "2023-04-03"
   },
   "refs": "jvn:JVNDB-2023-001400",
   "description": "CONPROSYS HMI System(CHS) vulnerable to SQL injection",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1261,
   "clock_known": true,
   "hours_public": 30264,
   "clock_origin": "advisory",
   "advisory_date": "2023-04-03",
   "advisory_days_public": 1261,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "jvn": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001400.html"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-28355",
   "state": "RESERVED",
   "public_date": "2023-04-11",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-04-11"
   },
   "refs": "csaf:Schneider Electric CPCERT\tSEVD-2023-101-01\thttps://www.se.com/.well-known/csaf/2023/sevd-2023-101-01.json",
   "description": "CVE-2023-28355",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1253,
   "clock_known": true,
   "hours_public": 30072,
   "clock_origin": "advisory",
   "advisory_date": "2023-04-11",
   "advisory_days_public": 1253,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://www.se.com/.well-known/csaf/2023/sevd-2023-101-01.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-21119",
   "state": "RESERVED",
   "public_date": "2023-05-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2023-05-01",
    "csaf": "2023-05-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-1101\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1101.json;osv:Android::unknown:",
   "description": "In Gs101Pipeline::Update of gs101_displaycolor_pipeline.cc, there is a possible device reboot when watching a video due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1233,
   "clock_known": true,
   "hours_public": 29592,
   "clock_origin": "advisory",
   "advisory_date": "2023-05-01",
   "advisory_days_public": 1233,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1101.json",
    "osv": "https://osv.dev/list?q=CVE-2023-21119"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-28641",
   "state": "RESERVED",
   "public_date": "2023-05-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2023-05-21"
   },
   "refs": "ghsa-repos:autolab/Autolab\tGHSA-962r-m9fj-3hj9",
   "description": "autolab/Autolab repository advisory GHSA-962r-m9fj-3hj9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1213,
   "clock_known": true,
   "hours_public": 29112,
   "clock_origin": "advisory",
   "advisory_date": "2023-05-21",
   "advisory_days_public": 1213,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/autolab/Autolab/security/advisories/GHSA-962r-m9fj-3hj9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40317",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40317",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40317"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40323",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40323",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40323"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40316",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40316",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40316"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40324",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40324",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40324"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40319",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40319",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40319"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40321",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40321",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40321"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40325",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40325",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40325"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40322",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40322",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40322"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40320",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40320",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40320"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-40318",
   "state": "RESERVED",
   "public_date": "2023-08-20",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2102\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json;ubuntu-osv:UBUNTU-CVE-2023-40318",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1122,
   "clock_known": true,
   "hours_public": 26928,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-20",
   "advisory_days_public": 1122,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2102.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-40318"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-35758",
   "state": "RESERVED",
   "public_date": "2023-08-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-08-30"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2237\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2237.json",
   "description": "CVE-2023-35758",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1112,
   "clock_known": true,
   "hours_public": 26688,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-30",
   "advisory_days_public": 1112,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2237.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-4638",
   "state": "RESERVED",
   "public_date": "2023-08-31",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2023-09-11",
    "csaf": "2023-08-31"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2244\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2244.json;ubuntu-osv:UBUNTU-CVE-2023-4638",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1111,
   "clock_known": true,
   "hours_public": 26664,
   "clock_origin": "advisory",
   "advisory_date": "2023-08-31",
   "advisory_days_public": 1111,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2244.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-4638"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-3281",
   "state": "RESERVED",
   "public_date": "2023-10-11",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-10-11"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2635\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2635.json",
   "description": "CVE-2023-3281",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1070,
   "clock_known": true,
   "hours_public": 25680,
   "clock_origin": "advisory",
   "advisory_date": "2023-10-11",
   "advisory_days_public": 1070,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2635.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-21386",
   "state": "RESERVED",
   "public_date": "2023-10-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-10-30"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2778\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2778.json",
   "description": "CVE-2023-21386",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1051,
   "clock_known": true,
   "hours_public": 25224,
   "clock_origin": "advisory",
   "advisory_date": "2023-10-30",
   "advisory_days_public": 1051,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2778.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-48675",
   "state": "RESERVED",
   "public_date": "2023-11-19",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-11-19"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-2966\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2966.json",
   "description": "CVE-2023-48675",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1031,
   "clock_known": true,
   "hours_public": 24744,
   "clock_origin": "advisory",
   "advisory_date": "2023-11-19",
   "advisory_days_public": 1031,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2966.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6670",
   "state": "RESERVED",
   "public_date": "2023-11-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-11-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3026\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3026.json",
   "description": "CVE-2023-6670",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1022,
   "clock_known": true,
   "hours_public": 24528,
   "clock_origin": "advisory",
   "advisory_date": "2023-11-28",
   "advisory_days_public": 1022,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3026.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6396",
   "state": "RESERVED",
   "public_date": "2023-12-04",
   "sources": "ubuntu-osv",
   "feed_count": 1,
   "dates": {
    "ubuntu-osv": "2023-12-04"
   },
   "refs": "ubuntu-osv:UBUNTU-CVE-2023-6396",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1016,
   "clock_known": true,
   "hours_public": 24384,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2023-6396"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6661",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6661",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6662",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6662",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6663",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6663",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6664",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6664",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6665",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6665",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6666",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6666",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6667",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6667",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6668",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6668",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6669",
   "state": "RESERVED",
   "public_date": "2023-12-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2023-12-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2023-3199\thttps://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json",
   "description": "CVE-2023-6669",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 1000,
   "clock_known": true,
   "hours_public": 24000,
   "clock_origin": "advisory",
   "advisory_date": "2023-12-20",
   "advisory_days_public": 1000,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3199.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-0234",
   "state": "RESERVED",
   "public_date": "2024-01-04",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2024-01-04",
    "csaf": "2024-01-04"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2024-0234\thttps://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0234.json;redhat:CVE-2024-0234",
   "description": "podman-desktop: Code injection Through Electron Fuses",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 985,
   "clock_known": true,
   "hours_public": 23640,
   "clock_origin": "advisory",
   "advisory_date": "2024-01-04",
   "advisory_days_public": 985,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2024-0234",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-0234.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2024-0234"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-49667",
   "state": "RESERVED",
   "public_date": "2024-02-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2024-02-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 957,
   "clock_known": true,
   "hours_public": 22968,
   "clock_origin": "advisory",
   "advisory_date": "2024-02-01",
   "advisory_days_public": 957,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2023-49667"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-49668",
   "state": "RESERVED",
   "public_date": "2024-02-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2024-02-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 957,
   "clock_known": true,
   "hours_public": 22968,
   "clock_origin": "advisory",
   "advisory_date": "2024-02-01",
   "advisory_days_public": 957,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2023-49668"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-23552",
   "state": "RESERVED",
   "public_date": "2024-02-04",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-02-04"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0290\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0290.json",
   "description": "CVE-2024-23552",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 954,
   "clock_known": true,
   "hours_public": 22896,
   "clock_origin": "advisory",
   "advisory_date": "2024-02-04",
   "advisory_days_public": 954,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0290.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-1314",
   "state": "RESERVED",
   "public_date": "2024-02-08",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2024-02-08",
    "osv": "2024-02-08"
   },
   "refs": "ghsa:GHSA-hvp4-vrv2-8wrq;osv:PyPI:kinto-attachment",
   "description": "Kinto Attachment's attachments can be replaced on read-only records",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 950,
   "clock_known": true,
   "hours_public": 22800,
   "clock_origin": "advisory",
   "advisory_date": "2024-02-08",
   "advisory_days_public": 950,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "kinto-attachment",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hvp4-vrv2-8wrq",
    "osv": "https://osv.dev/list?q=CVE-2024-1314"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-25555",
   "state": "RESERVED",
   "public_date": "2024-02-15",
   "sources": "jvn",
   "feed_count": 1,
   "dates": {
    "jvn": "2024-02-15"
   },
   "refs": "jvn:JVNDB-2024-002560",
   "description": "Android App \"Mopria Print Service\" vulnerable to improper intent handling",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 943,
   "clock_known": true,
   "hours_public": 22632,
   "clock_origin": "advisory",
   "advisory_date": "2024-02-15",
   "advisory_days_public": 943,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "jvn": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-002560.html"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-26048",
   "state": "RESERVED",
   "public_date": "2024-03-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-03-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0616\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0616.json",
   "description": "CVE-2024-26048",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 917,
   "clock_known": true,
   "hours_public": 22008,
   "clock_origin": "advisory",
   "advisory_date": "2024-03-12",
   "advisory_days_public": 917,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0616.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-30173",
   "state": "RESERVED",
   "public_date": "2024-04-01",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2024-04-02",
    "osv": "2024-04-02",
    "csaf": "2024-04-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0754\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0754.json;ghsa:GHSA-hhf8-f5w9-g6vh;osv:Packagist:causal/oidc",
   "description": "OpenID Connect Authentication (oidc) Typo3 extension Authentication Bypass",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 897,
   "clock_known": true,
   "hours_public": 21528,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-01",
   "advisory_days_public": 897,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "causal/oidc",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0754.json",
    "ghsa": "https://github.com/advisories/GHSA-hhf8-f5w9-g6vh",
    "osv": "https://osv.dev/list?q=CVE-2024-30173"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-28661",
   "state": "RESERVED",
   "public_date": "2024-04-04",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2024-04-04"
   },
   "refs": "alpine:ffmpeg;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0790\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0790.json",
   "description": "CVE-2024-28661",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 894,
   "clock_known": true,
   "hours_public": 21456,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-04",
   "advisory_days_public": 894,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ffmpeg",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2024-28661",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0790.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-28055",
   "state": "RESERVED",
   "public_date": "2024-04-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0845\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0845.json",
   "description": "CVE-2024-28055",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 889,
   "clock_known": true,
   "hours_public": 21336,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-09",
   "advisory_days_public": 889,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0845.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-3324",
   "state": "RESERVED",
   "public_date": "2024-04-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0836\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0836.json",
   "description": "CVE-2024-3324",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 889,
   "clock_known": true,
   "hours_public": 21336,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-09",
   "advisory_days_public": 889,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0836.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-3326",
   "state": "RESERVED",
   "public_date": "2024-04-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0836\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0836.json",
   "description": "CVE-2024-3326",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 889,
   "clock_known": true,
   "hours_public": 21336,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-09",
   "advisory_days_public": 889,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0836.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-3327",
   "state": "RESERVED",
   "public_date": "2024-04-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0836\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0836.json",
   "description": "CVE-2024-3327",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 889,
   "clock_known": true,
   "hours_public": 21336,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-09",
   "advisory_days_public": 889,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0836.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-26320",
   "state": "RESERVED",
   "public_date": "2024-04-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0933\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json",
   "description": "CVE-2024-26320",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 880,
   "clock_known": true,
   "hours_public": 21120,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-18",
   "advisory_days_public": 880,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-26321",
   "state": "RESERVED",
   "public_date": "2024-04-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0933\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json",
   "description": "CVE-2024-26321",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 880,
   "clock_known": true,
   "hours_public": 21120,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-18",
   "advisory_days_public": 880,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-26322",
   "state": "RESERVED",
   "public_date": "2024-04-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0933\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json",
   "description": "CVE-2024-26322",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 880,
   "clock_known": true,
   "hours_public": 21120,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-18",
   "advisory_days_public": 880,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-26325",
   "state": "RESERVED",
   "public_date": "2024-04-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0933\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json",
   "description": "CVE-2024-26325",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 880,
   "clock_known": true,
   "hours_public": 21120,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-18",
   "advisory_days_public": 880,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-26326",
   "state": "RESERVED",
   "public_date": "2024-04-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-04-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-0933\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json",
   "description": "CVE-2024-26326",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 880,
   "clock_known": true,
   "hours_public": 21120,
   "clock_origin": "advisory",
   "advisory_date": "2024-04-18",
   "advisory_days_public": 880,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0933.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-23694",
   "state": "RESERVED",
   "public_date": "2024-05-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2024-05-01",
    "csaf": "2024-05-07"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1065\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1065.json;osv:Android::unknown:",
   "description": "In multiple locations, there is a possible way to use a paired Bluetooth LE audio device to achieve code execution due to a use after free.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 867,
   "clock_known": true,
   "hours_public": 20808,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-01",
   "advisory_days_public": 867,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1065.json",
    "osv": "https://osv.dev/list?q=CVE-2024-23694"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-34456",
   "state": "RESERVED",
   "public_date": "2024-05-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1028\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1028.json",
   "description": "CVE-2024-34456",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 863,
   "clock_known": true,
   "hours_public": 20712,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-05",
   "advisory_days_public": 863,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1028.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4047",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4047",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4048",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4048",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4049",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4049",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4050",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4050",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4051",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4051",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4052",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4052",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4053",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4053",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4054",
   "state": "RESERVED",
   "public_date": "2024-05-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1085\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json",
   "description": "CVE-2024-4054",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 859,
   "clock_known": true,
   "hours_public": 20616,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-09",
   "advisory_days_public": 859,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-27131",
   "state": "RESERVED",
   "public_date": "2024-05-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1195\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1195.json",
   "description": "CVE-2024-27131",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 848,
   "clock_known": true,
   "hours_public": 20352,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-20",
   "advisory_days_public": 848,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1195.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-31969",
   "state": "RESERVED",
   "public_date": "2024-05-28",
   "sources": "alas",
   "feed_count": 1,
   "dates": {
    "alas": "2024-05-28"
   },
   "refs": "alas:CVE-2024-31969",
   "description": "In sudo-1.8.23-10.amzn2.3.6 (Amazon Linux 2) and sudo-1.8.23-10.58.amzn1 (Amazon Linux 1), a user with an entry in the sudoers file, enabling them to run commands as another unprivileged user, can leverage it to run commands as root.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 840,
   "clock_known": true,
   "hours_public": 20160,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-28",
   "advisory_days_public": 840,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2024-31969.html"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-4407",
   "state": "RESERVED",
   "public_date": "2024-05-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1247\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1247.json",
   "description": "CVE-2024-4407",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 840,
   "clock_known": true,
   "hours_public": 20160,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-28",
   "advisory_days_public": 840,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1247.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-5027",
   "state": "RESERVED",
   "public_date": "2024-05-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-05-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1245\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1245.json",
   "description": "CVE-2024-5027",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 840,
   "clock_known": true,
   "hours_public": 20160,
   "clock_origin": "advisory",
   "advisory_date": "2024-05-28",
   "advisory_days_public": 840,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1245.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-31329",
   "state": "RESERVED",
   "public_date": "2024-06-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-06-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1278\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1278.json",
   "description": "CVE-2024-31329",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 834,
   "clock_known": true,
   "hours_public": 20016,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-03",
   "advisory_days_public": 834,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1278.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-31330",
   "state": "RESERVED",
   "public_date": "2024-06-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-06-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1278\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1278.json",
   "description": "CVE-2024-31330",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 834,
   "clock_known": true,
   "hours_public": 20016,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-03",
   "advisory_days_public": 834,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1278.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-27369",
   "state": "RESERVED",
   "public_date": "2024-06-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-06-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1304\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1304.json",
   "description": "CVE-2024-27369",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 832,
   "clock_known": true,
   "hours_public": 19968,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-05",
   "advisory_days_public": 832,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1304.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-6537",
   "state": "RESERVED",
   "public_date": "2024-06-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2024-06-10"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM-Core\tGHSA-j482-m46g-v8r2",
   "description": "SuiteCRM/SuiteCRM-Core repository advisory GHSA-j482-m46g-v8r2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 827,
   "clock_known": true,
   "hours_public": 19848,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-10",
   "advisory_days_public": 827,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM-Core/security/advisories/GHSA-j482-m46g-v8r2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-36223",
   "state": "RESERVED",
   "public_date": "2024-06-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-06-14"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2024-0259\thttps://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0259.json",
   "description": "CVE-2024-36223",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 823,
   "clock_known": true,
   "hours_public": 19752,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-14",
   "advisory_days_public": 823,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0259.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-33861",
   "state": "RESERVED",
   "public_date": "2024-06-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-06-15"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2024:13925-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_13925-1.json",
   "description": "CVE-2024-33861",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 822,
   "clock_known": true,
   "hours_public": 19728,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-15",
   "advisory_days_public": 822,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_13925-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-38445",
   "state": "RESERVED",
   "public_date": "2024-06-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-06-18"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2024-38445\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-38445.json",
   "description": "CVE-2024-38445",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 819,
   "clock_known": true,
   "hours_public": 19656,
   "clock_origin": "advisory",
   "advisory_date": "2024-06-18",
   "advisory_days_public": 819,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-38445.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-36592",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:SUSE Product Security Team\tSUSE-SU-2024:2360-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2024_2360-1.json",
   "description": "CVE-2024-36592",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2024_2360-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40606",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40606",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40607",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40607",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40608",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40608",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40609",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40609",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40610",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40610",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40611",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40611",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40612",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40612",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-40613",
   "state": "RESERVED",
   "public_date": "2024-07-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-07-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1585\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json",
   "description": "CVE-2024-40613",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 798,
   "clock_known": true,
   "hours_public": 19152,
   "clock_origin": "advisory",
   "advisory_date": "2024-07-09",
   "advisory_days_public": 798,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1585.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-34735",
   "state": "RESERVED",
   "public_date": "2024-08-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2024-08-01",
    "csaf": "2024-08-06"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2024-0322\thttps://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0322.json;osv:Android:platform/frameworks/base",
   "description": "In multiple locations, there is a possible background activity launch due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 775,
   "clock_known": true,
   "hours_public": 18600,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-01",
   "advisory_days_public": 775,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0322.json",
    "osv": "https://osv.dev/list?q=CVE-2024-34735"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-20452",
   "state": "RESERVED",
   "public_date": "2024-08-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-08-07"
   },
   "refs": "csaf:Cisco\tcisco-sa-spa-http-vulns-RJZmX2Xz\thttps://www.cisco.com/.well-known/csaf/2024/cisco-sa-spa-http-vulns-rjzmx2xz.json",
   "description": "Cisco Small Business SPA300 and SPA500 HTTP Web UI Authenticated Arbitrary Command Execution Vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 769,
   "clock_known": true,
   "hours_public": 18456,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-07",
   "advisory_days_public": 769,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://www.cisco.com/.well-known/csaf/2024/cisco-sa-spa-http-vulns-rjzmx2xz.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-20453",
   "state": "RESERVED",
   "public_date": "2024-08-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-08-07"
   },
   "refs": "csaf:Cisco\tcisco-sa-spa-http-vulns-RJZmX2Xz\thttps://www.cisco.com/.well-known/csaf/2024/cisco-sa-spa-http-vulns-rjzmx2xz.json",
   "description": "Cisco Small Business SPA300 and SPA500 HTTP Web UI Authenticated Denial of Service Vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 769,
   "clock_known": true,
   "hours_public": 18456,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-07",
   "advisory_days_public": 769,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://www.cisco.com/.well-known/csaf/2024/cisco-sa-spa-http-vulns-rjzmx2xz.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-21969",
   "state": "RESERVED",
   "public_date": "2024-08-13",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-08-13"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1837\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1837.json",
   "description": "CVE-2024-21969",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 763,
   "clock_known": true,
   "hours_public": 18312,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-13",
   "advisory_days_public": 763,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1837.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-41993",
   "state": "RESERVED",
   "public_date": "2024-08-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-08-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-1855\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1855.json",
   "description": "CVE-2024-41993",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 762,
   "clock_known": true,
   "hours_public": 18288,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-14",
   "advisory_days_public": 762,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1855.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-6992",
   "state": "RESERVED",
   "public_date": "2024-08-18",
   "sources": "alpine,csaf,debian",
   "feed_count": 3,
   "dates": {
    "csaf": "2024-08-18"
   },
   "refs": "alpine:qt6-qtwebengine;csaf:SUSE Product Security Team\topenSUSE-SU-2024:14272-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_14272-1.json;debian:chromium",
   "description": "CVE-2024-6992",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 758,
   "clock_known": true,
   "hours_public": 18192,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-18",
   "advisory_days_public": 758,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qt6-qtwebengine",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2024-6992",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_14272-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-6992"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-6993",
   "state": "RESERVED",
   "public_date": "2024-08-18",
   "sources": "csaf,debian",
   "feed_count": 2,
   "dates": {
    "csaf": "2024-08-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2024:14272-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_14272-1.json;debian:chromium",
   "description": "CVE-2024-6993",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 758,
   "clock_known": true,
   "hours_public": 18192,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-18",
   "advisory_days_public": 758,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "chromium",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_14272-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-6993"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-6597",
   "state": "RESERVED",
   "public_date": "2024-08-27",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-08-27"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2024-6597\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-6597.json",
   "description": "CVE-2024-6597",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 749,
   "clock_known": true,
   "hours_public": 17976,
   "clock_origin": "advisory",
   "advisory_date": "2024-08-27",
   "advisory_days_public": 749,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-6597.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-37009",
   "state": "RESERVED",
   "public_date": "2024-09-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-2090\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json",
   "description": "CVE-2024-37009",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 736,
   "clock_known": true,
   "hours_public": 17664,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-09",
   "advisory_days_public": 736,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-37010",
   "state": "RESERVED",
   "public_date": "2024-09-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-2090\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json",
   "description": "CVE-2024-37010",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 736,
   "clock_known": true,
   "hours_public": 17664,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-09",
   "advisory_days_public": 736,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-37011",
   "state": "RESERVED",
   "public_date": "2024-09-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-2090\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json",
   "description": "CVE-2024-37011",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 736,
   "clock_known": true,
   "hours_public": 17664,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-09",
   "advisory_days_public": 736,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-37012",
   "state": "RESERVED",
   "public_date": "2024-09-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-2090\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json",
   "description": "CVE-2024-37012",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 736,
   "clock_known": true,
   "hours_public": 17664,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-09",
   "advisory_days_public": 736,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-42014",
   "state": "RESERVED",
   "public_date": "2024-09-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-2090\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json",
   "description": "CVE-2024-42014",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 736,
   "clock_known": true,
   "hours_public": 17664,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-09",
   "advisory_days_public": 736,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2090.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-45110",
   "state": "RESERVED",
   "public_date": "2024-09-11",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-11"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2024-0368\thttps://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0368.json",
   "description": "CVE-2024-45110",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 734,
   "clock_known": true,
   "hours_public": 17616,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-11",
   "advisory_days_public": 734,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0368.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-38393",
   "state": "RESERVED",
   "public_date": "2024-09-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-09-30"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2024-0385\thttps://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0385.json",
   "description": "CVE-2024-38393",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 715,
   "clock_known": true,
   "hours_public": 17160,
   "clock_origin": "advisory",
   "advisory_date": "2024-09-30",
   "advisory_days_public": 715,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0385.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-9370",
   "state": "RESERVED",
   "public_date": "2024-10-04",
   "sources": "csaf,debian,msrc",
   "feed_count": 3,
   "dates": {
    "csaf": "2024-10-04",
    "msrc": "2024-10-08"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2024:14383-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_14383-1.json;debian:chromium;msrc:msrc:2024-Oct",
   "description": "CVE-2024-9370",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 711,
   "clock_known": true,
   "hours_public": 17064,
   "clock_origin": "advisory",
   "advisory_date": "2024-10-04",
   "advisory_days_public": 711,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "chromium",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_14383-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-9370",
    "msrc": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-9370"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-8928",
   "state": "RESERVED",
   "public_date": "2024-10-08",
   "sources": "alas,csaf",
   "feed_count": 2,
   "dates": {
    "alas": "2024-10-12",
    "csaf": "2024-10-08"
   },
   "refs": "alas:CVE-2024-8928;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3116\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3116.json",
   "description": "php: Erroneous parsing of multipart form data",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 707,
   "clock_known": true,
   "hours_public": 16968,
   "clock_origin": "advisory",
   "advisory_date": "2024-10-08",
   "advisory_days_public": 707,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2024-8928.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3116.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-11249",
   "state": "RESERVED",
   "public_date": "2024-11-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-11-14"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2024-11249\thttps://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-11249.json",
   "description": "zlib-rs: zlib-rs stack overflow during decompression with malicious input",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 670,
   "clock_known": true,
   "hours_public": 16080,
   "clock_origin": "advisory",
   "advisory_date": "2024-11-14",
   "advisory_days_public": 670,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-11249.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-10512",
   "state": "RESERVED",
   "public_date": "2024-11-26",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-11-26"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3548\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3548.json",
   "description": "CVE-2024-10512",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 658,
   "clock_known": true,
   "hours_public": 15792,
   "clock_origin": "advisory",
   "advisory_date": "2024-11-26",
   "advisory_days_public": 658,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3548.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-8257",
   "state": "RESERVED",
   "public_date": "2024-12-05",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-12-01",
    "csaf": "2024-12-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3622\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3622.json;osv:Android::unknown:",
   "description": "In multiple locations, there is a possible bypass between two Java Card Applets due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 649,
   "clock_known": true,
   "hours_public": 15576,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-05",
   "advisory_days_public": 649,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3622.json",
    "osv": "https://osv.dev/list?q=CVE-2024-8257"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-46185",
   "state": "RESERVED",
   "public_date": "2024-12-06",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-06"
   },
   "refs": "csaf:SUSE Product Security Team\tSUSE-SU-2024:4079-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2024_4079-1.json",
   "description": "CVE-2024-46185",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 648,
   "clock_known": true,
   "hours_public": 15552,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-06",
   "advisory_days_public": 648,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2024_4079-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-43711",
   "state": "RESERVED",
   "public_date": "2024-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3669\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3669.json",
   "description": "CVE-2024-43711",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 644,
   "clock_known": true,
   "hours_public": 15456,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-10",
   "advisory_days_public": 644,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3669.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-44074",
   "state": "RESERVED",
   "public_date": "2024-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3668\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3668.json",
   "description": "CVE-2024-44074",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 644,
   "clock_known": true,
   "hours_public": 15456,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-10",
   "advisory_days_public": 644,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3668.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-54033",
   "state": "RESERVED",
   "public_date": "2024-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3677\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3677.json",
   "description": "CVE-2024-54033",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 644,
   "clock_known": true,
   "hours_public": 15456,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-10",
   "advisory_days_public": 644,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3677.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-54052",
   "state": "RESERVED",
   "public_date": "2024-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3677\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3677.json",
   "description": "CVE-2024-54052",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 644,
   "clock_known": true,
   "hours_public": 15456,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-10",
   "advisory_days_public": 644,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3677.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-54035",
   "state": "RESERVED",
   "public_date": "2024-12-11",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-11"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2024-0483\thttps://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0483.json",
   "description": "CVE-2024-54035",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 643,
   "clock_known": true,
   "hours_public": 15432,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-11",
   "advisory_days_public": 643,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2024/ncsc-2024-0483.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-12455",
   "state": "RESERVED",
   "public_date": "2024-12-12",
   "sources": "alas,csaf,debian,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2024-12-20",
    "redhat": "2024-12-12",
    "csaf": "2024-12-14"
   },
   "refs": "alas:CVE-2024-12455;csaf:SUSE Product Security Team\tCVE-2024-12455\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-12455.json;debian:glibc;redhat:CVE-2024-12455",
   "description": "glibc: glibc in Fedora 41 ships a broken getrandom/arc4random for ppc64le platform",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 642,
   "clock_known": true,
   "hours_public": 15408,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-12",
   "advisory_days_public": 642,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "glibc",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2024-12455.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-12455.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-12455",
    "redhat": "https://access.redhat.com/security/cve/CVE-2024-12455"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55643",
   "state": "RESERVED",
   "public_date": "2024-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3704\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json",
   "description": "CVE-2024-55643",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 638,
   "clock_known": true,
   "hours_public": 15312,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-16",
   "advisory_days_public": 638,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55644",
   "state": "RESERVED",
   "public_date": "2024-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3704\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json",
   "description": "CVE-2024-55644",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 638,
   "clock_known": true,
   "hours_public": 15312,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-16",
   "advisory_days_public": 638,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55645",
   "state": "RESERVED",
   "public_date": "2024-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3704\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json",
   "description": "CVE-2024-55645",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 638,
   "clock_known": true,
   "hours_public": 15312,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-16",
   "advisory_days_public": 638,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55646",
   "state": "RESERVED",
   "public_date": "2024-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3704\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json",
   "description": "CVE-2024-55646",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 638,
   "clock_known": true,
   "hours_public": 15312,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-16",
   "advisory_days_public": 638,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55647",
   "state": "RESERVED",
   "public_date": "2024-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3704\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json",
   "description": "CVE-2024-55647",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 638,
   "clock_known": true,
   "hours_public": 15312,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-16",
   "advisory_days_public": 638,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55648",
   "state": "RESERVED",
   "public_date": "2024-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2024-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2024-3704\thttps://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json",
   "description": "CVE-2024-55648",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 638,
   "clock_known": true,
   "hours_public": 15312,
   "clock_origin": "advisory",
   "advisory_date": "2024-12-16",
   "advisory_days_public": 638,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3704.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55919",
   "state": "RESERVED",
   "public_date": "2024-12-17",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2024-12-17"
   },
   "refs": "debian:sympa;ubuntu-osv:UBUNTU-CVE-2024-55919",
   "description": "[Improper input validation on generic SSO login]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 637,
   "clock_known": true,
   "hours_public": 15288,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "sympa",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-55919",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2024-55919"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-9525",
   "state": "RESERVED",
   "public_date": "2025-01-09",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-01-09"
   },
   "refs": "zdi:ZDI-25-025",
   "description": "ZDI advisory ZDI-25-025",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 614,
   "clock_known": true,
   "hours_public": 14736,
   "clock_origin": "advisory",
   "advisory_date": "2025-01-09",
   "advisory_days_public": 614,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-025/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-9523",
   "state": "RESERVED",
   "public_date": "2025-01-09",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-01-09"
   },
   "refs": "zdi:ZDI-25-023",
   "description": "ZDI advisory ZDI-25-023",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 614,
   "clock_known": true,
   "hours_public": 14736,
   "clock_origin": "advisory",
   "advisory_date": "2025-01-09",
   "advisory_days_public": 614,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-023/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-48943",
   "state": "RESERVED",
   "public_date": "2025-01-10",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2025-01-10"
   },
   "refs": "debian:fort-validator;ubuntu-osv:UBUNTU-CVE-2024-48943",
   "description": "A malicious RPKI rsync repository can prevent Fort from finishing its validation run by drip-feeding its content.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 613,
   "clock_known": true,
   "hours_public": 14712,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fort-validator",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-48943",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2024-48943"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-53889",
   "state": "RESERVED",
   "public_date": "2025-01-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-01-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0112\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0112.json",
   "description": "CVE-2024-53889",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 607,
   "clock_known": true,
   "hours_public": 14568,
   "clock_origin": "advisory",
   "advisory_date": "2025-01-16",
   "advisory_days_public": 607,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0112.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-52948",
   "state": "RESERVED",
   "public_date": "2025-01-22",
   "sources": "debian",
   "feed_count": 1,
   "dates": {},
   "refs": "debian:lemonldap-ng",
   "description": "lemonldap-ng",
   "state_verified_this_run": true,
   "public_date_origin": "lookup",
   "days_public": 601,
   "clock_known": true,
   "hours_public": 14424,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "lemonldap-ng",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-52948"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49743",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In multiple locations, there is a possible way to launch an activity from the background due to BAL Bypass.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2024-49743"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0094",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/packages/apps/Settings",
   "description": "In onCreateOptionsMenu of UserSettings.java, there is a possible way to remove the work profile by opening a hidden activity due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/packages/apps/Settings",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0094"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49741",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In multiple functions of AppWidgetServiceImpl.java, there is a possible persistent denial of service due to resource exhaustion.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2024-49741"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49721",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In InputMethodSubtypeArray of InputMethodSubtypeArray.java, there is a possible way to bypass a key intent check to launch arbitrary activity due to Parcel mismatch.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2024-49721"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0095",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/packages/apps/Settings",
   "description": "In AppTimeSpentPresenter of AppTimeSpentPreference.kt, there is a possible way to hijack implicit intent.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/packages/apps/Settings",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0095"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0096",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/hardware/st/nfc",
   "description": "In handlePollingLoopData of hal_fwlog.cc, there is a possible out of bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/hardware/st/nfc",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0096"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49723",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/external/conscrypt",
   "description": "In static of NativeCrypto.java, there is a possible way to obtain clear-text data due to improperly used crypto.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/external/conscrypt",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2024-49723"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49746",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/native",
   "description": "In multiple functions of Parcel.cpp, there is a possible way to manipulate file descriptors and escalate privileges due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/native",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2024-49746"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0097",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In transferTouchGesture of WindowManagerService.java , there is a possible way to steal sensitive user input due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0097"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0091",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/packages/apps/Settings",
   "description": "In isSafeIntent of AccountManagerService.java, there is a possible way to bypass an intent type check due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/packages/apps/Settings",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0091"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0098",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In multiple functions of TaskFragmentOrganizerController.java, there is a possible token leak due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0098"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49729",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/system/core",
   "description": "In GetTable of dm.cpp, there is a possible way to leak the raw FDE key in bug reports due to improperly used crypto.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/system/core",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2024-49729"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0099",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0099"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0100",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android:platform/frameworks/base",
   "description": "In onCreate of MediaProjectionPermissionActivity.java, there is a possible way to bypass user consent due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0100"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0088",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-02-01",
    "csaf": "2025-02-04"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0039\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json;osv:Android::linux_kernel:",
   "description": "In multiple functions of mremap.c, there is a possible use-after-free scenario in physical memory due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0039.json",
    "osv": "https://osv.dev/list?q=CVE-2025-0088"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0085",
   "state": "RESERVED",
   "public_date": "2025-02-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2025-02-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In registerCallback of BatteryMitigationAidl.cpp, there is a possible out of bounds read due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 591,
   "clock_known": true,
   "hours_public": 14184,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-01",
   "advisory_days_public": 591,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2025-0085"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49199",
   "state": "RESERVED",
   "public_date": "2025-02-11",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-11"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0318\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0318.json",
   "description": "CVE-2024-49199",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 581,
   "clock_known": true,
   "hours_public": 13944,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-11",
   "advisory_days_public": 581,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0318.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-23380",
   "state": "RESERVED",
   "public_date": "2025-02-13",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-13"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0377\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0377.json",
   "description": "CVE-2025-23380",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 579,
   "clock_known": true,
   "hours_public": 13896,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-13",
   "advisory_days_public": 579,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0377.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-6837",
   "state": "RESERVED",
   "public_date": "2025-02-14",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2025-02-14"
   },
   "refs": "alpine:grafana;csaf:SUSE Product Security Team\tSUSE-SU-2025:0524-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_0524-1.json",
   "description": "CVE-2024-6837",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 578,
   "clock_known": true,
   "hours_public": 13872,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-14",
   "advisory_days_public": 578,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "grafana",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2024-6837",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_0524-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-42511",
   "state": "RESERVED",
   "public_date": "2025-02-24",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-24"
   },
   "refs": "csaf:SUSE Product Security Team\tSUSE-FU-2025:0661-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-fu-2025_0661-1.json",
   "description": "CVE-2024-42511",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 568,
   "clock_known": true,
   "hours_public": 13632,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-24",
   "advisory_days_public": 568,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-fu-2025_0661-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-12361",
   "state": "RESERVED",
   "public_date": "2025-02-25",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-25"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2025:14833-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_14833-1.json",
   "description": "CVE-2024-12361",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 567,
   "clock_known": true,
   "hours_public": 13608,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-25",
   "advisory_days_public": 567,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_14833-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27227",
   "state": "RESERVED",
   "public_date": "2025-02-26",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-26"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0451\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0451.json",
   "description": "CVE-2025-27227",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 566,
   "clock_known": true,
   "hours_public": 13584,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-26",
   "advisory_days_public": 566,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0451.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27228",
   "state": "RESERVED",
   "public_date": "2025-02-26",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-26"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0451\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0451.json",
   "description": "CVE-2025-27228",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 566,
   "clock_known": true,
   "hours_public": 13584,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-26",
   "advisory_days_public": 566,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0451.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27229",
   "state": "RESERVED",
   "public_date": "2025-02-26",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-02-26"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0451\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0451.json",
   "description": "CVE-2025-27229",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 566,
   "clock_known": true,
   "hours_public": 13584,
   "clock_origin": "advisory",
   "advisory_date": "2025-02-26",
   "advisory_days_public": 566,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0451.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-49198",
   "state": "RESERVED",
   "public_date": "2025-03-02",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-03-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0464\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0464.json",
   "description": "CVE-2024-49198",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 562,
   "clock_known": true,
   "hours_public": 13488,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-02",
   "advisory_days_public": 562,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0464.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-51943",
   "state": "RESERVED",
   "public_date": "2025-03-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0476\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0476.json",
   "description": "CVE-2024-51943",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 561,
   "clock_known": true,
   "hours_public": 13464,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-03",
   "advisory_days_public": 561,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0476.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-30081",
   "state": "RESERVED",
   "public_date": "2025-03-17",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-03-19",
    "osv": "2025-03-19",
    "csaf": "2025-03-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0575\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0575.json;ghsa:GHSA-vmgw-24w6-9v82;osv:Packagist:clickstorm/cs-seo",
   "description": "Clickstorm SEO Allows Cross-Site Scripting (XSS)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 547,
   "clock_known": true,
   "hours_public": 13128,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-17",
   "advisory_days_public": 547,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "clickstorm/cs-seo",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0575.json",
    "ghsa": "https://github.com/advisories/GHSA-vmgw-24w6-9v82",
    "osv": "https://osv.dev/list?q=CVE-2025-30081"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-30083",
   "state": "RESERVED",
   "public_date": "2025-03-17",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-03-19",
    "osv": "2025-03-19",
    "csaf": "2025-03-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0575\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0575.json;ghsa:GHSA-rrh3-cgmx-w62f;osv:Packagist:codingms/additional-tca",
   "description": "Additional TCA Allows Cross-Site Scripting (XSS)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 547,
   "clock_known": true,
   "hours_public": 13128,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-17",
   "advisory_days_public": 547,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "codingms/additional-tca",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0575.json",
    "ghsa": "https://github.com/advisories/GHSA-rrh3-cgmx-w62f",
    "osv": "https://osv.dev/list?q=CVE-2025-30083"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-30082",
   "state": "RESERVED",
   "public_date": "2025-03-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-03-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0575\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0575.json",
   "description": "CVE-2025-30082",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 547,
   "clock_known": true,
   "hours_public": 13128,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-17",
   "advisory_days_public": 547,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0575.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-2792",
   "state": "RESERVED",
   "public_date": "2025-03-26",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2025-03-26",
    "osv": "2025-03-26"
   },
   "refs": "ghsa:GHSA-3p6v-hrg8-8qj7;osv:npm:@mozilla/readability",
   "description": "@mozilla/readability Denial of Service through Regex",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 538,
   "clock_known": true,
   "hours_public": 12912,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-26",
   "advisory_days_public": 538,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@mozilla/readability",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-3p6v-hrg8-8qj7",
    "osv": "https://osv.dev/list?q=CVE-2025-2792"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-1827",
   "state": "RESERVED",
   "public_date": "2025-03-26",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-03-26"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0644\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0644.json",
   "description": "CVE-2025-1827",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 538,
   "clock_known": true,
   "hours_public": 12912,
   "clock_origin": "advisory",
   "advisory_date": "2025-03-26",
   "advisory_days_public": 538,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0644.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26415",
   "state": "RESERVED",
   "public_date": "2025-04-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-04-01",
    "csaf": "2025-04-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0787\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0787.json;osv:Android::unknown:",
   "description": "In n/a of n/a, there is a possible n/a due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 532,
   "clock_known": true,
   "hours_public": 12768,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-01",
   "advisory_days_public": 532,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0787.json",
    "osv": "https://osv.dev/list?q=CVE-2025-26415"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-28269",
   "state": "RESERVED",
   "public_date": "2025-04-07",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2025-04-07",
    "osv": "2025-04-07"
   },
   "refs": "ghsa:GHSA-hpqf-m68j-2pfx;osv:npm:js-object-utilities",
   "description": "js-object-utilities Vulnerable to Prototype Pollution",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 526,
   "clock_known": true,
   "hours_public": 12624,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-07",
   "advisory_days_public": 526,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "js-object-utilities",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hpqf-m68j-2pfx",
    "osv": "https://osv.dev/list?q=CVE-2025-28269"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27529",
   "state": "RESERVED",
   "public_date": "2025-04-07",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-04-07"
   },
   "refs": "zdi:ZDI-25-201",
   "description": "ZDI advisory ZDI-25-201",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 526,
   "clock_known": true,
   "hours_public": 12624,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-07",
   "advisory_days_public": 526,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-201/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-20570",
   "state": "RESERVED",
   "public_date": "2025-04-08",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2025-04-08",
    "csaf": "2025-04-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0748\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0748.json;ghsa-repos:microsoft/vscode\tGHSA-hwrx-jgf2-74hw",
   "description": "microsoft/vscode repository advisory GHSA-hwrx-jgf2-74hw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 525,
   "clock_known": true,
   "hours_public": 12600,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-08",
   "advisory_days_public": 525,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0748.json",
    "ghsa-repos": "https://github.com/microsoft/vscode/security/advisories/GHSA-hwrx-jgf2-74hw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32416",
   "state": "RESERVED",
   "public_date": "2025-04-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-04-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0834\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json",
   "description": "CVE-2025-32416",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 518,
   "clock_known": true,
   "hours_public": 12432,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-15",
   "advisory_days_public": 518,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32417",
   "state": "RESERVED",
   "public_date": "2025-04-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-04-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0834\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json",
   "description": "CVE-2025-32417",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 518,
   "clock_known": true,
   "hours_public": 12432,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-15",
   "advisory_days_public": 518,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32418",
   "state": "RESERVED",
   "public_date": "2025-04-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-04-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0834\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json",
   "description": "CVE-2025-32418",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 518,
   "clock_known": true,
   "hours_public": 12432,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-15",
   "advisory_days_public": 518,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32419",
   "state": "RESERVED",
   "public_date": "2025-04-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-04-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0834\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json",
   "description": "CVE-2025-32419",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 518,
   "clock_known": true,
   "hours_public": 12432,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-15",
   "advisory_days_public": 518,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0834.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-32198",
   "state": "RESERVED",
   "public_date": "2025-04-25",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2025-04-25",
    "osv": "2025-04-25"
   },
   "refs": "ghsa:GHSA-95fc-g4gj-mqmx;osv:Go:github.com/rancher/steve",
   "description": "Steve doesn\u2019t verify a server\u2019s certificate and is susceptible to man-in-the-middle (MitM) attacks",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 508,
   "clock_known": true,
   "hours_public": 12192,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-25",
   "advisory_days_public": 508,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/rancher/steve",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-95fc-g4gj-mqmx",
    "osv": "https://osv.dev/list?q=CVE-2023-32198"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-23390",
   "state": "RESERVED",
   "public_date": "2025-04-25",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-04-25",
    "osv": "2025-04-25",
    "csaf": "2025-05-07"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2025:15059-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15059-1.json;ghsa:GHSA-xgpc-q899-67p8;osv:Go:github.com/rancher/fleet",
   "description": "Fleet doesn\u2019t validate a server\u2019s certificate when connecting through SSH",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 508,
   "clock_known": true,
   "hours_public": 12192,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-25",
   "advisory_days_public": 508,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/rancher/fleet",
   "ecosystem": "Go",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15059-1.json",
    "ghsa": "https://github.com/advisories/GHSA-xgpc-q899-67p8",
    "osv": "https://osv.dev/list?q=CVE-2025-23390"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-22031",
   "state": "RESERVED",
   "public_date": "2025-04-25",
   "sources": "csaf,ghsa,ghsa-repos,osv",
   "feed_count": 4,
   "dates": {
    "ghsa": "2025-04-25",
    "ghsa-repos": "2025-04-25",
    "osv": "2025-04-25",
    "csaf": "2025-05-07"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2025:15059-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15059-1.json;ghsa-repos:rancher/rancher\tGHSA-8h6m-wv39-239m;ghsa:GHSA-8h6m-wv39-239m;osv:Go:github.com/rancher/rancher",
   "description": "Rancher users who can create Projects can gain access to arbitrary projects",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 508,
   "clock_known": true,
   "hours_public": 12192,
   "clock_origin": "advisory",
   "advisory_date": "2025-04-25",
   "advisory_days_public": 508,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/rancher/rancher",
   "ecosystem": "Go",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15059-1.json",
    "ghsa": "https://github.com/advisories/GHSA-8h6m-wv39-239m",
    "ghsa-repos": "https://github.com/rancher/rancher/security/advisories/GHSA-8h6m-wv39-239m",
    "osv": "https://osv.dev/list?q=CVE-2024-22031"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-2774",
   "state": "RESERVED",
   "public_date": "2025-05-01",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2025-05-04",
    "zdi": "2025-05-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-0929\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0929.json;zdi:ZDI-25-282",
   "description": "CVE-2025-2774",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 502,
   "clock_known": true,
   "hours_public": 12048,
   "clock_origin": "advisory",
   "advisory_date": "2025-05-01",
   "advisory_days_public": 502,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0929.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-282/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-57391",
   "state": "RESERVED",
   "public_date": "2025-05-12",
   "sources": "jvn",
   "feed_count": 1,
   "dates": {
    "jvn": "2025-05-12"
   },
   "refs": "jvn:JVNDB-2025-004671",
   "description": "Multiple vulnerabilities in GL-MT2500 and GL-MT2500A",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 491,
   "clock_known": true,
   "hours_public": 11784,
   "clock_origin": "advisory",
   "advisory_date": "2025-05-12",
   "advisory_days_public": 491,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "jvn": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-004671.html"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-47425",
   "state": "RESERVED",
   "public_date": "2025-05-14",
   "sources": "ghsa,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa": "2025-05-15",
    "ghsa-repos": "2025-05-14"
   },
   "refs": "ghsa-repos:reflex-dev/reflex\tGHSA-rf8x-9mhr-49wg;ghsa:GHSA-rf8x-9mhr-49wg",
   "description": "Reflex vulnerable to private state fields modification",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 489,
   "clock_known": true,
   "hours_public": 11736,
   "clock_origin": "advisory",
   "advisory_date": "2025-05-14",
   "advisory_days_public": 489,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-rf8x-9mhr-49wg",
    "ghsa-repos": "https://github.com/reflex-dev/reflex/security/advisories/GHSA-rf8x-9mhr-49wg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-55906",
   "state": "RESERVED",
   "public_date": "2025-05-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-05-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1093\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1093.json",
   "description": "CVE-2024-55906",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 485,
   "clock_known": true,
   "hours_public": 11640,
   "clock_origin": "advisory",
   "advisory_date": "2025-05-18",
   "advisory_days_public": 485,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1093.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32314",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In ppmp_protect_buf of drm_fw.c, there is a possible memory protection issue due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32314"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32338",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In nvt_flash_read of nt36xxx.c, there is a possible out of bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32338"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32339",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In TBD of TBD, there is a possible out of bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32339"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32315",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In tbd of tbd, there is a possible lockscreen bypass due to an unusual root cause.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32315"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32336",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In wl_escan_handler of TBD, there is a possible out of bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32336"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32337",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In sms_SetTpUdIe() of sms_PduCodec.cc, there is a possible out of bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32337"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32340",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In ProtocolMiscCurrentLinkCapacityEstimate() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32340"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26459",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In SetLogicalToPhysicalSlotPortMapping::onRequest of commands.cpp, there is a possible out of bounds write due to a buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-26459"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32334",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "Analysis: Access Vector: Local Layer: Userland Root Causes: Heap Buffer Overflow SRS Categories: - Android Security SRS Category: Memory Safety Writeup: A stack trace alone with PoC app is insufficient to determine if this represents a genuine memory corruption vulnerability reachable by an untrusted application.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32334"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26457",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "CVE-2025-26457",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-26457"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26460",
   "state": "RESERVED",
   "public_date": "2025-06-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-06-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In CopyDataFromFmq of common_utils.cpp, there is a possible out of bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 471,
   "clock_known": true,
   "hours_public": 11304,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-01",
   "advisory_days_public": 471,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-26460"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27230",
   "state": "RESERVED",
   "public_date": "2025-06-02",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1224\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1224.json",
   "description": "CVE-2025-27230",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 470,
   "clock_known": true,
   "hours_public": 11280,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-02",
   "advisory_days_public": 470,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1224.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-21486",
   "state": "RESERVED",
   "public_date": "2025-06-03",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-06-05",
    "ghsa-repos": "2025-06-03",
    "osv": "2025-06-05"
   },
   "refs": "ghsa-repos:denoland/deno\tGHSA-jv4x-jv3h-qff5;ghsa:GHSA-jv4x-jv3h-qff5;osv:crates.io:deno",
   "description": "Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 469,
   "clock_known": true,
   "hours_public": 11256,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-03",
   "advisory_days_public": 469,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "deno",
   "ecosystem": "crates.io",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-jv4x-jv3h-qff5",
    "ghsa-repos": "https://github.com/denoland/deno/security/advisories/GHSA-jv4x-jv3h-qff5",
    "osv": "https://osv.dev/list?q=CVE-2024-21486"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-51538",
   "state": "RESERVED",
   "public_date": "2025-06-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1236\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1236.json",
   "description": "CVE-2024-51538",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 469,
   "clock_known": true,
   "hours_public": 11256,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-03",
   "advisory_days_public": 469,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1236.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-5293",
   "state": "RESERVED",
   "public_date": "2025-06-04",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-04"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1243\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1243.json",
   "description": "CVE-2025-5293",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 468,
   "clock_known": true,
   "hours_public": 11232,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-04",
   "advisory_days_public": 468,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1243.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-22485",
   "state": "RESERVED",
   "public_date": "2025-06-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1272\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1272.json",
   "description": "CVE-2025-22485",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 463,
   "clock_known": true,
   "hours_public": 11112,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-09",
   "advisory_days_public": 463,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1272.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32335",
   "state": "RESERVED",
   "public_date": "2025-06-10",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-12-01",
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1291\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json;osv:Android::unknown:",
   "description": "In convertHalTDToRil of commands.cpp, there is a possible out of bounds write due to a buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 462,
   "clock_known": true,
   "hours_public": 11088,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-10",
   "advisory_days_public": 462,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1291.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32335"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-47100",
   "state": "RESERVED",
   "public_date": "2025-06-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1285\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1285.json",
   "description": "CVE-2025-47100",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 462,
   "clock_known": true,
   "hours_public": 11088,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-10",
   "advisory_days_public": 462,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1285.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49512",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49512",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49513",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49513",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49514",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49514",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49515",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49515",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49516",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49516",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49517",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49517",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-49518",
   "state": "RESERVED",
   "public_date": "2025-06-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1353\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json",
   "description": "CVE-2025-49518",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 455,
   "clock_known": true,
   "hours_public": 10920,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-17",
   "advisory_days_public": 455,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-56920",
   "state": "RESERVED",
   "public_date": "2025-06-24",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-06-24"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1384\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1384.json",
   "description": "CVE-2024-56920",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 448,
   "clock_known": true,
   "hours_public": 10752,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-24",
   "advisory_days_public": 448,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1384.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-6809",
   "state": "RESERVED",
   "public_date": "2025-06-27",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-06-27"
   },
   "refs": "zdi:ZDI-25-466",
   "description": "ZDI advisory ZDI-25-466",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 445,
   "clock_known": true,
   "hours_public": 10680,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-27",
   "advisory_days_public": 445,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-466/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-6808",
   "state": "RESERVED",
   "public_date": "2025-06-27",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-06-27"
   },
   "refs": "zdi:ZDI-25-465",
   "description": "ZDI advisory ZDI-25-465",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 445,
   "clock_known": true,
   "hours_public": 10680,
   "clock_origin": "advisory",
   "advisory_date": "2025-06-27",
   "advisory_days_public": 445,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-465/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-22436",
   "state": "RESERVED",
   "public_date": "2025-07-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-07-07"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1476\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1476.json",
   "description": "CVE-2025-22436",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 435,
   "clock_known": true,
   "hours_public": 10440,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-07",
   "advisory_days_public": 435,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1476.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26433",
   "state": "RESERVED",
   "public_date": "2025-07-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-07-07"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1476\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1476.json",
   "description": "CVE-2025-26433",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 435,
   "clock_known": true,
   "hours_public": 10440,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-07",
   "advisory_days_public": 435,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1476.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-6812",
   "state": "RESERVED",
   "public_date": "2025-07-07",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-07-07"
   },
   "refs": "zdi:ZDI-25-473",
   "description": "ZDI advisory ZDI-25-473",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 435,
   "clock_known": true,
   "hours_public": 10440,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-07",
   "advisory_days_public": 435,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-473/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-36350",
   "state": "RESERVED",
   "public_date": "2025-07-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-07-08"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0213\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0213.json",
   "description": "CVE-2025-36350",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 434,
   "clock_known": true,
   "hours_public": 10416,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-08",
   "advisory_days_public": 434,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0213.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-7041",
   "state": "RESERVED",
   "public_date": "2025-07-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-07-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1504\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1504.json",
   "description": "CVE-2025-7041",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 434,
   "clock_known": true,
   "hours_public": 10416,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-08",
   "advisory_days_public": 434,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1504.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-6243",
   "state": "RESERVED",
   "public_date": "2025-07-08",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2025-07-08"
   },
   "refs": "certcc:VU#613753",
   "description": "RUCKUS Virtual SmartZone (vSZ) and RUCKUS Network Director (RND) contain multiple vulnerabilities",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 434,
   "clock_known": true,
   "hours_public": 10416,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-08",
   "advisory_days_public": 434,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/613753"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-2790",
   "state": "RESERVED",
   "public_date": "2025-07-11",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-07-11"
   },
   "refs": "zdi:ZDI-25-590",
   "description": "ZDI advisory ZDI-25-590",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 431,
   "clock_known": true,
   "hours_public": 10344,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-11",
   "advisory_days_public": 431,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-590/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-33143",
   "state": "RESERVED",
   "public_date": "2025-07-29",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-07-29"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1675\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1675.json",
   "description": "CVE-2025-33143",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 413,
   "clock_known": true,
   "hours_public": 9912,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-29",
   "advisory_days_public": 413,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1675.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-8389",
   "state": "RESERVED",
   "public_date": "2025-07-30",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-07-30"
   },
   "refs": "zdi:ZDI-25-732",
   "description": "ZDI advisory ZDI-25-732",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 412,
   "clock_known": true,
   "hours_public": 9888,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-30",
   "advisory_days_public": 412,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-732/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-3132",
   "state": "RESERVED",
   "public_date": "2025-07-30",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-07-30"
   },
   "refs": "zdi:ZDI-25-730",
   "description": "ZDI advisory ZDI-25-730",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 412,
   "clock_known": true,
   "hours_public": 9888,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-30",
   "advisory_days_public": 412,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-730/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-41419",
   "state": "RESERVED",
   "public_date": "2025-07-31",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-07-31",
    "ghsa-repos": "2025-07-31",
    "osv": "2025-07-31"
   },
   "refs": "ghsa-repos:modelscope/ms-swift\tGHSA-7c78-rm87-5673;ghsa:GHSA-7c78-rm87-5673;osv:PyPI:ms-swift",
   "description": "MS SWIFT WEB-UI RCE Vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 411,
   "clock_known": true,
   "hours_public": 9864,
   "clock_origin": "advisory",
   "advisory_date": "2025-07-31",
   "advisory_days_public": 411,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ms-swift",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-7c78-rm87-5673",
    "ghsa-repos": "https://github.com/modelscope/ms-swift/security/advisories/GHSA-7c78-rm87-5673",
    "osv": "https://osv.dev/list?q=CVE-2025-41419"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-43867",
   "state": "RESERVED",
   "public_date": "2025-08-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-07"
   },
   "refs": "csaf:CISA\tICSA-25-219-02\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-219-02.json",
   "description": "Johnson Controls FX Server, FX80 and FX90 (Update A)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 404,
   "clock_known": true,
   "hours_public": 9696,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-07",
   "advisory_days_public": 404,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-219-02.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-53697",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:CISA\tICSA-25-224-02\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json",
   "description": "Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 (Update A)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-53698",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:CISA\tICSA-25-224-02\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json",
   "description": "Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 (Update A)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-53699",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:CISA\tICSA-25-224-02\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json",
   "description": "Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 (Update A)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-53700",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:CISA\tICSA-25-224-02\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json",
   "description": "Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 (Update A)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-224-02.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-21965",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1770\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1770.json",
   "description": "CVE-2024-21965",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1770.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-36312",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1767\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1767.json",
   "description": "CVE-2024-36312",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1767.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-8094",
   "state": "RESERVED",
   "public_date": "2025-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1816\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1816.json",
   "description": "CVE-2025-8094",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 399,
   "clock_known": true,
   "hours_public": 9576,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-12",
   "advisory_days_public": 399,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1816.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-52617",
   "state": "RESERVED",
   "public_date": "2025-08-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1854\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1854.json",
   "description": "CVE-2025-52617",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 394,
   "clock_known": true,
   "hours_public": 9456,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-17",
   "advisory_days_public": 394,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1854.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-53016",
   "state": "RESERVED",
   "public_date": "2025-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2025-08-19"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-48h6-hpp2-357h",
   "description": "discourse/discourse repository advisory GHSA-48h6-hpp2-357h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 392,
   "clock_known": true,
   "hours_public": 9408,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-19",
   "advisory_days_public": 392,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-48h6-hpp2-357h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-9037",
   "state": "RESERVED",
   "public_date": "2025-08-19",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2025-08-19"
   },
   "refs": "certcc:VU#706118",
   "description": "Workhorse Software Services, Inc. software prior to version 1.9.4.48019, default deployment is vulnerable to multiple issues.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 392,
   "clock_known": true,
   "hours_public": 9408,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-19",
   "advisory_days_public": 392,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/706118"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-9040",
   "state": "RESERVED",
   "public_date": "2025-08-19",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2025-08-19"
   },
   "refs": "certcc:VU#706118",
   "description": "Workhorse Software Services, Inc. software prior to version 1.9.4.48019, default deployment is vulnerable to multiple issues.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 392,
   "clock_known": true,
   "hours_public": 9408,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-19",
   "advisory_days_public": 392,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/706118"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-9141",
   "state": "RESERVED",
   "public_date": "2025-08-20",
   "sources": "csaf,ghsa,ghsa-repos,osv,redhat",
   "feed_count": 5,
   "dates": {
    "ghsa": "2025-08-21",
    "ghsa-repos": "2025-08-20",
    "redhat": "2025-08-20",
    "osv": "2025-08-21",
    "csaf": "2025-08-20"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2025-9141\thttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9141.json;ghsa-repos:vllm-project/vllm\tGHSA-79j6-g2m3-jgfw;ghsa:GHSA-79j6-g2m3-jgfw;osv:PyPI:vllm;redhat:CVE-2025-9141",
   "description": "vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 391,
   "clock_known": true,
   "hours_public": 9384,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-20",
   "advisory_days_public": 391,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "vllm",
   "ecosystem": "PyPI",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9141.json",
    "ghsa": "https://github.com/advisories/GHSA-79j6-g2m3-jgfw",
    "ghsa-repos": "https://github.com/vllm-project/vllm/security/advisories/GHSA-79j6-g2m3-jgfw",
    "osv": "https://osv.dev/list?q=CVE-2025-9141",
    "redhat": "https://access.redhat.com/security/cve/CVE-2025-9141"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-11058",
   "state": "RESERVED",
   "public_date": "2025-08-26",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-08-26",
    "osv": "2025-08-26",
    "csaf": "2025-08-26"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2025-11058\thttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11058.json;ghsa:GHSA-cfmv-h8fx-85m7;osv:PyPI:xml2rfc",
   "description": "xml2rfc has an arbitrary file read vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 385,
   "clock_known": true,
   "hours_public": 9240,
   "clock_origin": "advisory",
   "advisory_date": "2025-08-26",
   "advisory_days_public": 385,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "xml2rfc",
   "ecosystem": "PyPI",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11058.json",
    "ghsa": "https://github.com/advisories/GHSA-cfmv-h8fx-85m7",
    "osv": "https://osv.dev/list?q=CVE-2025-11058"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-36910",
   "state": "RESERVED",
   "public_date": "2025-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2025-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In hw_oem_imei_init of hw_oem_imei.c, there is a possible escalation of privilege due to hardware identifiers not being fused to OTP. This could lead to local escalation of privilege with no additional execution privileges needed.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 379,
   "clock_known": true,
   "hours_public": 9096,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-01",
   "advisory_days_public": 379,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2025-36910"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32344",
   "state": "RESERVED",
   "public_date": "2025-09-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-09-01",
    "csaf": "2025-09-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1964\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1964.json;osv:Android::unknown:",
   "description": "In SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 379,
   "clock_known": true,
   "hours_public": 9096,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-01",
   "advisory_days_public": 379,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1964.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32344"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32342",
   "state": "RESERVED",
   "public_date": "2025-09-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-09-01",
    "csaf": "2025-09-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1964\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1964.json;osv:Android::unknown:",
   "description": "In CopyDataFromFmq of common_utils.cpp, there is a possible out of bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 379,
   "clock_known": true,
   "hours_public": 9096,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-01",
   "advisory_days_public": 379,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1964.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32342"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-32343",
   "state": "RESERVED",
   "public_date": "2025-09-01",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2025-09-01",
    "csaf": "2025-09-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-1964\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1964.json;osv:Android::unknown:",
   "description": "In CopyDataFromFmq of common_utils.cpp, there is a possible out of bounds write due to an integer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 379,
   "clock_known": true,
   "hours_public": 9096,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-01",
   "advisory_days_public": 379,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1964.json",
    "osv": "https://osv.dev/list?q=CVE-2025-32343"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-11059",
   "state": "RESERVED",
   "public_date": "2025-09-10",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2025-09-10",
    "osv": "2025-09-10",
    "csaf": "2025-09-10"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2025-11059\thttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11059.json;ghsa:GHSA-9mv7-3c64-mmqw;osv:PyPI:xml2rfc",
   "description": "xml2rfc is vulnerable to arbitrary file reads through prepped files",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 370,
   "clock_known": true,
   "hours_public": 8880,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-10",
   "advisory_days_public": 370,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "xml2rfc",
   "ecosystem": "PyPI",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11059.json",
    "ghsa": "https://github.com/advisories/GHSA-9mv7-3c64-mmqw",
    "osv": "https://osv.dev/list?q=CVE-2025-11059"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-9125",
   "state": "RESERVED",
   "public_date": "2025-09-22",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2025-09-22"
   },
   "refs": "certcc:VU#780141",
   "description": "Cross-site scripting vulnerability in Lectora course navigation",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 358,
   "clock_known": true,
   "hours_public": 8592,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-22",
   "advisory_days_public": 358,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/780141"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-59688",
   "state": "RESERVED",
   "public_date": "2025-09-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-09-23"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2025:15572-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15572-1.json",
   "description": "CVE-2025-59688",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 357,
   "clock_known": true,
   "hours_public": 8568,
   "clock_origin": "advisory",
   "advisory_date": "2025-09-23",
   "advisory_days_public": 357,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15572-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27687",
   "state": "RESERVED",
   "public_date": "2025-10-01",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-10-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2185\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2185.json",
   "description": "CVE-2025-27687",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 349,
   "clock_known": true,
   "hours_public": 8376,
   "clock_origin": "advisory",
   "advisory_date": "2025-10-01",
   "advisory_days_public": 349,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2185.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-61620",
   "state": "RESERVED",
   "public_date": "2025-10-07",
   "sources": "csaf,ghsa,ghsa-repos,osv,redhat",
   "feed_count": 5,
   "dates": {
    "ghsa": "2025-10-07",
    "ghsa-repos": "2025-10-07",
    "redhat": "2025-10-08",
    "osv": "2025-10-07",
    "csaf": "2026-02-27"
   },
   "refs": "csaf:Red Hat Product Security\tRHSA-2026:3462\thttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3462.json;ghsa-repos:vllm-project/vllm\tGHSA-6fvq-23cw-5628;ghsa:GHSA-6fvq-23cw-5628;osv:PyPI:vllm;redhat:CVE-2025-61620",
   "description": "vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 343,
   "clock_known": true,
   "hours_public": 8232,
   "clock_origin": "advisory",
   "advisory_date": "2025-10-07",
   "advisory_days_public": 343,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "vllm",
   "ecosystem": "PyPI",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3462.json",
    "ghsa": "https://github.com/advisories/GHSA-6fvq-23cw-5628",
    "ghsa-repos": "https://github.com/vllm-project/vllm/security/advisories/GHSA-6fvq-23cw-5628",
    "osv": "https://osv.dev/list?q=CVE-2025-61620",
    "redhat": "https://access.redhat.com/security/cve/CVE-2025-61620"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-59977",
   "state": "RESERVED",
   "public_date": "2025-10-13",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-10-13"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0305\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0305.json",
   "description": "CVE-2025-59977",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 337,
   "clock_known": true,
   "hours_public": 8088,
   "clock_origin": "advisory",
   "advisory_date": "2025-10-13",
   "advisory_days_public": 337,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0305.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-62704",
   "state": "RESERVED",
   "public_date": "2025-10-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-10-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2341\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2341.json",
   "description": "CVE-2025-62704",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 330,
   "clock_known": true,
   "hours_public": 7920,
   "clock_origin": "advisory",
   "advisory_date": "2025-10-20",
   "advisory_days_public": 330,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2341.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-57779",
   "state": "RESERVED",
   "public_date": "2025-10-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2025-10-25"
   },
   "refs": "ghsa-repos:pi-hole/web\tGHSA-8hr3-47jh-25vr",
   "description": "pi-hole/web repository advisory GHSA-8hr3-47jh-25vr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 325,
   "clock_known": true,
   "hours_public": 7800,
   "clock_origin": "advisory",
   "advisory_date": "2025-10-25",
   "advisory_days_public": 325,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pi-hole/web/security/advisories/GHSA-8hr3-47jh-25vr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-14439",
   "state": "RESERVED",
   "public_date": "2025-10-29",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-10-29"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2025-14439\thttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14439.json",
   "description": "usd: OpenUSD: Remote Code Execution via a specially crafted file",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 321,
   "clock_known": true,
   "hours_public": 7704,
   "clock_origin": "advisory",
   "advisory_date": "2025-10-29",
   "advisory_days_public": 321,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14439.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-62768",
   "state": "RESERVED",
   "public_date": "2025-11-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-11-07"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2025-62768\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2025-62768.json",
   "description": "CVE-2025-62768",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 312,
   "clock_known": true,
   "hours_public": 7488,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-07",
   "advisory_days_public": 312,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2025-62768.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-33134",
   "state": "RESERVED",
   "public_date": "2025-11-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-11-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2532\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2532.json",
   "description": "CVE-2025-33134",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 310,
   "clock_known": true,
   "hours_public": 7440,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-09",
   "advisory_days_public": 310,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2532.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-64172",
   "state": "RESERVED",
   "public_date": "2025-11-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2025-11-13"
   },
   "refs": "ghsa-repos:apollographql/federation\tGHSA-m8jr-fxqx-8xx6",
   "description": "apollographql/federation repository advisory GHSA-m8jr-fxqx-8xx6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 306,
   "clock_known": true,
   "hours_public": 7344,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-13",
   "advisory_days_public": 306,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/apollographql/federation/security/advisories/GHSA-m8jr-fxqx-8xx6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-62769",
   "state": "RESERVED",
   "public_date": "2025-11-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-11-14"
   },
   "refs": "csaf:SUSE Product Security Team\tSUSE-SU-2025:4100-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_4100-1.json",
   "description": "CVE-2025-62769",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 305,
   "clock_known": true,
   "hours_public": 7320,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-14",
   "advisory_days_public": 305,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_4100-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-13207",
   "state": "RESERVED",
   "public_date": "2025-11-20",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2025-11-20"
   },
   "refs": "certcc:VU#268029",
   "description": "Tenda N300 Wi-Fi 4G LTE Router 4G03 Pro impacted by vulnerabilities",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 299,
   "clock_known": true,
   "hours_public": 7176,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-20",
   "advisory_days_public": 299,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/268029"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-24481",
   "state": "RESERVED",
   "public_date": "2025-11-20",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2025-11-20"
   },
   "refs": "certcc:VU#268029",
   "description": "Tenda N300 Wi-Fi 4G LTE Router 4G03 Pro impacted by vulnerabilities",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 299,
   "clock_known": true,
   "hours_public": 7176,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-20",
   "advisory_days_public": 299,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/268029"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-13402",
   "state": "RESERVED",
   "public_date": "2025-11-21",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2025-11-21",
    "csaf": "2025-11-24"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2025:15762-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15762-1.json;ubuntu-osv:UBUNTU-CVE-2025-13402",
   "description": "[RNP PKESK Session Keys Generated as All-Zero]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 298,
   "clock_known": true,
   "hours_public": 7152,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-24",
   "advisory_days_public": 295,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15762-1.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2025-13402"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-66288",
   "state": "RESERVED",
   "public_date": "2025-11-25",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-11-25"
   },
   "refs": "zdi:ZDI-25-1015",
   "description": "ZDI advisory ZDI-25-1015",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 294,
   "clock_known": true,
   "hours_public": 7056,
   "clock_origin": "advisory",
   "advisory_date": "2025-11-25",
   "advisory_days_public": 294,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-1015/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-57736",
   "state": "RESERVED",
   "public_date": "2025-12-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-09"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2025:15803-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15803-1.json",
   "description": "CVE-2025-57736",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 280,
   "clock_known": true,
   "hours_public": 6720,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-09",
   "advisory_days_public": 280,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2025_15803-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-64874",
   "state": "RESERVED",
   "public_date": "2025-12-09",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2789\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2789.json",
   "description": "CVE-2025-64874",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 280,
   "clock_known": true,
   "hours_public": 6720,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-09",
   "advisory_days_public": 280,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2789.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-64540",
   "state": "RESERVED",
   "public_date": "2025-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-10"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0389\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0389.json",
   "description": "CVE-2025-64540",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 279,
   "clock_known": true,
   "hours_public": 6696,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-10",
   "advisory_days_public": 279,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0389.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-64552",
   "state": "RESERVED",
   "public_date": "2025-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-10"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0389\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0389.json",
   "description": "CVE-2025-64552",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 279,
   "clock_known": true,
   "hours_public": 6696,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-10",
   "advisory_days_public": 279,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0389.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-64860",
   "state": "RESERVED",
   "public_date": "2025-12-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-10"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0389\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0389.json",
   "description": "CVE-2025-64860",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 279,
   "clock_known": true,
   "hours_public": 6696,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-10",
   "advisory_days_public": 279,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0389.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-14400",
   "state": "RESERVED",
   "public_date": "2025-12-10",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2025-12-10"
   },
   "refs": "zdi:ZDI-25-1061",
   "description": "ZDI advisory ZDI-25-1061",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 279,
   "clock_known": true,
   "hours_public": 6696,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-10",
   "advisory_days_public": 279,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-25-1061/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-43874",
   "state": "RESERVED",
   "public_date": "2025-12-11",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-11"
   },
   "refs": "csaf:CISA\tICSA-25-345-02\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-02.json",
   "description": "Johnson Controls iSTAR Ultra",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 278,
   "clock_known": true,
   "hours_public": 6672,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-11",
   "advisory_days_public": 278,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-02.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-46681",
   "state": "RESERVED",
   "public_date": "2025-12-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2856\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2856.json",
   "description": "CVE-2025-46681",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 274,
   "clock_known": true,
   "hours_public": 6576,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-15",
   "advisory_days_public": 274,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2856.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-67854",
   "state": "RESERVED",
   "public_date": "2025-12-15",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2851\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2851.json",
   "description": "CVE-2025-67854",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 274,
   "clock_known": true,
   "hours_public": 6576,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-15",
   "advisory_days_public": 274,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2851.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-66475",
   "state": "RESERVED",
   "public_date": "2025-12-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2865\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2865.json",
   "description": "CVE-2025-66475",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 273,
   "clock_known": true,
   "hours_public": 6552,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-16",
   "advisory_days_public": 273,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2865.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-57779",
   "state": "RESERVED",
   "public_date": "2025-12-24",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-24"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0401\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0401.json",
   "description": "CVE-2025-57779",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 265,
   "clock_known": true,
   "hours_public": 6360,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-24",
   "advisory_days_public": 265,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0401.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-58085",
   "state": "RESERVED",
   "public_date": "2025-12-24",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-24"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0401\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0401.json",
   "description": "CVE-2025-58085",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 265,
   "clock_known": true,
   "hours_public": 6360,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-24",
   "advisory_days_public": 265,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0401.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-59488",
   "state": "RESERVED",
   "public_date": "2025-12-24",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-24"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2025-0401\thttps://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0401.json",
   "description": "CVE-2025-59488",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 265,
   "clock_known": true,
   "hours_public": 6360,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-24",
   "advisory_days_public": 265,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2025/ncsc-2025-0401.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-67326",
   "state": "RESERVED",
   "public_date": "2025-12-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2923\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json",
   "description": "CVE-2025-67326",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 261,
   "clock_known": true,
   "hours_public": 6264,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-28",
   "advisory_days_public": 261,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-67327",
   "state": "RESERVED",
   "public_date": "2025-12-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2923\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json",
   "description": "CVE-2025-67327",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 261,
   "clock_known": true,
   "hours_public": 6264,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-28",
   "advisory_days_public": 261,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-67328",
   "state": "RESERVED",
   "public_date": "2025-12-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2923\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json",
   "description": "CVE-2025-67328",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 261,
   "clock_known": true,
   "hours_public": 6264,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-28",
   "advisory_days_public": 261,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-67329",
   "state": "RESERVED",
   "public_date": "2025-12-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2025-12-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2025-2923\thttps://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json",
   "description": "CVE-2025-67329",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 261,
   "clock_known": true,
   "hours_public": 6264,
   "clock_origin": "advisory",
   "advisory_date": "2025-12-28",
   "advisory_days_public": 261,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2923.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-65606",
   "state": "RESERVED",
   "public_date": "2026-01-06",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2026-01-06"
   },
   "refs": "certcc:VU#295169",
   "description": "TOTOLINK EX200 firmware-upload error handling can activate an unauthenticated root telnet service",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 252,
   "clock_known": true,
   "hours_public": 6048,
   "clock_origin": "advisory",
   "advisory_date": "2026-01-06",
   "advisory_days_public": 252,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/295169"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-13328",
   "state": "RESERVED",
   "public_date": "2026-01-15",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2026-01-15"
   },
   "refs": "certcc:VU#472136",
   "description": "Information Leak and DoS Vulnerabilities in Redmi Buds 3 Pro through 6 Pro",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 243,
   "clock_known": true,
   "hours_public": 5832,
   "clock_origin": "advisory",
   "advisory_date": "2026-01-15",
   "advisory_days_public": 243,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/472136"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-13834",
   "state": "RESERVED",
   "public_date": "2026-01-15",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2026-01-15"
   },
   "refs": "certcc:VU#472136",
   "description": "Information Leak and DoS Vulnerabilities in Redmi Buds 3 Pro through 6 Pro",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 243,
   "clock_known": true,
   "hours_public": 5832,
   "clock_origin": "advisory",
   "advisory_date": "2026-01-15",
   "advisory_days_public": 243,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/472136"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-31884",
   "state": "RESERVED",
   "public_date": "2026-01-20",
   "sources": "alas,csaf,debian,ghsa-repos,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-01-22",
    "ubuntu-osv": "2026-01-21",
    "ghsa-repos": "2026-01-21",
    "redhat": "2026-01-20",
    "csaf": "2026-02-17"
   },
   "refs": "alas:CVE-2024-31884;csaf:Red Hat Product Security\tRHSA-2026:2800\thttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2800.json;debian:ceph;ghsa-repos:ceph/ceph\tGHSA-xj9f-7g59-m4jx;redhat:CVE-2024-31884;ubuntu-osv:UBUNTU-CVE-2024",
   "description": "A vulnerability was found in how Ceph uses Pybind, which does not implement correct certificate checking.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 238,
   "clock_known": true,
   "hours_public": 5712,
   "clock_origin": "advisory",
   "advisory_date": "2026-01-20",
   "advisory_days_public": 238,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ceph",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2024-31884.html",
    "csaf": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2800.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-31884",
    "ghsa-repos": "https://github.com/ceph/ceph/security/advisories/GHSA-xj9f-7g59-m4jx",
    "redhat": "https://access.redhat.com/security/cve/CVE-2024-31884",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2024-31884"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-65586",
   "state": "RESERVED",
   "public_date": "2026-01-20",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2026-01-20"
   },
   "refs": "certcc:VU#481830",
   "description": "Libheif uncompressed codec lacks bounds check leading to application crash",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 238,
   "clock_known": true,
   "hours_public": 5712,
   "clock_origin": "advisory",
   "advisory_date": "2026-01-20",
   "advisory_days_public": 238,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/481830"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-65852",
   "state": "RESERVED",
   "public_date": "2026-02-06",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-02-06",
    "ghsa-repos": "2026-02-06",
    "osv": "2026-02-06"
   },
   "refs": "ghsa-repos:gogs/gogs\tGHSA-rjv5-9px2-fqw6;ghsa:GHSA-rjv5-9px2-fqw6;osv:Go:gogs.io/gogs",
   "description": "Gogs has authorization bypass in repository deletion API",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 221,
   "clock_known": true,
   "hours_public": 5304,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-06",
   "advisory_days_public": 221,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gogs.io/gogs",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-rjv5-9px2-fqw6",
    "ghsa-repos": "https://github.com/gogs/gogs/security/advisories/GHSA-rjv5-9px2-fqw6",
    "osv": "https://osv.dev/list?q=CVE-2025-65852"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-0026",
   "state": "RESERVED",
   "public_date": "2026-02-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-02-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0381\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0381.json",
   "description": "CVE-2025-0026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 217,
   "clock_known": true,
   "hours_public": 5208,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-10",
   "advisory_days_public": 217,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0381.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-25995",
   "state": "RESERVED",
   "public_date": "2026-02-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-11"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-727f-w7gp-pw84",
   "description": "opf/openproject repository advisory GHSA-727f-w7gp-pw84",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 216,
   "clock_known": true,
   "hours_public": 5184,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-11",
   "advisory_days_public": 216,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-727f-w7gp-pw84"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-25948",
   "state": "RESERVED",
   "public_date": "2026-02-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-11"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-8fq7-cmmf-2793",
   "description": "opf/openproject repository advisory GHSA-8fq7-cmmf-2793",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 216,
   "clock_known": true,
   "hours_public": 5184,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-11",
   "advisory_days_public": 216,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-8fq7-cmmf-2793"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-64441",
   "state": "RESERVED",
   "public_date": "2026-02-12",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-08",
    "csaf": "2026-02-12"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:10189-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10189-1.json;ghsa-repos:owncloud/security-advisories\tGHSA-rm46-prxr-79cr",
   "description": "owncloud/security-advisories repository advisory GHSA-rm46-prxr-79cr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 215,
   "clock_known": true,
   "hours_public": 5160,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-12",
   "advisory_days_public": 215,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10189-1.json",
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-rm46-prxr-79cr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-2574",
   "state": "RESERVED",
   "public_date": "2026-02-16",
   "sources": "alas,csaf,debian,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-02-16",
    "redhat": "2026-02-16",
    "csaf": "2026-02-18"
   },
   "refs": "alas:CVE-2026-2574;csaf:SUSE Product Security Team\tCVE-2026-2574\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-2574.json;debian:glib-networking;redhat:CVE-2026-2574",
   "description": "A flaw was found in glib-networking.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 211,
   "clock_known": true,
   "hours_public": 5064,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-16",
   "advisory_days_public": 211,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "glib-networking",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-2574.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-2574.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-2574",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-2574"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27006",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-4fvm-rrc8-mgch",
   "description": "opf/openproject repository advisory GHSA-4fvm-rrc8-mgch",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-4fvm-rrc8-mgch"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26976",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-6m5j-mp2j-cgmm",
   "description": "opf/openproject repository advisory GHSA-6m5j-mp2j-cgmm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-6m5j-mp2j-cgmm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26970",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-jrhg-mx22-57rm",
   "description": "opf/openproject repository advisory GHSA-jrhg-mx22-57rm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-jrhg-mx22-57rm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26971",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-xh2h-jfr6-3qhc",
   "description": "opf/openproject repository advisory GHSA-xh2h-jfr6-3qhc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-xh2h-jfr6-3qhc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26969",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-r4v5-h2fp-fhxf",
   "description": "opf/openproject repository advisory GHSA-r4v5-h2fp-fhxf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-r4v5-h2fp-fhxf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26966",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-5m66-2gm7-6jcc",
   "description": "opf/openproject repository advisory GHSA-5m66-2gm7-6jcc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-5m66-2gm7-6jcc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26968",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-g62r-9rgf-h53q",
   "description": "opf/openproject repository advisory GHSA-g62r-9rgf-h53q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-g62r-9rgf-h53q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27019",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-18"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-r85w-rv9m-q784",
   "description": "opf/openproject repository advisory GHSA-r85w-rv9m-q784",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-r85w-rv9m-q784"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-67832",
   "state": "RESERVED",
   "public_date": "2026-02-18",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-02-18"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0461\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0461.json",
   "description": "CVE-2025-67832",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 209,
   "clock_known": true,
   "hours_public": 5016,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-18",
   "advisory_days_public": 209,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0461.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27164",
   "state": "RESERVED",
   "public_date": "2026-02-21",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-02-21",
    "csaf": "2026-02-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0472\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json;ghsa-repos:openclaw/openclaw\tGHSA-x2g4-7mj7-2hhj",
   "description": "openclaw/openclaw repository advisory GHSA-x2g4-7mj7-2hhj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 206,
   "clock_known": true,
   "hours_public": 4944,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-21",
   "advisory_days_public": 206,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json",
    "ghsa-repos": "https://github.com/openclaw/openclaw/security/advisories/GHSA-x2g4-7mj7-2hhj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27165",
   "state": "RESERVED",
   "public_date": "2026-02-21",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-02-21",
    "csaf": "2026-02-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0472\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json;ghsa-repos:openclaw/openclaw\tGHSA-74xj-763f-264w",
   "description": "openclaw/openclaw repository advisory GHSA-74xj-763f-264w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 206,
   "clock_known": true,
   "hours_public": 4944,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-21",
   "advisory_days_public": 206,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json",
    "ghsa-repos": "https://github.com/openclaw/openclaw/security/advisories/GHSA-74xj-763f-264w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27159",
   "state": "RESERVED",
   "public_date": "2026-02-21",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-02-21",
    "csaf": "2026-02-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0472\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json;ghsa-repos:openclaw/openclaw\tGHSA-xwcr-v472-8hhr",
   "description": "openclaw/openclaw repository advisory GHSA-xwcr-v472-8hhr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 206,
   "clock_known": true,
   "hours_public": 4944,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-21",
   "advisory_days_public": 206,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json",
    "ghsa-repos": "https://github.com/openclaw/openclaw/security/advisories/GHSA-xwcr-v472-8hhr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27158",
   "state": "RESERVED",
   "public_date": "2026-02-21",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-02-21",
    "csaf": "2026-02-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0472\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json;ghsa-repos:openclaw/openclaw\tGHSA-2prf-9cw7-fq62",
   "description": "openclaw/openclaw repository advisory GHSA-2prf-9cw7-fq62",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 206,
   "clock_known": true,
   "hours_public": 4944,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-21",
   "advisory_days_public": 206,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json",
    "ghsa-repos": "https://github.com/openclaw/openclaw/security/advisories/GHSA-2prf-9cw7-fq62"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27209",
   "state": "RESERVED",
   "public_date": "2026-02-21",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-02-21",
    "csaf": "2026-02-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0472\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json;ghsa-repos:openclaw/openclaw\tGHSA-65rx-fvh6-r4h2",
   "description": "openclaw/openclaw repository advisory GHSA-65rx-fvh6-r4h2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 206,
   "clock_known": true,
   "hours_public": 4944,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-21",
   "advisory_days_public": 206,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0472.json",
    "ghsa-repos": "https://github.com/openclaw/openclaw/security/advisories/GHSA-65rx-fvh6-r4h2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-20140",
   "state": "RESERVED",
   "public_date": "2026-02-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-02-23"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0068\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0068.json",
   "description": "CVE-2026-20140",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 204,
   "clock_known": true,
   "hours_public": 4896,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-23",
   "advisory_days_public": 204,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0068.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-20143",
   "state": "RESERVED",
   "public_date": "2026-02-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-02-23"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0068\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0068.json",
   "description": "CVE-2026-20143",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 204,
   "clock_known": true,
   "hours_public": 4896,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-23",
   "advisory_days_public": 204,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0068.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-22802",
   "state": "RESERVED",
   "public_date": "2026-02-24",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-02-24"
   },
   "refs": "alpine:cacti;csaf:SUSE Product Security Team\topenSUSE-SU-2026:10241-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10241-1.json",
   "description": "CVE-2026-22802",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 203,
   "clock_known": true,
   "hours_public": 4872,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-24",
   "advisory_days_public": 203,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-22802",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10241-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39043",
   "state": "RESERVED",
   "public_date": "2026-02-25",
   "sources": "alas,alpine,csaf,debian,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-06-19",
    "ubuntu-osv": "2026-06-17",
    "csaf": "2026-02-25"
   },
   "refs": "alas:CVE-2026-39043;alpine:gst-plugins-good;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0525\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0525.json;debian:gst-plugins-good1.0;ubuntu-osv:UBUNTU-CVE-20",
   "description": "Heap buffer overflow in the Matroska (MKV) demuxer when calculating decompressed buffer sizes for bz2-compressed tracks.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 202,
   "clock_known": true,
   "hours_public": 4848,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-25",
   "advisory_days_public": 202,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gst-plugins-good",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-39043.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39043",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0525.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-39043",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-39043"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39044",
   "state": "RESERVED",
   "public_date": "2026-02-25",
   "sources": "alas,alpine,csaf,debian,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-06-19",
    "ubuntu-osv": "2026-06-17",
    "csaf": "2026-02-25"
   },
   "refs": "alas:CVE-2026-39044;alpine:gst-plugins-good;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0525\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0525.json;debian:gst-plugins-good1.0;ubuntu-osv:UBUNTU-CVE-20",
   "description": "An integer overflow in the WAV parser (wavparse) when handling malformed WAV files with cue chunks.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 202,
   "clock_known": true,
   "hours_public": 4848,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-25",
   "advisory_days_public": 202,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gst-plugins-good",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-39044.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39044",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0525.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-39044",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-39044"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27827",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-v8cr-7x8f-78mq",
   "description": "opf/openproject repository advisory GHSA-v8cr-7x8f-78mq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-v8cr-7x8f-78mq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27817",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-c76v-8735-35hq",
   "description": "opf/openproject repository advisory GHSA-c76v-8735-35hq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-c76v-8735-35hq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27733",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-w9w6-f59w-89vj",
   "description": "opf/openproject repository advisory GHSA-w9w6-f59w-89vj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-w9w6-f59w-89vj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27731",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-3qgp-q2x5-c4jw",
   "description": "opf/openproject repository advisory GHSA-3qgp-q2x5-c4jw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-3qgp-q2x5-c4jw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27722",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-xw8w-4qxm-g9gv",
   "description": "opf/openproject repository advisory GHSA-xw8w-4qxm-g9gv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-xw8w-4qxm-g9gv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27721",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-w92f-h4wh-g4w4",
   "description": "opf/openproject repository advisory GHSA-w92f-h4wh-g4w4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-w92f-h4wh-g4w4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27720",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-xfmm-g339-3x85",
   "description": "opf/openproject repository advisory GHSA-xfmm-g339-3x85",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-xfmm-g339-3x85"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27719",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-7xv7-73x4-qqvp",
   "description": "opf/openproject repository advisory GHSA-7xv7-73x4-qqvp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-7xv7-73x4-qqvp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27717",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-p3hw-5g6p-69f2",
   "description": "opf/openproject repository advisory GHSA-p3hw-5g6p-69f2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-p3hw-5g6p-69f2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27718",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-cxm3-9m5g-9cq4",
   "description": "opf/openproject repository advisory GHSA-cxm3-9m5g-9cq4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-cxm3-9m5g-9cq4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27716",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-qpg6-635j-wjc2",
   "description": "opf/openproject repository advisory GHSA-qpg6-635j-wjc2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-qpg6-635j-wjc2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-27715",
   "state": "RESERVED",
   "public_date": "2026-02-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-02-26"
   },
   "refs": "ghsa-repos:opf/openproject\tGHSA-j4m9-7hff-8qgr",
   "description": "opf/openproject repository advisory GHSA-j4m9-7hff-8qgr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 201,
   "clock_known": true,
   "hours_public": 4824,
   "clock_origin": "advisory",
   "advisory_date": "2026-02-26",
   "advisory_days_public": 201,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opf/openproject/security/advisories/GHSA-j4m9-7hff-8qgr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21735",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-03-03"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0074\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0074.json",
   "description": "CVE-2026-21735",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0074.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71205",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-03-03",
    "zdi": "2026-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0587\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json;zdi:ZDI-26-144",
   "description": "CVE-2025-71205",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-144/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71206",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-03-03",
    "zdi": "2026-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0587\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json;zdi:ZDI-26-145",
   "description": "CVE-2025-71206",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-145/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71207",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-03-03",
    "zdi": "2026-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0587\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json;zdi:ZDI-26-146",
   "description": "CVE-2025-71207",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-146/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71208",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-03-03",
    "zdi": "2026-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0587\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json;zdi:ZDI-26-147",
   "description": "CVE-2025-71208",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-147/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71209",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-03-03",
    "zdi": "2026-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0587\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json;zdi:ZDI-26-148",
   "description": "CVE-2025-71209",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0587.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-148/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-3493",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-03-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0582\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0582.json",
   "description": "CVE-2026-3493",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0582.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71218",
   "state": "RESERVED",
   "public_date": "2026-03-03",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-03-03"
   },
   "refs": "zdi:ZDI-26-149",
   "description": "ZDI advisory ZDI-26-149",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 196,
   "clock_known": true,
   "hours_public": 4704,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-03",
   "advisory_days_public": 196,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-149/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-3836",
   "state": "RESERVED",
   "public_date": "2026-03-09",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-03-26",
    "ubuntu-osv": "2026-03-26",
    "redhat": "2026-03-09",
    "csaf": "2026-04-09"
   },
   "refs": "alas:CVE-2026-3836;csaf:Red Hat Product Security\tRHSA-2026:7349\thttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7349.json;debian:dnf5;redhat:CVE-2026-3836;ubuntu-osv:UBUNTU-CVE-2026-3836",
   "description": "A flaw was found in dnf5.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 190,
   "clock_known": true,
   "hours_public": 4560,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-09",
   "advisory_days_public": 190,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "dnf5",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-3836.html",
    "csaf": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7349.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-3836",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-3836",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-3836"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-26364",
   "state": "RESERVED",
   "public_date": "2026-03-10",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-03-10"
   },
   "refs": "zdi:ZDI-26-177",
   "description": "ZDI advisory ZDI-26-177",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 189,
   "clock_known": true,
   "hours_public": 4536,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-10",
   "advisory_days_public": 189,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-177/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-31977",
   "state": "RESERVED",
   "public_date": "2026-03-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-03-11"
   },
   "refs": "ghsa-repos:HKUDS/nanobot\tGHSA-g6cf-xjwr-pm77",
   "description": "HKUDS/nanobot repository advisory GHSA-g6cf-xjwr-pm77",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 188,
   "clock_known": true,
   "hours_public": 4512,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-11",
   "advisory_days_public": 188,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HKUDS/nanobot/security/advisories/GHSA-g6cf-xjwr-pm77"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-32307",
   "state": "RESERVED",
   "public_date": "2026-03-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-03-12"
   },
   "refs": "ghsa-repos:OneUptime/oneuptime\tGHSA-f5j9-g76m-vvp9",
   "description": "OneUptime/oneuptime repository advisory GHSA-f5j9-g76m-vvp9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 187,
   "clock_known": true,
   "hours_public": 4488,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-12",
   "advisory_days_public": 187,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OneUptime/oneuptime/security/advisories/GHSA-f5j9-g76m-vvp9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-65587",
   "state": "RESERVED",
   "public_date": "2026-03-12",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2026-03-12"
   },
   "refs": "certcc:VU#907705",
   "description": "Graphql-upload-minimal has a prototype pollution vulnerability.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 187,
   "clock_known": true,
   "hours_public": 4488,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-12",
   "advisory_days_public": 187,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/907705"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-3312",
   "state": "RESERVED",
   "public_date": "2026-03-13",
   "sources": "csaf,debian,redhat,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-03-18",
    "redhat": "2026-03-13",
    "csaf": "2026-03-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-3312\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3312.json;debian:pagure;redhat:CVE-2026-3312;ubuntu-osv:UBUNTU-CVE-2026-3312",
   "description": "pagure",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 186,
   "clock_known": true,
   "hours_public": 4464,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-13",
   "advisory_days_public": 186,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "pagure",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3312.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-3312",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-3312",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-3312"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-2046",
   "state": "RESERVED",
   "public_date": "2026-03-16",
   "sources": "alas,csaf,debian,ubuntu-osv,zdi",
   "feed_count": 5,
   "dates": {
    "alas": "2026-03-20",
    "ubuntu-osv": "2026-03-19",
    "csaf": "2026-03-18",
    "zdi": "2026-03-16"
   },
   "refs": "alas:CVE-2026-2046;csaf:SUSE Product Security Team\tCVE-2026-2046\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-2046.json;debian:gimp;ubuntu-osv:UBUNTU-CVE-2026-2046;zdi:ZDI-26-213",
   "description": "GIMP LBM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 183,
   "clock_known": true,
   "hours_public": 4392,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-16",
   "advisory_days_public": 183,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-2046.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-2046.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-2046",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-2046",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-213/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-59490",
   "state": "RESERVED",
   "public_date": "2026-03-25",
   "sources": "csaf,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-03-30",
    "csaf": "2026-03-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0876\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0876.json;debian:znuny;ubuntu-osv:UBUNTU-CVE-2025-59490",
   "description": "znuny",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 174,
   "clock_known": true,
   "hours_public": 4176,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-25",
   "advisory_days_public": 174,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "znuny",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0876.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2025-59490",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2025-59490"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-59393",
   "state": "RESERVED",
   "public_date": "2026-03-25",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-03-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0876\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0876.json",
   "description": "CVE-2025-59393",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 174,
   "clock_known": true,
   "hours_public": 4176,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-25",
   "advisory_days_public": 174,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0876.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-33864",
   "state": "RESERVED",
   "public_date": "2026-03-26",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-03-26",
    "osv": "2026-03-26"
   },
   "refs": "ghsa:GHSA-44fc-8fm5-q62h;osv:npm:convict",
   "description": "Convict has Prototype Pollution via startsWith() function",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 173,
   "clock_known": true,
   "hours_public": 4152,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-26",
   "advisory_days_public": 173,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "convict",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-44fc-8fm5-q62h",
    "osv": "https://osv.dev/list?q=CVE-2026-33864"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-33863",
   "state": "RESERVED",
   "public_date": "2026-03-26",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-03-26",
    "osv": "2026-03-26"
   },
   "refs": "ghsa:GHSA-hf2r-9gf9-rwch;osv:npm:convict",
   "description": "Convict has prototype pollution via load(), loadFile(), and schema initialization",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 173,
   "clock_known": true,
   "hours_public": 4152,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-26",
   "advisory_days_public": 173,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "convict",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hf2r-9gf9-rwch",
    "osv": "https://osv.dev/list?q=CVE-2026-33863"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-4981",
   "state": "RESERVED",
   "public_date": "2026-03-27",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-03-27",
    "csaf": "2026-03-27"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-4981\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4981.json;redhat:CVE-2026-4981",
   "description": "rhacs: Red Hat Advanced Cluster Security (ACS): Open Redirect and Content Spoofing via OAuth callback endpoint",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 172,
   "clock_known": true,
   "hours_public": 4128,
   "clock_origin": "advisory",
   "advisory_date": "2026-03-27",
   "advisory_days_public": 172,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-4981",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4981.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-4981"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0058",
   "state": "RESERVED",
   "public_date": "2026-04-01",
   "sources": "csaf,samsung",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-04-06",
    "samsung": "2026-04-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-0974\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0974.json;samsung:SMR-Apr-2026",
   "description": "CVE-2026-0058",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 167,
   "clock_known": true,
   "hours_public": 4008,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-01",
   "advisory_days_public": 167,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0974.json",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-20713",
   "state": "RESERVED",
   "public_date": "2026-04-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-04-01"
   },
   "refs": "samsung:SMR-Apr-2026",
   "description": "Samsung SMR Apr 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 167,
   "clock_known": true,
   "hours_public": 4008,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-01",
   "advisory_days_public": 167,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-30762",
   "state": "RESERVED",
   "public_date": "2026-04-02",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-04-04",
    "ghsa-repos": "2026-04-02",
    "osv": "2026-04-04"
   },
   "refs": "ghsa-repos:HKUDS/LightRAG\tGHSA-mcww-4hxq-hfr3;ghsa:GHSA-mcww-4hxq-hfr3;osv:PyPI:lightrag-hku",
   "description": "LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 166,
   "clock_known": true,
   "hours_public": 3984,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-02",
   "advisory_days_public": 166,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "lightrag-hku",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-mcww-4hxq-hfr3",
    "ghsa-repos": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-mcww-4hxq-hfr3",
    "osv": "https://osv.dev/list?q=CVE-2026-30762"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-1403",
   "state": "RESERVED",
   "public_date": "2026-04-08",
   "sources": "csaf,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-04-09",
    "csaf": "2026-04-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1010\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1010.json;ubuntu-osv:UBUNTU-CVE-2026-1403",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 160,
   "clock_known": true,
   "hours_public": 3840,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-08",
   "advisory_days_public": 160,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1010.json",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-1403"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-65016",
   "state": "RESERVED",
   "public_date": "2026-04-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-04-09"
   },
   "refs": "ghsa-repos:eProsima/Fast-DDS\tGHSA-7r5r-66jr-gwrw",
   "description": "eProsima/Fast-DDS repository advisory GHSA-7r5r-66jr-gwrw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 159,
   "clock_known": true,
   "hours_public": 3816,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-09",
   "advisory_days_public": 159,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7r5r-66jr-gwrw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-3865",
   "state": "RESERVED",
   "public_date": "2026-04-10",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-04-10",
    "csaf": "2026-04-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1051\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1051.json;redhat:CVE-2026-3865",
   "description": "csi-driver-smb: Kubernetes CSI Driver for SMB: Path Traversal vulnerability allows unauthorized file operations via insufficient subDir validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 158,
   "clock_known": true,
   "hours_public": 3792,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-10",
   "advisory_days_public": 158,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-3865",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1051.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-3865"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58387",
   "state": "RESERVED",
   "public_date": "2026-04-11",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-08",
    "ubuntu-osv": "2026-07-09",
    "redhat": "2026-04-11",
    "csaf": "2026-07-06"
   },
   "refs": "alas:CVE-2026-58387;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2219\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2219.json;debian:gimp;redhat:CVE-2026-58387;ubuntu-osv:UBUNTU-CVE-2026-58387",
   "description": "A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 157,
   "clock_known": true,
   "hours_public": 3768,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-11",
   "advisory_days_public": 157,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58387.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2219.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58387",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58387",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58387"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58382",
   "state": "RESERVED",
   "public_date": "2026-04-11",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-08",
    "ubuntu-osv": "2026-07-09",
    "redhat": "2026-04-11",
    "csaf": "2026-07-09"
   },
   "refs": "alas:CVE-2026-58382;csaf:SUSE Product Security Team\tCVE-2026-58382\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-58382.json;debian:gimp;redhat:CVE-2026-58382;ubuntu-osv:UBUNTU-CVE-2026-58382",
   "description": "A flaw was found in GIMP's Jeff's Image Format (JIF) parser.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 157,
   "clock_known": true,
   "hours_public": 3768,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-11",
   "advisory_days_public": 157,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58382.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-58382.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58382",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58382",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58382"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58386",
   "state": "RESERVED",
   "public_date": "2026-04-11",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-08",
    "ubuntu-osv": "2026-07-09",
    "redhat": "2026-04-11",
    "csaf": "2026-07-07"
   },
   "refs": "alas:CVE-2026-58386;csaf:SUSE Product Security Team\tCVE-2026-58386\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-58386.json;debian:gimp;redhat:CVE-2026-58386;ubuntu-osv:UBUNTU-CVE-2026-58386",
   "description": "A flaw was found in GIMP's TIM loader.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 157,
   "clock_known": true,
   "hours_public": 3768,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-11",
   "advisory_days_public": 157,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58386.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-58386.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58386",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58386",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58386"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58388",
   "state": "RESERVED",
   "public_date": "2026-04-11",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-08",
    "ubuntu-osv": "2026-07-09",
    "redhat": "2026-04-11",
    "csaf": "2026-07-07"
   },
   "refs": "alas:CVE-2026-58388;csaf:SUSE Product Security Team\tCVE-2026-58388\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-58388.json;debian:gimp;redhat:CVE-2026-58388;ubuntu-osv:UBUNTU-CVE-2026-58388",
   "description": "A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 157,
   "clock_known": true,
   "hours_public": 3768,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-11",
   "advisory_days_public": 157,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58388.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-58388.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58388",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58388",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58388"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58383",
   "state": "RESERVED",
   "public_date": "2026-04-11",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-08",
    "ubuntu-osv": "2026-07-09",
    "redhat": "2026-04-11",
    "csaf": "2026-07-06"
   },
   "refs": "alas:CVE-2026-58383;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2219\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2219.json;debian:gimp;redhat:CVE-2026-58383;ubuntu-osv:UBUNTU-CVE-2026-58383",
   "description": "A flaw was found in GIMP's Jeff's Image Format (JIF) parser.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 157,
   "clock_known": true,
   "hours_public": 3768,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-11",
   "advisory_days_public": 157,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58383.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2219.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58383",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58383",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58383"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58385",
   "state": "RESERVED",
   "public_date": "2026-04-11",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-07",
    "ubuntu-osv": "2026-07-09",
    "redhat": "2026-04-11",
    "csaf": "2026-07-06"
   },
   "refs": "alas:CVE-2026-58385;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2219\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2219.json;debian:gimp;redhat:CVE-2026-58385;ubuntu-osv:UBUNTU-CVE-2026-58385",
   "description": "A flaw was found in GIMP's PVR decoder.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 157,
   "clock_known": true,
   "hours_public": 3768,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-11",
   "advisory_days_public": 157,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gimp",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58385.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2219.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58385",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58385",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58385"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-6856",
   "state": "RESERVED",
   "public_date": "2026-04-13",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-04-13",
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1238\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1238.json;redhat:CVE-2026-6856",
   "description": "keycloak: keycloak: acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 155,
   "clock_known": true,
   "hours_public": 3720,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-13",
   "advisory_days_public": 155,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-6856",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1238.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-6856"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-4036",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-4036",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40530",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40530",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40531",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40531",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40532",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40532",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40533",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40533",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40534",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40534",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40535",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40535",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40536",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40536",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40537",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40537",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40538",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40538",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40539",
   "state": "RESERVED",
   "public_date": "2026-04-14",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1125\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json",
   "description": "CVE-2026-40539",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 154,
   "clock_known": true,
   "hours_public": 3696,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-14",
   "advisory_days_public": 154,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1125.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-32179",
   "state": "RESERVED",
   "public_date": "2026-04-15",
   "sources": "alpine,ghsa,ghsa-repos,osv",
   "feed_count": 4,
   "dates": {
    "ghsa": "2026-04-16",
    "ghsa-repos": "2026-04-15",
    "osv": "2026-04-16"
   },
   "refs": "alpine:libmsquic;ghsa-repos:microsoft/msquic\tGHSA-gvvw-8j96-8g5r;ghsa:GHSA-gvvw-8j96-8g5r;osv:NuGet:Microsoft.Native.Quic.MsQuic.OpenSSL",
   "description": "MsQuic has a Remote Elevation of Privilege Vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 153,
   "clock_known": true,
   "hours_public": 3672,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-15",
   "advisory_days_public": 153,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libmsquic",
   "ecosystem": "NuGet",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-32179",
    "ghsa": "https://github.com/advisories/GHSA-gvvw-8j96-8g5r",
    "ghsa-repos": "https://github.com/microsoft/msquic/security/advisories/GHSA-gvvw-8j96-8g5r",
    "osv": "https://osv.dev/list?q=CVE-2026-32179"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5424",
   "state": "RESERVED",
   "public_date": "2026-04-15",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-04-15"
   },
   "refs": "zdi:ZDI-26-271",
   "description": "ZDI advisory ZDI-26-271",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 153,
   "clock_known": true,
   "hours_public": 3672,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-15",
   "advisory_days_public": 153,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-271/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-6434",
   "state": "RESERVED",
   "public_date": "2026-04-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-17"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-6434\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6434.json",
   "description": "rust-coreutils: rust-coreutils: Information disclosure via insecure temporary file permissions and improper cleanup in `uu_sort`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 151,
   "clock_known": true,
   "hours_public": 3624,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-17",
   "advisory_days_public": 151,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6434.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-6435",
   "state": "RESERVED",
   "public_date": "2026-04-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-17"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-6435\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6435.json",
   "description": "rust-coreutils: rust-coreutils: Arbitrary file permission modification via TOCTOU race in chmod symbolic link traversal",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 151,
   "clock_known": true,
   "hours_public": 3624,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-17",
   "advisory_days_public": 151,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6435.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-22020",
   "state": "RESERVED",
   "public_date": "2026-04-21",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-04-27",
    "ubuntu-osv": "2026-04-28",
    "redhat": "2026-04-21",
    "csaf": "2026-04-21"
   },
   "refs": "alas:CVE-2026-22020;csaf:Red Hat Product Security\tCVE-2026-22020\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22020.json;debian:openjdk-11;redhat:CVE-2026-22020;ubuntu-osv:UBUNTU-CVE-2026-22020",
   "description": "Updated libpng in Oracle Java.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 147,
   "clock_known": true,
   "hours_public": 3528,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-21",
   "advisory_days_public": 147,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "openjdk-11",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-22020.html",
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22020.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-22020",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-22020",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-22020"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54877",
   "state": "RESERVED",
   "public_date": "2026-04-21",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-21"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54877\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54877.json",
   "description": "ofono: ofono: double-free vulnerability in cbs_assembly_expire()",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 147,
   "clock_known": true,
   "hours_public": 3528,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-21",
   "advisory_days_public": 147,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54877.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35328",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-26"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\topenSUSE-SU-2026:10623-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10623-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35328",
   "description": "Infinite Loop When Handling Supported Versions TLS Extension",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-26",
   "advisory_days_public": 142,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35328",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10623-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35328",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35328"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35329",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-27"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\tSUSE-SU-2026:1637-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35329",
   "description": "NULL-Pointer Dereference When Processing Padding in PKCS#7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35329",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35329",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35329"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35331",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-27"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\tSUSE-SU-2026:1637-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35331",
   "description": "Accepting Certificates Violating Name Constraints",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35331",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35331",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35331"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35330",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-27"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\tSUSE-SU-2026:1637-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35330",
   "description": "Integer Underflow When Handling EAP-SIM/AKA Attributes",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35330",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35330",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35330"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35334",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-27"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\tSUSE-SU-2026:1637-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35334",
   "description": "Possible NULL-Pointer Dereference in RSA Decryption",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35334",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35334",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35334"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35333",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-27"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\tSUSE-SU-2026:1637-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35333",
   "description": "Integer Underflow When Handling RADIUS Attributes",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35333",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_1637-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35333",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35333"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35332",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-04-22",
    "csaf": "2026-04-26"
   },
   "refs": "alpine:strongswan;csaf:SUSE Product Security Team\topenSUSE-SU-2026:10623-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10623-1.json;debian:strongswan;ubuntu-osv:UBUNTU-CVE-2026-35332",
   "description": "NULL-Pointer Dereference When Handling ECDH Public Value in TLS",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-26",
   "advisory_days_public": 142,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "strongswan",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35332",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10623-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35332",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35332"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54878",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54878\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54878.json",
   "description": "ofono: ofono: stack-based buffer overflow in get_smsc_addr_cb()",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-22",
   "advisory_days_public": 146,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54878.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54879",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54879\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54879.json",
   "description": "ofono: ofono: stack-based buffer overflow in cusd_parse() via GSM 7-bit packing",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-22",
   "advisory_days_public": 146,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54879.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54880",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54880\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54880.json",
   "description": "ofono: ofono: stack-based buffer overflow in huawei_nwtime_notify() via sscanf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-22",
   "advisory_days_public": 146,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54880.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54881",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54881\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54881.json",
   "description": "ofono: ofono: heap-based buffer overflow in scan_nets_cb() via QMI network scan",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-22",
   "advisory_days_public": 146,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54881.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54882",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54882\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54882.json",
   "description": "ofono: ofono: stack-based buffer overflow in tlts_notify() via sscanf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-22",
   "advisory_days_public": 146,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54882.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54883",
   "state": "RESERVED",
   "public_date": "2026-04-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-54883\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54883.json",
   "description": "ofono: ofono: heap-based buffer overflow in HDLC decoder new_bytes()",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 146,
   "clock_known": true,
   "hours_public": 3504,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-22",
   "advisory_days_public": 146,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54883.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5744",
   "state": "RESERVED",
   "public_date": "2026-04-23",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-04-27",
    "ubuntu-osv": "2026-04-23"
   },
   "refs": "alas:CVE-2026-5744;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-5744",
   "description": "hw/uefi: heap overflow",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 145,
   "clock_known": true,
   "hours_public": 3480,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-5744.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-5744",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-5744"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5763",
   "state": "RESERVED",
   "public_date": "2026-04-23",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-04-27",
    "ubuntu-osv": "2026-04-23"
   },
   "refs": "alas:CVE-2026-5763;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-5763",
   "description": "virtio-scsi request size mismatch",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 145,
   "clock_known": true,
   "hours_public": 3480,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-27",
   "advisory_days_public": 141,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-5763.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-5763",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-5763"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-3890",
   "state": "RESERVED",
   "public_date": "2026-04-23",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-04-24",
    "ubuntu-osv": "2026-04-23"
   },
   "refs": "alas:CVE-2026-3890;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-3890",
   "description": "hcd-ohci: infinite loop",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 145,
   "clock_known": true,
   "hours_public": 3480,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-24",
   "advisory_days_public": 144,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-3890.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-3890",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-3890"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5761",
   "state": "RESERVED",
   "public_date": "2026-04-23",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-04-24",
    "ubuntu-osv": "2026-04-23"
   },
   "refs": "alas:CVE-2026-5761;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-5761",
   "description": "An internal buffer is used when processing VIRTIO_BLK_T_ZONE_REPORT requests.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 145,
   "clock_known": true,
   "hours_public": 3480,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-24",
   "advisory_days_public": 144,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-5761.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-5761",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-5761"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40540",
   "state": "RESERVED",
   "public_date": "2026-04-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1261\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1261.json",
   "description": "CVE-2026-40540",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 145,
   "clock_known": true,
   "hours_public": 3480,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-23",
   "advisory_days_public": 145,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1261.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40475",
   "state": "RESERVED",
   "public_date": "2026-04-28",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-04-28"
   },
   "refs": "alpine:py3-openssl;csaf:SUSE Product Security Team\topenSUSE-SU-2026:10646-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10646-1.json",
   "description": "CVE-2026-40475",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 140,
   "clock_known": true,
   "hours_public": 3360,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-28",
   "advisory_days_public": 140,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "py3-openssl",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-40475",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10646-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-33090",
   "state": "RESERVED",
   "public_date": "2026-04-29",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-04-29"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1322\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1322.json",
   "description": "CVE-2026-33090",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 139,
   "clock_known": true,
   "hours_public": 3336,
   "clock_origin": "advisory",
   "advisory_date": "2026-04-29",
   "advisory_days_public": 139,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1322.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0062",
   "state": "RESERVED",
   "public_date": "2026-05-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-05-01"
   },
   "refs": "samsung:SMR-May-2026",
   "description": "Samsung SMR May 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 137,
   "clock_known": true,
   "hours_public": 3288,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-01",
   "advisory_days_public": 137,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-6502",
   "state": "RESERVED",
   "public_date": "2026-05-06",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-05-07",
    "ubuntu-osv": "2026-05-06"
   },
   "refs": "alas:CVE-2026-6502;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-6502",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 132,
   "clock_known": true,
   "hours_public": 3168,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-07",
   "advisory_days_public": 131,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-6502.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-6502",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-6502"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46626",
   "state": "RESERVED",
   "public_date": "2026-05-20",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-05-21",
    "ghsa-repos": "2026-05-20"
   },
   "refs": "debian:symfony;ghsa-repos:symfony/symfony\tGHSA-fqc7-9xjw-jrh3;ubuntu-osv:UBUNTU-CVE-2026-46626",
   "description": "symfony",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 118,
   "clock_known": true,
   "hours_public": 2832,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-20",
   "advisory_days_public": 118,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "symfony",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-46626",
    "ghsa-repos": "https://github.com/symfony/symfony/security/advisories/GHSA-fqc7-9xjw-jrh3",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-46626"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45355",
   "state": "RESERVED",
   "public_date": "2026-05-20",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-05-20",
    "ghsa-repos": "2026-07-12"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-r72w-vfv6-52wg;ubuntu-osv:UBUNTU-CVE-2026-45355",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 118,
   "clock_known": true,
   "hours_public": 2832,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-12",
   "advisory_days_public": 65,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-45355",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45355",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-r72w-vfv6-52wg",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45355"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45354",
   "state": "RESERVED",
   "public_date": "2026-05-20",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-05-20",
    "ghsa-repos": "2026-07-12"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-x7mm-865g-6jp3;ubuntu-osv:UBUNTU-CVE-2026-45354",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 118,
   "clock_known": true,
   "hours_public": 2832,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-12",
   "advisory_days_public": 65,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-45354",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45354",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-x7mm-865g-6jp3",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45354"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45356",
   "state": "RESERVED",
   "public_date": "2026-05-20",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-05-20",
    "ghsa-repos": "2026-07-12"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-9963-q595-wm2x;ubuntu-osv:UBUNTU-CVE-2026-45356",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 118,
   "clock_known": true,
   "hours_public": 2832,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-12",
   "advisory_days_public": 65,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-45356",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45356",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-9963-q595-wm2x",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45356"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42783",
   "state": "RESERVED",
   "public_date": "2026-05-21",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-05-21"
   },
   "refs": "debian:rust-sequoia-openpgp;ubuntu-osv:UBUNTU-CVE-2026-42783",
   "description": "[openpgp: Don&#x27;t imply missing key flags from key type]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 117,
   "clock_known": true,
   "hours_public": 2808,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "rust-sequoia-openpgp",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-42783",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-42783"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42784",
   "state": "RESERVED",
   "public_date": "2026-05-22",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-05-22"
   },
   "refs": "debian:rust-sequoia-openpgp;ubuntu-osv:UBUNTU-CVE-2026-42784",
   "description": "[openpgp: Don&#x27;t imply missing key flags from key type]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 116,
   "clock_known": true,
   "hours_public": 2784,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "rust-sequoia-openpgp",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-42784",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-42784"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57964",
   "state": "RESERVED",
   "public_date": "2026-05-27",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-30",
    "redhat": "2026-05-27",
    "csaf": "2026-05-27"
   },
   "refs": "alas:CVE-2026-57964;csaf:Red Hat Product Security\tCVE-2026-57964\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57964.json;debian:spice-vdagent;redhat:CVE-2026-57964;ubuntu-osv:UBUNTU-CVE-2026-57964",
   "description": "A flaw was found in spice-vdagent.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 111,
   "clock_known": true,
   "hours_public": 2664,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-27",
   "advisory_days_public": 111,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "spice-vdagent",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-57964.html",
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57964.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57964",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-57964",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57964"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26843",
   "state": "RESERVED",
   "public_date": "2026-05-27",
   "sources": "csaf,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-05-29",
    "csaf": "2026-05-27"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1717\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1717.json;debian:znuny;ubuntu-osv:UBUNTU-CVE-2025-26843",
   "description": "znuny",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 111,
   "clock_known": true,
   "hours_public": 2664,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-27",
   "advisory_days_public": 111,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "znuny",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1717.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2025-26843",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2025-26843"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46352",
   "state": "RESERVED",
   "public_date": "2026-05-28",
   "sources": "csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-06-02",
    "csaf": "2026-05-28"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:10885-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10885-1.json;debian:suricata;ghsa-repos:OISF/suricata\tGHSA-rc34-46x6-mxxm;ubuntu-osv:UBUNTU-CVE-2026-46352;ubuntu:CVE-2026-46352",
   "description": "[defrag: fragmented encapsulated traffic with fragments can lead to deadlock]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 110,
   "clock_known": true,
   "hours_public": 2640,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-28",
   "advisory_days_public": 110,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10885-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-46352",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-rc34-46x6-mxxm",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-46352",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-46352"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-13745",
   "state": "RESERVED",
   "public_date": "2026-05-29",
   "sources": "alas,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-05-29",
    "ubuntu-osv": "2026-05-29",
    "csaf": "2026-05-30"
   },
   "refs": "alas:CVE-2024-13745;csaf:SUSE Product Security Team\tCVE-2024-13745\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-13745.json;debian:edk2;ubuntu-osv:UBUNTU-CVE-2024-13745",
   "description": "The bug allows an attacker to make the TPM record and measure one partition table layout while the firmware and operating system actually use a different layout.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 109,
   "clock_known": true,
   "hours_public": 2616,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-29",
   "advisory_days_public": 109,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "edk2",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2024-13745.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2024-13745.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2024-13745",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2024-13745"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-38739",
   "state": "RESERVED",
   "public_date": "2026-05-29",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-05-29",
    "osv": "2026-05-29"
   },
   "refs": "ghsa:GHSA-xg9x-h37w-h3r3;osv:Packagist:ezsystems/ezpublish-legacy",
   "description": "ezsystems/ezpublish-legacy has a SQL injection in dfscleanup",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 109,
   "clock_known": true,
   "hours_public": 2616,
   "clock_origin": "advisory",
   "advisory_date": "2026-05-29",
   "advisory_days_public": 109,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ezsystems/ezpublish-legacy",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-xg9x-h37w-h3r3",
    "osv": "https://osv.dev/list?q=CVE-2026-38739"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41437",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-41437;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-41437",
   "description": "Potential out-of-bound read.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-41437.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-41437",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-41437"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41435",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-41435;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-41435",
   "description": "Qemu buffer overrun in hw/uefi",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-41435.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-41435",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-41435"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-8341",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-8341;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-8341",
   "description": "Qemu integer underflow in hw/uefi",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-8341.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-8341",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-8341"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41440",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-41440;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-41440",
   "description": "hw/uefi: add var-service-auth.c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-41440.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-41440",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-41440"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41439",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-41439;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-41439",
   "description": "hw/uefi: verify data size before accessing it in wrap_pkcs7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-41439.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-41439",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-41439"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41436",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-41436;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-41436",
   "description": "hw/uefi: verify pio_xfer_offset before calculating buffer checksum",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-41436.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-41436",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-41436"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49390",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-01",
    "ghsa-repos": "2026-07-27"
   },
   "refs": "alas:CVE-2026-49390;alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-mr8x-76wr-q995;ubuntu-osv:UBUNTU-CVE-2026-49390",
   "description": "The server quantum option in afp.conf is not range-validated during configuration parsing.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-49390.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-49390",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49390",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-mr8x-76wr-q995",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49390"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41438",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-06-01",
    "ubuntu-osv": "2026-06-02"
   },
   "refs": "alas:CVE-2026-41438;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-41438",
   "description": "The vulnerability is a 16-bit integer wrap: when sizeof(*pe) + lv->name_size exceeds UINT16_MAX, the pe->size field (uint16_t) wraps, leading to memory corruption in the QEMU process.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-41438.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-41438",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-41438"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49387",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-06-01",
    "ghsa-repos": "2026-07-27"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-32jr-2xqg-gv48;ubuntu-osv:UBUNTU-CVE-2026-49387",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-49387",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49387",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-32jr-2xqg-gv48",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49387"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49388",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-06-01",
    "ghsa-repos": "2026-07-27"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-5fvw-g64v-r556;ubuntu-osv:UBUNTU-CVE-2026-49388",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-49388",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49388",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-5fvw-g64v-r556",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49388"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49389",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-06-01",
    "ghsa-repos": "2026-07-27"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-xxv4-7f4m-g2g9;ubuntu-osv:UBUNTU-CVE-2026-49389",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-49389",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49389",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-xxv4-7f4m-g2g9",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49389"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54355",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-01"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-xqj6-vjqr-33vv",
   "description": "MapServer/MapServer repository advisory GHSA-xqj6-vjqr-33vv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-xqj6-vjqr-33vv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54354",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-01"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-xp29-8wp5-wc3p",
   "description": "MapServer/MapServer repository advisory GHSA-xp29-8wp5-wc3p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-xp29-8wp5-wc3p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28574",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android:platform/packages/modules/Nfc;samsung:SMR-Jun-2026",
   "description": "In onServiceConnected of HostEmulationManager.java, there is a possible way to perform BAL due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/packages/modules/Nfc",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-28574",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21538",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21538",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21538",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21541",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21541",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21541",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21542",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21542",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21542",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21545",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21545",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21545",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21539",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21539",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21539",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21540",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21540",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21540",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21543",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21543",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21543",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21544",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21544",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21544",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21546",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-01",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1772\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21546",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1772.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21546",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-21547",
   "state": "RESERVED",
   "public_date": "2026-06-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-06-01",
    "csaf": "2026-06-02",
    "samsung": "2026-06-01"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0173\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0173.json;osv:Android::unknown:;samsung:SMR-Jun-2026",
   "description": "CVE-2026-21547",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 106,
   "clock_known": true,
   "hours_public": 2544,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-01",
   "advisory_days_public": 106,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0173.json",
    "osv": "https://osv.dev/list?q=CVE-2026-21547",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11053",
   "state": "RESERVED",
   "public_date": "2026-06-02",
   "sources": "csaf,debian,msrc,redhat",
   "feed_count": 4,
   "dates": {
    "redhat": "2026-06-02",
    "csaf": "2026-06-05",
    "msrc": "2026-06-09"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:10958-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10958-1.json;debian:chromium;msrc:msrc:2026-Jun;redhat:CVE-2026-11053",
   "description": "chromium-browser: chromium-browser: VULNERABILITY in WebRTC",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 105,
   "clock_known": true,
   "hours_public": 2520,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-02",
   "advisory_days_public": 105,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "chromium",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10958-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-11053",
    "msrc": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11053",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-11053"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11099",
   "state": "RESERVED",
   "public_date": "2026-06-02",
   "sources": "csaf,debian,msrc,redhat",
   "feed_count": 4,
   "dates": {
    "redhat": "2026-06-02",
    "csaf": "2026-06-05",
    "msrc": "2026-06-09"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:10958-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10958-1.json;debian:chromium;msrc:msrc:2026-Jun;redhat:CVE-2026-11099",
   "description": "chromium-browser: skia: chromium-browser: skia: Vulnerability in Skia",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 105,
   "clock_known": true,
   "hours_public": 2520,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-02",
   "advisory_days_public": 105,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "chromium",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_10958-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-11099",
    "msrc": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11099",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-11099"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-10615",
   "state": "RESERVED",
   "public_date": "2026-06-02",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1781\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1781.json",
   "description": "CVE-2026-10615",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 105,
   "clock_known": true,
   "hours_public": 2520,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-02",
   "advisory_days_public": 105,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1781.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-8462",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-04",
    "osv": "2026-06-04"
   },
   "refs": "ghsa:GHSA-wc3v-3457-c8cm;osv:Go:github.com/openmeterio/openmeter",
   "description": "OpenMeter: SQL injection through meter creation",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/openmeterio/openmeter",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-wc3v-3457-c8cm",
    "osv": "https://osv.dev/list?q=CVE-2026-8462"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49292",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-07-02",
    "ghsa-repos": "2026-06-04",
    "osv": "2026-07-02"
   },
   "refs": "ghsa-repos:kiwitcms/Kiwi\tGHSA-v8rp-6xcv-fwgh;ghsa:GHSA-v8rp-6xcv-fwgh;osv:PyPI:kiwitcms",
   "description": "Kiwi TCMS's /init-db/ page renders and responds to requests after first use",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "kiwitcms",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-v8rp-6xcv-fwgh",
    "ghsa-repos": "https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-v8rp-6xcv-fwgh",
    "osv": "https://osv.dev/list?q=CVE-2026-49292"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50291",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-04"
   },
   "refs": "ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-q3c7-3225-66h7",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-q3c7-3225-66h7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-q3c7-3225-66h7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50022",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-04"
   },
   "refs": "ghsa-repos:NCEAS/metacat\tGHSA-57g5-qq6w-7jr8",
   "description": "NCEAS/metacat repository advisory GHSA-57g5-qq6w-7jr8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/NCEAS/metacat/security/advisories/GHSA-57g5-qq6w-7jr8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54337",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-04"
   },
   "refs": "ghsa-repos:ShaneIsrael/fireshare\tGHSA-hmh2-6g84-q8jx",
   "description": "ShaneIsrael/fireshare repository advisory GHSA-hmh2-6g84-q8jx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54343",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-04"
   },
   "refs": "ghsa-repos:frappe/lms\tGHSA-3mq2-3c8v-m92j",
   "description": "frappe/lms repository advisory GHSA-3mq2-3c8v-m92j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/lms/security/advisories/GHSA-3mq2-3c8v-m92j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54462",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-04"
   },
   "refs": "ghsa-repos:knative/pkg\tGHSA-2hw4-c9m4-f2fj",
   "description": "knative/pkg repository advisory GHSA-2hw4-c9m4-f2fj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/knative/pkg/security/advisories/GHSA-2hw4-c9m4-f2fj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54460",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-04"
   },
   "refs": "ghsa-repos:open-reception/appointment-booking-software\tGHSA-g233-m625-m3pc",
   "description": "open-reception/appointment-booking-software repository advisory GHSA-g233-m625-m3pc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-g233-m625-m3pc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-10040",
   "state": "RESERVED",
   "public_date": "2026-06-04",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-04"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1789\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1789.json",
   "description": "CVE-2026-10040",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 103,
   "clock_known": true,
   "hours_public": 2472,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-04",
   "advisory_days_public": 103,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1789.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53954",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-05",
    "osv": "2026-06-05"
   },
   "refs": "ghsa:GHSA-5x67-j5xg-c5gj;osv:PyPI:bugsink",
   "description": "Bugsink: DOS using large numbers of event tags",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "bugsink",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-5x67-j5xg-c5gj",
    "osv": "https://osv.dev/list?q=CVE-2026-53954"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45726",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-05",
    "osv": "2026-06-05"
   },
   "refs": "ghsa:GHSA-wv8c-6mx2-xf4j;osv:Go:github.com/siderolabs/omni",
   "description": "Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/siderolabs/omni",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-wv8c-6mx2-xf4j",
    "osv": "https://osv.dev/list?q=CVE-2026-45726"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45723",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-05",
    "osv": "2026-06-05"
   },
   "refs": "ghsa:GHSA-c66c-vq6w-fvh5;osv:Go:github.com/siderolabs/omni",
   "description": "Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/siderolabs/omni",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-c66c-vq6w-fvh5",
    "osv": "https://osv.dev/list?q=CVE-2026-45723"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45720",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-05",
    "osv": "2026-06-05"
   },
   "refs": "ghsa:GHSA-5x9f-6vg5-qg4m;osv:Go:github.com/siderolabs/omni",
   "description": "Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/siderolabs/omni",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-5x9f-6vg5-qg4m",
    "osv": "https://osv.dev/list?q=CVE-2026-45720"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50275",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-05"
   },
   "refs": "ghsa-repos:DataDog/dd-trace-php\tGHSA-phwx-ww2p-cv9v",
   "description": "DataDog/dd-trace-php repository advisory GHSA-phwx-ww2p-cv9v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/DataDog/dd-trace-php/security/advisories/GHSA-phwx-ww2p-cv9v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54524",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-05"
   },
   "refs": "ghsa-repos:frappe/hrms\tGHSA-2gv7-x4h2-3737",
   "description": "frappe/hrms repository advisory GHSA-2gv7-x4h2-3737",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/hrms/security/advisories/GHSA-2gv7-x4h2-3737"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54510",
   "state": "RESERVED",
   "public_date": "2026-06-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-05"
   },
   "refs": "ghsa-repos:murtaza-nasir/speakr\tGHSA-x4q4-3ww4-h329",
   "description": "murtaza-nasir/speakr repository advisory GHSA-x4q4-3ww4-h329",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 102,
   "clock_known": true,
   "hours_public": 2448,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-05",
   "advisory_days_public": 102,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/murtaza-nasir/speakr/security/advisories/GHSA-x4q4-3ww4-h329"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54571",
   "state": "RESERVED",
   "public_date": "2026-06-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-06"
   },
   "refs": "ghsa-repos:ESP32Async/ESPAsyncWebServer\tGHSA-4phx-fcj6-46r4",
   "description": "ESP32Async/ESPAsyncWebServer repository advisory GHSA-4phx-fcj6-46r4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 101,
   "clock_known": true,
   "hours_public": 2424,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-06",
   "advisory_days_public": 101,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ESP32Async/ESPAsyncWebServer/security/advisories/GHSA-4phx-fcj6-46r4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54597",
   "state": "RESERVED",
   "public_date": "2026-06-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-06"
   },
   "refs": "ghsa-repos:itflow-org/itflow\tGHSA-m63v-j7fw-hq2h",
   "description": "itflow-org/itflow repository advisory GHSA-m63v-j7fw-hq2h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 101,
   "clock_known": true,
   "hours_public": 2424,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-06",
   "advisory_days_public": 101,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/itflow-org/itflow/security/advisories/GHSA-m63v-j7fw-hq2h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54596",
   "state": "RESERVED",
   "public_date": "2026-06-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-06"
   },
   "refs": "ghsa-repos:itflow-org/itflow\tGHSA-f9m3-qjc9-v27j",
   "description": "itflow-org/itflow repository advisory GHSA-f9m3-qjc9-v27j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 101,
   "clock_known": true,
   "hours_public": 2424,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-06",
   "advisory_days_public": 101,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/itflow-org/itflow/security/advisories/GHSA-f9m3-qjc9-v27j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52727",
   "state": "RESERVED",
   "public_date": "2026-06-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-06"
   },
   "refs": "ghsa-repos:lxc/lxc-ci\tGHSA-4h59-f67g-5qxp",
   "description": "lxc/lxc-ci repository advisory GHSA-4h59-f67g-5qxp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 101,
   "clock_known": true,
   "hours_public": 2424,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-06",
   "advisory_days_public": 101,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/lxc/lxc-ci/security/advisories/GHSA-4h59-f67g-5qxp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47252",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-08",
    "ghsa-repos": "2026-06-07",
    "osv": "2026-06-08"
   },
   "refs": "ghsa-repos:julien040/anyquery\tGHSA-hrj8-hjv8-mgwc;ghsa:GHSA-hrj8-hjv8-mgwc;osv:Go:github.com/julien040/anyquery/plugins/chrome",
   "description": "Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/julien040/anyquery/plugins/chrome",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hrj8-hjv8-mgwc",
    "ghsa-repos": "https://github.com/julien040/anyquery/security/advisories/GHSA-hrj8-hjv8-mgwc",
    "osv": "https://osv.dev/list?q=CVE-2026-47252"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54627",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:HappySeaFox/sail\tGHSA-ccqf-rv86-h3wm",
   "description": "HappySeaFox/sail repository advisory GHSA-ccqf-rv86-h3wm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HappySeaFox/sail/security/advisories/GHSA-ccqf-rv86-h3wm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54626",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:HappySeaFox/sail\tGHSA-744p-cqg2-m33h",
   "description": "HappySeaFox/sail repository advisory GHSA-744p-cqg2-m33h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HappySeaFox/sail/security/advisories/GHSA-744p-cqg2-m33h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54613",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-gjxp-vrcw-69v8",
   "description": "givanz/Vvveb repository advisory GHSA-gjxp-vrcw-69v8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-gjxp-vrcw-69v8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54612",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-c3v9-3xrq-pvqv",
   "description": "givanz/Vvveb repository advisory GHSA-c3v9-3xrq-pvqv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-c3v9-3xrq-pvqv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54506",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-5cg7-phhv-4qjr",
   "description": "givanz/Vvveb repository advisory GHSA-5cg7-phhv-4qjr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-5cg7-phhv-4qjr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54507",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-xxp7-59p2-4jr8",
   "description": "givanz/Vvveb repository advisory GHSA-xxp7-59p2-4jr8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-xxp7-59p2-4jr8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54253",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-07"
   },
   "refs": "ghsa-repos:joni1802/ts3-manager\tGHSA-3cgm-7p4g-gffj",
   "description": "joni1802/ts3-manager repository advisory GHSA-3cgm-7p4g-gffj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/joni1802/ts3-manager/security/advisories/GHSA-3cgm-7p4g-gffj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48041",
   "state": "RESERVED",
   "public_date": "2026-06-07",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-08",
    "csaf": "2026-06-07"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1815\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1815.json;ghsa-repos:laravel/framework\tGHSA-crmm-hgp2-wgrp",
   "description": "laravel/framework repository advisory GHSA-crmm-hgp2-wgrp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 100,
   "clock_known": true,
   "hours_public": 2400,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-07",
   "advisory_days_public": 100,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1815.json",
    "ghsa-repos": "https://github.com/laravel/framework/security/advisories/GHSA-crmm-hgp2-wgrp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47321",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-06-08"
   },
   "refs": "debian:mina;ubuntu-osv:UBUNTU-CVE-2026-47321",
   "description": "mina",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mina",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-47321",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-47321"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48977",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-06-08"
   },
   "refs": "debian:openslide;ubuntu-osv:UBUNTU-CVE-2026-48977",
   "description": "openslide",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "openslide",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-48977",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-48977"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54677",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:Erudika/scoold\tGHSA-h2p4-mm8g-whxr",
   "description": "Erudika/scoold repository advisory GHSA-h2p4-mm8g-whxr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Erudika/scoold/security/advisories/GHSA-h2p4-mm8g-whxr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54676",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:Erudika/scoold\tGHSA-2cff-ppf7-pc42",
   "description": "Erudika/scoold repository advisory GHSA-2cff-ppf7-pc42",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Erudika/scoold/security/advisories/GHSA-2cff-ppf7-pc42"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54692",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:HappySeaFox/sail\tGHSA-gp27-qv2x-55v5",
   "description": "HappySeaFox/sail repository advisory GHSA-gp27-qv2x-55v5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HappySeaFox/sail/security/advisories/GHSA-gp27-qv2x-55v5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54671",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-chpq-hc43-6mhw",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-chpq-hc43-6mhw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-chpq-hc43-6mhw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54670",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-7p5g-g8xw-x47g",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-7p5g-g8xw-x47g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-7p5g-g8xw-x47g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54648",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-r376-2wr5-g9qx",
   "description": "cubecart/v6 repository advisory GHSA-r376-2wr5-g9qx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-r376-2wr5-g9qx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54647",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-hvmw-v8gc-4c29",
   "description": "cubecart/v6 repository advisory GHSA-hvmw-v8gc-4c29",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-hvmw-v8gc-4c29"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54646",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-qcx6-cg43-ffmx",
   "description": "cubecart/v6 repository advisory GHSA-qcx6-cg43-ffmx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-qcx6-cg43-ffmx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54645",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-43f6-gfcf-wj9c",
   "description": "cubecart/v6 repository advisory GHSA-43f6-gfcf-wj9c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-43f6-gfcf-wj9c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54644",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-v55x-fh73-29vq",
   "description": "cubecart/v6 repository advisory GHSA-v55x-fh73-29vq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-v55x-fh73-29vq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54643",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-8mmq-8hpq-2h23",
   "description": "cubecart/v6 repository advisory GHSA-8mmq-8hpq-2h23",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-8mmq-8hpq-2h23"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54642",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:cubecart/v6\tGHSA-cq6g-rf5m-42xg",
   "description": "cubecart/v6 repository advisory GHSA-cq6g-rf5m-42xg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cubecart/v6/security/advisories/GHSA-cq6g-rf5m-42xg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54633",
   "state": "RESERVED",
   "public_date": "2026-06-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-08"
   },
   "refs": "ghsa-repos:podofo/podofo\tGHSA-f3j2-7846-h5gg",
   "description": "podofo/podofo repository advisory GHSA-f3j2-7846-h5gg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 99,
   "clock_known": true,
   "hours_public": 2376,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-08",
   "advisory_days_public": 99,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/podofo/podofo/security/advisories/GHSA-f3j2-7846-h5gg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-3886",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "alas,csaf,debian,ubuntu-osv,zdi",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-10",
    "ubuntu-osv": "2026-07-09",
    "csaf": "2026-06-12",
    "zdi": "2026-06-09"
   },
   "refs": "alas:CVE-2026-3886;csaf:SUSE Product Security Team\tCVE-2026-3886\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-3886.json;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-3886;zdi:ZDI-26-332",
   "description": "virtio-gpu: fix overflow check when allocating 2d image",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-3886.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-3886.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-3886",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-3886",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-332/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50277",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:DataDog/dd-trace-cpp\tGHSA-ch7h-phmx-rqwq",
   "description": "DataDog/dd-trace-cpp repository advisory GHSA-ch7h-phmx-rqwq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/DataDog/dd-trace-cpp/security/advisories/GHSA-ch7h-phmx-rqwq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54767",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-399w-rxhp-jh9f",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-399w-rxhp-jh9f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-399w-rxhp-jh9f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52836",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:OpenDDS/OpenDDS\tGHSA-wcr7-gccq-vv56",
   "description": "OpenDDS/OpenDDS repository advisory GHSA-wcr7-gccq-vv56",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenDDS/OpenDDS/security/advisories/GHSA-wcr7-gccq-vv56"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45143",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-x88v-rg6r-vqq6",
   "description": "chamilo/chamilo-lms repository advisory GHSA-x88v-rg6r-vqq6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-x88v-rg6r-vqq6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45140",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-g4c3-4g96-6g4m",
   "description": "chamilo/chamilo-lms repository advisory GHSA-g4c3-4g96-6g4m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53557",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:dataease/SQLBot\tGHSA-vxwj-843f-9c9g",
   "description": "dataease/SQLBot repository advisory GHSA-vxwj-843f-9c9g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dataease/SQLBot/security/advisories/GHSA-vxwj-843f-9c9g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53556",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:dataease/SQLBot\tGHSA-vwjq-5h4h-x8g5",
   "description": "dataease/SQLBot repository advisory GHSA-vwjq-5h4h-x8g5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dataease/SQLBot/security/advisories/GHSA-vwjq-5h4h-x8g5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53555",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:dataease/SQLBot\tGHSA-v23m-5pvq-xcgx",
   "description": "dataease/SQLBot repository advisory GHSA-v23m-5pvq-xcgx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dataease/SQLBot/security/advisories/GHSA-v23m-5pvq-xcgx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53554",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:dataease/SQLBot\tGHSA-wxv4-pw5w-wx79",
   "description": "dataease/SQLBot repository advisory GHSA-wxv4-pw5w-wx79",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dataease/SQLBot/security/advisories/GHSA-wxv4-pw5w-wx79"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52852",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:traccar/traccar\tGHSA-6qh3-234v-r254",
   "description": "traccar/traccar repository advisory GHSA-6qh3-234v-r254",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/traccar/traccar/security/advisories/GHSA-6qh3-234v-r254"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52851",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:traccar/traccar\tGHSA-jx5h-fxhc-cc9w",
   "description": "traccar/traccar repository advisory GHSA-jx5h-fxhc-cc9w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/traccar/traccar/security/advisories/GHSA-jx5h-fxhc-cc9w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54716",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-09"
   },
   "refs": "ghsa-repos:valhalla/valhalla\tGHSA-qpf6-xp29-pg6r",
   "description": "valhalla/valhalla repository advisory GHSA-qpf6-xp29-pg6r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/valhalla/valhalla/security/advisories/GHSA-qpf6-xp29-pg6r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52903",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-06-09",
    "csaf": "2026-06-09"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-52903\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52903.json;redhat:CVE-2026-52903",
   "description": "manageiq: YAML safe_load production fallback to unsafe_load enables RCE via deserialization",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-52903",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52903.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-52903"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-10797",
   "state": "RESERVED",
   "public_date": "2026-06-09",
   "sources": "certcc",
   "feed_count": 1,
   "dates": {
    "certcc": "2026-06-09"
   },
   "refs": "certcc:VU#616257",
   "description": "Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 98,
   "clock_known": true,
   "hours_public": 2352,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-09",
   "advisory_days_public": 98,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "certcc": "https://www.kb.cert.org/vuls/id/616257"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48785",
   "state": "RESERVED",
   "public_date": "2026-06-10",
   "sources": "alpine,csaf,debian,ghsa,osv,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "ubuntu-osv": "2026-06-25",
    "ghsa": "2026-06-26",
    "osv": "2026-06-26",
    "csaf": "2026-06-10"
   },
   "refs": "alpine:apptainer;csaf:SUSE Product Security Team\topenSUSE-SU-2026:20942-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_20942-1.json;debian:apptainer;ghsa:GHSA-cr2j-534f-mf3g;osv:Go:github.com/apptainer/apptainer;ubuntu-osv:UBUNTU-",
   "description": "apptainer",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 97,
   "clock_known": true,
   "hours_public": 2328,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-10",
   "advisory_days_public": 97,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "apptainer",
   "ecosystem": "Go",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-48785",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_20942-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-48785",
    "ghsa": "https://github.com/advisories/GHSA-cr2j-534f-mf3g",
    "osv": "https://osv.dev/list?q=CVE-2026-48785",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-48785"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45562",
   "state": "RESERVED",
   "public_date": "2026-06-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-10"
   },
   "refs": "ghsa-repos:FreePBX/security-reporting\tGHSA-4g6v-whq9-944g",
   "description": "FreePBX/security-reporting repository advisory GHSA-4g6v-whq9-944g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 97,
   "clock_known": true,
   "hours_public": 2328,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-10",
   "advisory_days_public": 97,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FreePBX/security-reporting/security/advisories/GHSA-4g6v-whq9-944g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54544",
   "state": "RESERVED",
   "public_date": "2026-06-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-10"
   },
   "refs": "ghsa-repos:ShaneIsrael/fireshare\tGHSA-w7j7-gv7f-gj92",
   "description": "ShaneIsrael/fireshare repository advisory GHSA-w7j7-gv7f-gj92",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 97,
   "clock_known": true,
   "hours_public": 2328,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-10",
   "advisory_days_public": 97,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-w7j7-gv7f-gj92"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44236",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-06-11"
   },
   "refs": "debian:librabbitmq;ubuntu-osv:UBUNTU-CVE-2026-44236",
   "description": "Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "librabbitmq",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-44236",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-44236"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44235",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-06-11"
   },
   "refs": "debian:librabbitmq;ubuntu-osv:UBUNTU-CVE-2026-44235",
   "description": "size_t underflow in AMQP frame length computation leads to out-of-bounds read in rabbitmq-c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "librabbitmq",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-44235",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-44235"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54050",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-08-24",
    "ghsa-repos": "2026-06-11",
    "osv": "2026-08-24"
   },
   "refs": "ghsa-repos:sakaiproject/sakai\tGHSA-9284-fjc3-fmmj;ghsa:GHSA-9284-fjc3-fmmj;osv:Maven:org.sakaiproject.profile2:profile2-api",
   "description": "Sakai Profile Image Deletion has an IDOR",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.sakaiproject.profile2",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-9284-fjc3-fmmj",
    "ghsa-repos": "https://github.com/sakaiproject/sakai/security/advisories/GHSA-9284-fjc3-fmmj",
    "osv": "https://osv.dev/list?q=CVE-2026-54050"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54049",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-08-24",
    "ghsa-repos": "2026-06-11",
    "osv": "2026-08-24"
   },
   "refs": "ghsa-repos:sakaiproject/sakai\tGHSA-w2x5-gv52-9ccv;ghsa:GHSA-w2x5-gv52-9ccv;osv:Maven:org.sakaiproject.conversations:sakai-conversations-impl",
   "description": "Sakai Conversations has a Stored XSS Issue",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.sakaiproject.conversations",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-w2x5-gv52-9ccv",
    "ghsa-repos": "https://github.com/sakaiproject/sakai/security/advisories/GHSA-w2x5-gv52-9ccv",
    "osv": "https://osv.dev/list?q=CVE-2026-54049"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-45747",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "csaf,ghsa,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-08-19",
    "osv": "2026-08-19",
    "csaf": "2026-06-11"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1902\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1902.json;ghsa:GHSA-wf6j-gr27-g7ch;osv:Maven:org.geoserver:gs-main",
   "description": "GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.geoserver",
   "ecosystem": "Maven",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1902.json",
    "ghsa": "https://github.com/advisories/GHSA-wf6j-gr27-g7ch",
    "osv": "https://osv.dev/list?q=CVE-2024-45747"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52745",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-xrcr-hj37-q83j",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-xrcr-hj37-q83j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-xrcr-hj37-q83j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53953",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-vvhx-56q2-gcjq",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-vvhx-56q2-gcjq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vvhx-56q2-gcjq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55181",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:Quenary/tugtainer\tGHSA-rg7c-vpfp-2w43",
   "description": "Quenary/tugtainer repository advisory GHSA-rg7c-vpfp-2w43",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55083",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:dhis2/dhis2-core\tGHSA-3fr2-wvqx-cmr5",
   "description": "dhis2/dhis2-core repository advisory GHSA-3fr2-wvqx-cmr5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dhis2/dhis2-core/security/advisories/GHSA-3fr2-wvqx-cmr5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55231",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-327v-4f9p-5qxq",
   "description": "givanz/Vvveb repository advisory GHSA-327v-4f9p-5qxq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-327v-4f9p-5qxq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55230",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-97xr-82vc-wj2v",
   "description": "givanz/Vvveb repository advisory GHSA-97xr-82vc-wj2v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-97xr-82vc-wj2v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55232",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-11"
   },
   "refs": "ghsa-repos:givanz/Vvveb\tGHSA-r6g4-5m3x-xrqj",
   "description": "givanz/Vvveb repository advisory GHSA-r6g4-5m3x-xrqj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/givanz/Vvveb/security/advisories/GHSA-r6g4-5m3x-xrqj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52849",
   "state": "RESERVED",
   "public_date": "2026-06-11",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-06-11"
   },
   "refs": "zdi:ZDI-26-360",
   "description": "ZDI advisory ZDI-26-360",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 96,
   "clock_known": true,
   "hours_public": 2304,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-11",
   "advisory_days_public": 96,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-360/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52717",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "csaf,debian,redhat,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-06-17",
    "redhat": "2026-06-12",
    "csaf": "2026-08-18"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2026-52717\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-52717.json;debian:gst-libav1.0;redhat:CVE-2026-52717;ubuntu-osv:UBUNTU-CVE-2026-52717",
   "description": "gst-libav1.0",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gst-libav1.0",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-52717.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52717",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-52717",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-52717"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12893",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "csaf,debian,redhat,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-06",
    "redhat": "2026-06-12",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2026-12893\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-12893.json;debian:gst-libav1.0;redhat:CVE-2026-12893;ubuntu-osv:UBUNTU-CVE-2026-12893",
   "description": "[gstreamer1-libav: gstreamer1-libav: NULL pointer dereference in gstavdemux.c error handler]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gst-libav1.0",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-12893.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12893",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-12893",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12893"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54697",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-vc8p-8pxg-rfwg;osv:Maven:org.connectbot.sshlib:sshlib",
   "description": "ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.connectbot.sshlib",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-vc8p-8pxg-rfwg",
    "osv": "https://osv.dev/list?q=CVE-2026-54697"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54700",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-ch3q-cw5r-f4hg;osv:Maven:org.connectbot.sshlib:sshlib",
   "description": "ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.connectbot.sshlib",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-ch3q-cw5r-f4hg",
    "osv": "https://osv.dev/list?q=CVE-2026-54700"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53999",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-fp5j-4fj2-4jvq;osv:Go:github.com/radius-project/radius",
   "description": "Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/radius-project/radius",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-fp5j-4fj2-4jvq",
    "osv": "https://osv.dev/list?q=CVE-2026-53999"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28975",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-6ph5-fww6-vfwv;osv:SwiftURL:github.com/apple/swift-nio-extras",
   "description": "NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/apple/swift-nio-extras",
   "ecosystem": "SwiftURL",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-6ph5-fww6-vfwv",
    "osv": "https://osv.dev/list?q=CVE-2026-28975"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28980",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-rj37-6j9x-74q6;osv:SwiftURL:github.com/apple/swift-nio",
   "description": "SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/apple/swift-nio",
   "ecosystem": "SwiftURL",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-rj37-6j9x-74q6",
    "osv": "https://osv.dev/list?q=CVE-2026-28980"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-43671",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-r3rc-9hpw-54v9;osv:SwiftURL:github.com/apple/swift-nio",
   "description": "SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/apple/swift-nio",
   "ecosystem": "SwiftURL",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-r3rc-9hpw-54v9",
    "osv": "https://osv.dev/list?q=CVE-2026-43671"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28970",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-12",
    "osv": "2026-06-12"
   },
   "refs": "ghsa:GHSA-cq87-8r7h-962v;osv:SwiftURL:github.com/apple/swift-nio",
   "description": "SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/apple/swift-nio",
   "ecosystem": "SwiftURL",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-cq87-8r7h-962v",
    "osv": "https://osv.dev/list?q=CVE-2026-28970"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54708",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:FreePBX/security-reporting\tGHSA-5hhg-w366-g6fh",
   "description": "FreePBX/security-reporting repository advisory GHSA-5hhg-w366-g6fh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FreePBX/security-reporting/security/advisories/GHSA-5hhg-w366-g6fh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54675",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:FreePBX/security-reporting\tGHSA-95gm-cmxf-cv8v",
   "description": "FreePBX/security-reporting repository advisory GHSA-95gm-cmxf-cv8v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FreePBX/security-reporting/security/advisories/GHSA-95gm-cmxf-cv8v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54674",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:FreePBX/security-reporting\tGHSA-4jjr-8g5r-wv66",
   "description": "FreePBX/security-reporting repository advisory GHSA-4jjr-8g5r-wv66",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FreePBX/security-reporting/security/advisories/GHSA-4jjr-8g5r-wv66"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54710",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:FreePBX/security-reporting\tGHSA-j53p-5m8r-j3p6",
   "description": "FreePBX/security-reporting repository advisory GHSA-j53p-5m8r-j3p6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FreePBX/security-reporting/security/advisories/GHSA-j53p-5m8r-j3p6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55384",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-8c69-ch98-87r6",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-8c69-ch98-87r6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-8c69-ch98-87r6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55385",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-mfxg-qphw-3f3g",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-mfxg-qphw-3f3g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-mfxg-qphw-3f3g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55386",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-cp8p-jcqf-j39c",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-cp8p-jcqf-j39c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-cp8p-jcqf-j39c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55383",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-73q7-2953-8gvx",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-73q7-2953-8gvx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-73q7-2953-8gvx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55387",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-wxrv-73x6-8r62",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-wxrv-73x6-8r62",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-wxrv-73x6-8r62"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55381",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-j2vg-rxqr-5vc9",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-j2vg-rxqr-5vc9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-j2vg-rxqr-5vc9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55382",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-85wc-38p4-2wqq",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-85wc-38p4-2wqq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-85wc-38p4-2wqq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55167",
   "state": "RESERVED",
   "public_date": "2026-06-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-12"
   },
   "refs": "ghsa-repos:LDAPAccountManager/lam\tGHSA-xgjg-fchx-x3g3",
   "description": "LDAPAccountManager/lam repository advisory GHSA-xgjg-fchx-x3g3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 95,
   "clock_known": true,
   "hours_public": 2280,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-12",
   "advisory_days_public": 95,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-xgjg-fchx-x3g3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55494",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:Quenary/tugtainer\tGHSA-wgw2-c96g-p7h7",
   "description": "Quenary/tugtainer repository advisory GHSA-wgw2-c96g-p7h7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-wgw2-c96g-p7h7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55567",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:bleachbit/bleachbit\tGHSA-vcjw-px28-5w94",
   "description": "bleachbit/bleachbit repository advisory GHSA-vcjw-px28-5w94",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bleachbit/bleachbit/security/advisories/GHSA-vcjw-px28-5w94"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55562",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:jhuckaby/Cronicle\tGHSA-vh39-3pcm-2j63",
   "description": "jhuckaby/Cronicle repository advisory GHSA-vh39-3pcm-2j63",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jhuckaby/Cronicle/security/advisories/GHSA-vh39-3pcm-2j63"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48975",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:sysadminsmedia/homebox\tGHSA-7mr6-2wxw-27j9",
   "description": "sysadminsmedia/homebox repository advisory GHSA-7mr6-2wxw-27j9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-7mr6-2wxw-27j9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48974",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:sysadminsmedia/homebox\tGHSA-ffcw-whqh-hgqf",
   "description": "sysadminsmedia/homebox repository advisory GHSA-ffcw-whqh-hgqf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-ffcw-whqh-hgqf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48826",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:sysadminsmedia/homebox\tGHSA-559j-7w3w-4fr7",
   "description": "sysadminsmedia/homebox repository advisory GHSA-559j-7w3w-4fr7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-559j-7w3w-4fr7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55473",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:sysadminsmedia/homebox\tGHSA-r9pf-rg22-655m",
   "description": "sysadminsmedia/homebox repository advisory GHSA-r9pf-rg22-655m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-r9pf-rg22-655m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48976",
   "state": "RESERVED",
   "public_date": "2026-06-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-13"
   },
   "refs": "ghsa-repos:sysadminsmedia/homebox\tGHSA-mc8h-5c5v-37p7",
   "description": "sysadminsmedia/homebox repository advisory GHSA-mc8h-5c5v-37p7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 94,
   "clock_known": true,
   "hours_public": 2256,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-13",
   "advisory_days_public": 94,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-mc8h-5c5v-37p7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54554",
   "state": "RESERVED",
   "public_date": "2026-06-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-14"
   },
   "refs": "ghsa-repos:FOGProject/fogproject\tGHSA-q9gc-h2qc-qmx8",
   "description": "FOGProject/fogproject repository advisory GHSA-q9gc-h2qc-qmx8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 93,
   "clock_known": true,
   "hours_public": 2232,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-14",
   "advisory_days_public": 93,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FOGProject/fogproject/security/advisories/GHSA-q9gc-h2qc-qmx8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55610",
   "state": "RESERVED",
   "public_date": "2026-06-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-14"
   },
   "refs": "ghsa-repos:InvoiceShelf/InvoiceShelf\tGHSA-vgx6-6cqr-m8qr",
   "description": "InvoiceShelf/InvoiceShelf repository advisory GHSA-vgx6-6cqr-m8qr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 93,
   "clock_known": true,
   "hours_public": 2232,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-14",
   "advisory_days_public": 93,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-vgx6-6cqr-m8qr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55572",
   "state": "RESERVED",
   "public_date": "2026-06-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-14"
   },
   "refs": "ghsa-repos:e107inc/e107\tGHSA-5f75-c25x-59wx",
   "description": "e107inc/e107 repository advisory GHSA-5f75-c25x-59wx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 93,
   "clock_known": true,
   "hours_public": 2232,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-14",
   "advisory_days_public": 93,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/e107inc/e107/security/advisories/GHSA-5f75-c25x-59wx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55573",
   "state": "RESERVED",
   "public_date": "2026-06-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-14"
   },
   "refs": "ghsa-repos:e107inc/e107\tGHSA-c8h6-wpj3-4cr8",
   "description": "e107inc/e107 repository advisory GHSA-c8h6-wpj3-4cr8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 93,
   "clock_known": true,
   "hours_public": 2232,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-14",
   "advisory_days_public": 93,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/e107inc/e107/security/advisories/GHSA-c8h6-wpj3-4cr8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53922",
   "state": "RESERVED",
   "public_date": "2026-06-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-14"
   },
   "refs": "ghsa-repos:openwrt/odhcpd\tGHSA-7hcw-g2jh-pqv5",
   "description": "openwrt/odhcpd repository advisory GHSA-7hcw-g2jh-pqv5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 93,
   "clock_known": true,
   "hours_public": 2232,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-14",
   "advisory_days_public": 93,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/odhcpd/security/advisories/GHSA-7hcw-g2jh-pqv5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53582",
   "state": "RESERVED",
   "public_date": "2026-06-14",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-15",
    "csaf": "2026-06-14"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1917\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1917.json;ghsa-repos:opnsense/core\tGHSA-xww7-76m6-mh2r",
   "description": "opnsense/core repository advisory GHSA-xww7-76m6-mh2r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 93,
   "clock_known": true,
   "hours_public": 2232,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-14",
   "advisory_days_public": 93,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1917.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-xww7-76m6-mh2r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-55662",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ubuntu-osv",
   "feed_count": 1,
   "dates": {
    "ubuntu-osv": "2026-06-15"
   },
   "refs": "ubuntu-osv:UBUNTU-CVE-2025-55662",
   "description": "",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2025-55662"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39902",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-07-27",
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json;ghsa-repos:Cacti/cacti\tGHSA-c4qp-j9r9-fq24",
   "description": "Cacti/cacti repository advisory GHSA-c4qp-j9r9-fq24",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39902",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
    "ghsa-repos": "https://github.com/Cacti/cacti/security/advisories/GHSA-c4qp-j9r9-fq24"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46531",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-06-18",
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json;ghsa-repos:Cacti/cacti\tGHSA-37jj-rx8x-4wf2",
   "description": "Cacti/cacti repository advisory GHSA-37jj-rx8x-4wf2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-46531",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
    "ghsa-repos": "https://github.com/Cacti/cacti/security/advisories/GHSA-37jj-rx8x-4wf2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54532",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:CloudPirates-io/helm-charts\tGHSA-gv8x-4mc5-r65r",
   "description": "CloudPirates-io/helm-charts repository advisory GHSA-gv8x-4mc5-r65r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CloudPirates-io/helm-charts/security/advisories/GHSA-gv8x-4mc5-r65r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53711",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:IBM/mcp-context-forge\tGHSA-x6gc-rm5j-55mw",
   "description": "IBM/mcp-context-forge repository advisory GHSA-x6gc-rm5j-55mw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/IBM/mcp-context-forge/security/advisories/GHSA-x6gc-rm5j-55mw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53709",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:IBM/mcp-context-forge\tGHSA-m8rv-5m6m-32ff",
   "description": "IBM/mcp-context-forge repository advisory GHSA-m8rv-5m6m-32ff",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/IBM/mcp-context-forge/security/advisories/GHSA-m8rv-5m6m-32ff"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55684",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-g2hm-m6gw-fcgg",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-g2hm-m6gw-fcgg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-g2hm-m6gw-fcgg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55683",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-vjxh-wcf9-4qgq",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-vjxh-wcf9-4qgq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-vjxh-wcf9-4qgq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55682",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-5xhr-jrv8-j4j2",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-5xhr-jrv8-j4j2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-5xhr-jrv8-j4j2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55681",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-9q8x-jqpj-23xp",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-9q8x-jqpj-23xp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-9q8x-jqpj-23xp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55680",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-fxcc-q2j6-w2rf",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-fxcc-q2j6-w2rf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-fxcc-q2j6-w2rf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55679",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-wm6j-4rfm-399q",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-wm6j-4rfm-399q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-wm6j-4rfm-399q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55644",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:element-hq/element-x-ios\tGHSA-54w7-rw44-49m7",
   "description": "element-hq/element-x-ios repository advisory GHSA-54w7-rw44-49m7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/element-hq/element-x-ios/security/advisories/GHSA-54w7-rw44-49m7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54459",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-jp5j-9px9-g47g",
   "description": "error311/FileRise repository advisory GHSA-jp5j-9px9-g47g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-jp5j-9px9-g47g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55159",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-15"
   },
   "refs": "ghsa-repos:openwrt/luci\tGHSA-ggpf-xrph-wg5v",
   "description": "openwrt/luci repository advisory GHSA-ggpf-xrph-wg5v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/luci/security/advisories/GHSA-ggpf-xrph-wg5v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44481",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-44481",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-44481",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39952",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39952",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39952",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40078",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-40078",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-40078",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39949",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39949",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39949",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40081",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-40081",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-40081",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39898",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39898",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39898",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41884",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-41884",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-41884",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39896",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39896",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39896",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39950",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39950",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39950",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39939",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39939",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39939",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39947",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39947",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39947",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39895",
   "state": "RESERVED",
   "public_date": "2026-06-15",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-15"
   },
   "refs": "alpine:cacti;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1931\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json",
   "description": "CVE-2026-39895",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 92,
   "clock_known": true,
   "hours_public": 2208,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-15",
   "advisory_days_public": 92,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "cacti",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-39895",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1931.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53614",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "alas,csaf,debian,ghsa-repos,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-06-20",
    "ubuntu-osv": "2026-06-18",
    "ghsa-repos": "2026-06-16",
    "redhat": "2026-06-16",
    "csaf": "2026-06-25"
   },
   "refs": "alas:CVE-2026-53614;csaf:SUSE Product Security Team\tCVE-2026-53614\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-53614.json;debian:util-linux;ghsa-repos:util-linux/util-linux\tGHSA-67r7-8m5w-22wx;redhat:CVE-2026-53614;ubuntu-osv:UBUNTU-",
   "description": "Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "util-linux",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-53614.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-53614.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53614",
    "ghsa-repos": "https://github.com/util-linux/util-linux/security/advisories/GHSA-67r7-8m5w-22wx",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-53614",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53614"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53613",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "alas,csaf,debian,ghsa-repos,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-06-20",
    "ubuntu-osv": "2026-06-18",
    "ghsa-repos": "2026-06-16",
    "redhat": "2026-06-16",
    "csaf": "2026-06-25"
   },
   "refs": "alas:CVE-2026-53613;csaf:SUSE Product Security Team\tCVE-2026-53613\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-53613.json;debian:util-linux;ghsa-repos:util-linux/util-linux\tGHSA-8gj5-72r3-428g;redhat:CVE-2026-53613;ubuntu-osv:UBUNTU-",
   "description": "Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "util-linux",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-53613.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-53613.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53613",
    "ghsa-repos": "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-53613",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53613"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53612",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "alas,csaf,debian,ghsa-repos,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-06-20",
    "ubuntu-osv": "2026-06-18",
    "ghsa-repos": "2026-06-16",
    "redhat": "2026-06-16",
    "csaf": "2026-06-25"
   },
   "refs": "alas:CVE-2026-53612;csaf:SUSE Product Security Team\tCVE-2026-53612\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-53612.json;debian:util-linux;ghsa-repos:util-linux/util-linux\tGHSA-g8wm-75wr-g2vh;redhat:CVE-2026-53612;ubuntu-osv:UBUNTU-",
   "description": "Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "util-linux",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-53612.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-53612.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53612",
    "ghsa-repos": "https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-53612",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53612"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53615",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-06-20",
    "ubuntu-osv": "2026-06-18",
    "ghsa-repos": "2026-06-16",
    "csaf": "2026-08-19"
   },
   "refs": "alas:CVE-2026-53615;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2938\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2938.json;debian:util-linux;ghsa-repos:util-linux/util-linux\tGHSA-h4rw-gv36-wmp5;ubun",
   "description": "Integer Overflow or Wraparound in libblkid/src/partitions/dos.c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "util-linux",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-53615.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2938.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53615",
    "ghsa-repos": "https://github.com/util-linux/util-linux/security/advisories/GHSA-h4rw-gv36-wmp5",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53615"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55842",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Erudika/scoold\tGHSA-q684-4jqv-c63c",
   "description": "Erudika/scoold repository advisory GHSA-q684-4jqv-c63c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Erudika/scoold/security/advisories/GHSA-q684-4jqv-c63c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55840",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Erudika/scoold\tGHSA-85fm-6f2v-74pq",
   "description": "Erudika/scoold repository advisory GHSA-85fm-6f2v-74pq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Erudika/scoold/security/advisories/GHSA-85fm-6f2v-74pq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55835",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Lookyloo/lookyloo\tGHSA-66gj-hmcp-5cfj",
   "description": "Lookyloo/lookyloo repository advisory GHSA-66gj-hmcp-5cfj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Lookyloo/lookyloo/security/advisories/GHSA-66gj-hmcp-5cfj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55480",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-17",
    "csaf": "2026-06-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1968\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1968.json;ghsa-repos:OpenPrinting/cups\tGHSA-jj94-x3qh-ffp9",
   "description": "OpenPrinting/cups repository advisory GHSA-jj94-x3qh-ffp9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1968.json",
    "ghsa-repos": "https://github.com/OpenPrinting/cups/security/advisories/GHSA-jj94-x3qh-ffp9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55453",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-17",
    "csaf": "2026-06-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1968\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1968.json;ghsa-repos:OpenPrinting/cups\tGHSA-7hqf-mfhx-7r3v",
   "description": "OpenPrinting/cups repository advisory GHSA-7hqf-mfhx-7r3v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1968.json",
    "ghsa-repos": "https://github.com/OpenPrinting/cups/security/advisories/GHSA-7hqf-mfhx-7r3v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54631",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-99pw-2v29-v4wc",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-99pw-2v29-v4wc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-99pw-2v29-v4wc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54630",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-w5m7-3xf7-6g7g",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-w5m7-3xf7-6g7g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-w5m7-3xf7-6g7g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54615",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-gp89-jfq9-x8r9",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-gp89-jfq9-x8r9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-gp89-jfq9-x8r9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54915",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Tautulli/Tautulli\tGHSA-7c9r-fhj9-87xm",
   "description": "Tautulli/Tautulli repository advisory GHSA-7c9r-fhj9-87xm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Tautulli/Tautulli/security/advisories/GHSA-7c9r-fhj9-87xm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52835",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Tautulli/Tautulli\tGHSA-8ww5-pp25-3jm8",
   "description": "Tautulli/Tautulli repository advisory GHSA-8ww5-pp25-3jm8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Tautulli/Tautulli/security/advisories/GHSA-8ww5-pp25-3jm8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49995",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Tautulli/Tautulli\tGHSA-r6pg-vqxj-v75j",
   "description": "Tautulli/Tautulli repository advisory GHSA-r6pg-vqxj-v75j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Tautulli/Tautulli/security/advisories/GHSA-r6pg-vqxj-v75j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45381",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:Tautulli/Tautulli\tGHSA-mjvc-6cc2-6ffr",
   "description": "Tautulli/Tautulli repository advisory GHSA-mjvc-6cc2-6ffr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Tautulli/Tautulli/security/advisories/GHSA-mjvc-6cc2-6ffr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55103",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:discourse/discourse-activity-pub\tGHSA-jw39-rch6-mhwf",
   "description": "discourse/discourse-activity-pub repository advisory GHSA-jw39-rch6-mhwf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse-activity-pub/security/advisories/GHSA-jw39-rch6-mhwf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55796",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:frappe/hrms\tGHSA-c32r-q985-64xr",
   "description": "frappe/hrms repository advisory GHSA-c32r-q985-64xr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/hrms/security/advisories/GHSA-c32r-q985-64xr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54657",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:open-zaak/open-zaak\tGHSA-f29q-7rpr-jmjx",
   "description": "open-zaak/open-zaak repository advisory GHSA-f29q-7rpr-jmjx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-zaak/open-zaak/security/advisories/GHSA-f29q-7rpr-jmjx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55836",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:open-zaak/open-zaak\tGHSA-x5cj-23hr-5r54",
   "description": "open-zaak/open-zaak repository advisory GHSA-x5cj-23hr-5r54",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-zaak/open-zaak/security/advisories/GHSA-x5cj-23hr-5r54"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55897",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:openwrt/luci\tGHSA-vj96-f37g-37f6",
   "description": "openwrt/luci repository advisory GHSA-vj96-f37g-37f6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/luci/security/advisories/GHSA-vj96-f37g-37f6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55862",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:pupnp/pupnp\tGHSA-25cx-xv8x-j247",
   "description": "pupnp/pupnp repository advisory GHSA-25cx-xv8x-j247",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pupnp/pupnp/security/advisories/GHSA-25cx-xv8x-j247"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54238",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-16"
   },
   "refs": "ghsa-repos:supabase/realtime\tGHSA-hg9h-6mhq-6c2v",
   "description": "supabase/realtime repository advisory GHSA-hg9h-6mhq-6c2v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/supabase/realtime/security/advisories/GHSA-hg9h-6mhq-6c2v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46655",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-06-16",
    "csaf": "2026-06-16"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-46655\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46655.json;redhat:CVE-2026-46655",
   "description": "virtio-win: viosock.sys: integer overflow in VIOSockSelect leads to heap-based buffer overflow",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-46655",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46655.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-46655"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-68405",
   "state": "RESERVED",
   "public_date": "2026-06-16",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-16"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-1966\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1966.json",
   "description": "CVE-2025-68405",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 91,
   "clock_known": true,
   "hours_public": 2184,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-16",
   "advisory_days_public": 91,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1966.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54711",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:Aiven-Open/pghoard\tGHSA-mpx4-jmpr-vm8v;ghsa:GHSA-mpx4-jmpr-vm8v;osv:PyPI:pghoard",
   "description": "PGHoard: Password written to debug log",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "pghoard",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-mpx4-jmpr-vm8v",
    "ghsa-repos": "https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-mpx4-jmpr-vm8v",
    "osv": "https://osv.dev/list?q=CVE-2026-54711"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57144",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-6jcq-6546-qrrw;ghsa:GHSA-6jcq-6546-qrrw;osv:PyPI:praisonai",
   "description": "PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-6jcq-6546-qrrw",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6jcq-6546-qrrw",
    "osv": "https://osv.dev/list?q=CVE-2026-57144"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57143",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-4pcv-mg8v-vrgf;ghsa:GHSA-4pcv-mg8v-vrgf;osv:PyPI:praisonaiagents",
   "description": "PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonaiagents",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-4pcv-mg8v-vrgf",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4pcv-mg8v-vrgf",
    "osv": "https://osv.dev/list?q=CVE-2026-57143"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57146",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-jxcw-qp4h-6jfq;ghsa:GHSA-jxcw-qp4h-6jfq;osv:PyPI:praisonai",
   "description": "PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-jxcw-qp4h-6jfq",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-jxcw-qp4h-6jfq",
    "osv": "https://osv.dev/list?q=CVE-2026-57146"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57142",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-7qw2-w5rc-37x2;ghsa:GHSA-7qw2-w5rc-37x2;osv:PyPI:praisonai",
   "description": "PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-7qw2-w5rc-37x2",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7qw2-w5rc-37x2",
    "osv": "https://osv.dev/list?q=CVE-2026-57142"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57113",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-f44v-7qgw-9gh9;ghsa:GHSA-f44v-7qgw-9gh9;osv:PyPI:praisonai",
   "description": "PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-f44v-7qgw-9gh9",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-f44v-7qgw-9gh9",
    "osv": "https://osv.dev/list?q=CVE-2026-57113"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57121",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-rh39-9c67-59mh;ghsa:GHSA-rh39-9c67-59mh;osv:PyPI:praisonai-platform",
   "description": "PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai-platform",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-rh39-9c67-59mh",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-rh39-9c67-59mh",
    "osv": "https://osv.dev/list?q=CVE-2026-57121"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57116",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-892r-p3jq-jp24;ghsa:GHSA-892r-p3jq-jp24;osv:PyPI:praisonai",
   "description": "PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-892r-p3jq-jp24",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-892r-p3jq-jp24",
    "osv": "https://osv.dev/list?q=CVE-2026-57116"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57118",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-x8cv-xmq7-p8xp;ghsa:GHSA-x8cv-xmq7-p8xp;osv:PyPI:praisonaiagents",
   "description": "PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonaiagents",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-x8cv-xmq7-p8xp",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x8cv-xmq7-p8xp",
    "osv": "https://osv.dev/list?q=CVE-2026-57118"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57114",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-rjvw-7vvw-549v;ghsa:GHSA-rjvw-7vvw-549v;osv:PyPI:praisonai",
   "description": "PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-rjvw-7vvw-549v",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-rjvw-7vvw-549v",
    "osv": "https://osv.dev/list?q=CVE-2026-57114"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57117",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-w6h2-fr4q-xvxv;ghsa:GHSA-w6h2-fr4q-xvxv;osv:PyPI:praisonai",
   "description": "PraisonAI: Compute-bridged file tools allow shell command injection",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-w6h2-fr4q-xvxv",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-w6h2-fr4q-xvxv",
    "osv": "https://osv.dev/list?q=CVE-2026-57117"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56838",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-v847-hxxw-3pxg;ghsa:GHSA-v847-hxxw-3pxg;osv:PyPI:praisonai",
   "description": "PraisonAI recipe.run_stream skips dangerous-tool policy enforcement",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-v847-hxxw-3pxg",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-v847-hxxw-3pxg",
    "osv": "https://osv.dev/list?q=CVE-2026-56838"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56840",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-63v4-w882-g4x2;ghsa:GHSA-63v4-w882-g4x2;osv:PyPI:praisonai",
   "description": "PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-63v4-w882-g4x2",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-63v4-w882-g4x2",
    "osv": "https://osv.dev/list?q=CVE-2026-56840"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56837",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-fc26-m9pf-v56q;ghsa:GHSA-fc26-m9pf-v56q;osv:PyPI:praisonai",
   "description": "PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-fc26-m9pf-v56q",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fc26-m9pf-v56q",
    "osv": "https://osv.dev/list?q=CVE-2026-56837"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56834",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-j7qx-p75m-wp7g;ghsa:GHSA-j7qx-p75m-wp7g;osv:PyPI:praisonai",
   "description": "PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-j7qx-p75m-wp7g",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-j7qx-p75m-wp7g",
    "osv": "https://osv.dev/list?q=CVE-2026-56834"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56835",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-qvpf-j64c-jmhr;ghsa:GHSA-qvpf-j64c-jmhr;osv:PyPI:praisonai",
   "description": "PraisonAI Slack app_mention bypasses configured user/channel authorization",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-qvpf-j64c-jmhr",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qvpf-j64c-jmhr",
    "osv": "https://osv.dev/list?q=CVE-2026-56835"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56836",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-5qw8-f2g9-ff29;ghsa:GHSA-5qw8-f2g9-ff29;osv:PyPI:praisonai",
   "description": "PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-5qw8-f2g9-ff29",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5qw8-f2g9-ff29",
    "osv": "https://osv.dev/list?q=CVE-2026-56836"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56833",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-22cj-m4wf-fv2c;ghsa:GHSA-22cj-m4wf-fv2c;osv:PyPI:praisonai",
   "description": "PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-22cj-m4wf-fv2c",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-22cj-m4wf-fv2c",
    "osv": "https://osv.dev/list?q=CVE-2026-56833"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56832",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "osv": "2026-06-18"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-8579-rgg5-ph2m;ghsa:GHSA-8579-rgg5-ph2m;osv:PyPI:praisonai",
   "description": "PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "praisonai",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-8579-rgg5-ph2m",
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8579-rgg5-ph2m",
    "osv": "https://osv.dev/list?q=CVE-2026-56832"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55226",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "csaf,ghsa,ghsa-repos,osv,redhat",
   "feed_count": 5,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "redhat": "2026-06-17",
    "osv": "2026-06-18",
    "csaf": "2026-06-17"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-55226\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55226.json;ghsa-repos:strimzi/strimzi-kafka-operator\tGHSA-r427-j2h7-wv3m;ghsa:GHSA-r427-j2h7-wv3m;osv:Maven:io.strimzi:strimzi;redhat:CVE-2",
   "description": "Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.strimzi",
   "ecosystem": "Maven",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55226.json",
    "ghsa": "https://github.com/advisories/GHSA-r427-j2h7-wv3m",
    "ghsa-repos": "https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-r427-j2h7-wv3m",
    "osv": "https://osv.dev/list?q=CVE-2026-55226",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-55226"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55225",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "csaf,ghsa,ghsa-repos,osv,redhat",
   "feed_count": 5,
   "dates": {
    "ghsa": "2026-06-18",
    "ghsa-repos": "2026-06-17",
    "redhat": "2026-06-17",
    "osv": "2026-06-18",
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Red Hat Product Security\tRHSA-2026:54435\thttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54435.json;ghsa-repos:strimzi/strimzi-kafka-operator\tGHSA-mw9r-p8xp-wx96;ghsa:GHSA-mw9r-p8xp-wx96;osv:Maven:io.strimzi:strimzi;red",
   "description": "Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.strimzi",
   "ecosystem": "Maven",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54435.json",
    "ghsa": "https://github.com/advisories/GHSA-mw9r-p8xp-wx96",
    "ghsa-repos": "https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-mw9r-p8xp-wx96",
    "osv": "https://osv.dev/list?q=CVE-2026-55225",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-55225"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57183",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:Erudika/scoold\tGHSA-6q9q-cqq5-hvmq",
   "description": "Erudika/scoold repository advisory GHSA-6q9q-cqq5-hvmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Erudika/scoold/security/advisories/GHSA-6q9q-cqq5-hvmq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55467",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:OpenPrinting/cups\tGHSA-69qc-prxg-h2c7",
   "description": "OpenPrinting/cups repository advisory GHSA-69qc-prxg-h2c7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenPrinting/cups/security/advisories/GHSA-69qc-prxg-h2c7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55422",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:conda-forge/conda-forge.github.io\tGHSA-r5vj-wgjv-r524",
   "description": "conda-forge/conda-forge.github.io repository advisory GHSA-r5vj-wgjv-r524",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/conda-forge/conda-forge.github.io/security/advisories/GHSA-r5vj-wgjv-r524"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55498",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-83rw-5ffw-p798",
   "description": "error311/FileRise repository advisory GHSA-83rw-5ffw-p798",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-83rw-5ffw-p798"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55888",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:flatpak/xdg-desktop-portal\tGHSA-cm83-2936-gxjm",
   "description": "flatpak/xdg-desktop-portal repository advisory GHSA-cm83-2936-gxjm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/flatpak/xdg-desktop-portal/security/advisories/GHSA-cm83-2936-gxjm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55889",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:flatpak/xdg-desktop-portal\tGHSA-c5cf-79w8-pvfh",
   "description": "flatpak/xdg-desktop-portal repository advisory GHSA-c5cf-79w8-pvfh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/flatpak/xdg-desktop-portal/security/advisories/GHSA-c5cf-79w8-pvfh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48741",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:mz-automation/libiec61850\tGHSA-8mfr-hq64-9w33",
   "description": "mz-automation/libiec61850 repository advisory GHSA-8mfr-hq64-9w33",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/libiec61850/security/advisories/GHSA-8mfr-hq64-9w33"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48503",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:mz-automation/libiec61850\tGHSA-4c8m-jr3r-h8j2",
   "description": "mz-automation/libiec61850 repository advisory GHSA-4c8m-jr3r-h8j2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/libiec61850/security/advisories/GHSA-4c8m-jr3r-h8j2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55606",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:openwrt/odhcpd\tGHSA-x8x4-7gvf-gp45",
   "description": "openwrt/odhcpd repository advisory GHSA-x8x4-7gvf-gp45",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/odhcpd/security/advisories/GHSA-x8x4-7gvf-gp45"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57488",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:pupnp/pupnp\tGHSA-g6c2-x4r9-352g",
   "description": "pupnp/pupnp repository advisory GHSA-g6c2-x4r9-352g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pupnp/pupnp/security/advisories/GHSA-g6c2-x4r9-352g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57486",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:pupnp/pupnp\tGHSA-q54q-vx78-v9rq",
   "description": "pupnp/pupnp repository advisory GHSA-q54q-vx78-v9rq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pupnp/pupnp/security/advisories/GHSA-q54q-vx78-v9rq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57487",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:pupnp/pupnp\tGHSA-gcj7-j9f7-q84c",
   "description": "pupnp/pupnp repository advisory GHSA-gcj7-j9f7-q84c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pupnp/pupnp/security/advisories/GHSA-gcj7-j9f7-q84c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56723",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-374g-4f73-g7m7",
   "description": "zammad/zammad repository advisory GHSA-374g-4f73-g7m7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-374g-4f73-g7m7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56724",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-pv3q-74g5-w7fv",
   "description": "zammad/zammad repository advisory GHSA-pv3q-74g5-w7fv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-pv3q-74g5-w7fv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56725",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-45cx-9mrq-mmcj",
   "description": "zammad/zammad repository advisory GHSA-45cx-9mrq-mmcj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-45cx-9mrq-mmcj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56727",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-56jc-34c8-2xq4",
   "description": "zammad/zammad repository advisory GHSA-56jc-34c8-2xq4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-56jc-34c8-2xq4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56726",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-96hh-fmj3-h4hp",
   "description": "zammad/zammad repository advisory GHSA-96hh-fmj3-h4hp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-96hh-fmj3-h4hp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56732",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-6rmm-28j9-q99q",
   "description": "zammad/zammad repository advisory GHSA-6rmm-28j9-q99q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-6rmm-28j9-q99q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56730",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-pf47-8964-pp23",
   "description": "zammad/zammad repository advisory GHSA-pf47-8964-pp23",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-pf47-8964-pp23"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56728",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-jvcg-5539-vvc3",
   "description": "zammad/zammad repository advisory GHSA-jvcg-5539-vvc3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-jvcg-5539-vvc3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56729",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-4m54-p3mr-22g2",
   "description": "zammad/zammad repository advisory GHSA-4m54-p3mr-22g2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-4m54-p3mr-22g2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56731",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-p9xp-gx8r-4397",
   "description": "zammad/zammad repository advisory GHSA-p9xp-gx8r-4397",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-p9xp-gx8r-4397"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56734",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-q3cr-3wq3-29hx",
   "description": "zammad/zammad repository advisory GHSA-q3cr-3wq3-29hx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-q3cr-3wq3-29hx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56733",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-p3mg-2jxr-hww2",
   "description": "zammad/zammad repository advisory GHSA-p3mg-2jxr-hww2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-p3mg-2jxr-hww2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56735",
   "state": "RESERVED",
   "public_date": "2026-06-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-17"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-7fwx-3xr4-qm6w",
   "description": "zammad/zammad repository advisory GHSA-7fwx-3xr4-qm6w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 90,
   "clock_known": true,
   "hours_public": 2160,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-17",
   "advisory_days_public": 90,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-7fwx-3xr4-qm6w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-36849",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "alas,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-06-20",
    "ubuntu-osv": "2026-06-18",
    "csaf": "2026-07-08"
   },
   "refs": "alas:CVE-2026-36849;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11225-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11225-1.json;debian:tiff;ubuntu-osv:UBUNTU-CVE-2026-36849",
   "description": "Denial of Service via large SamplesPerPixel tag",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-20",
   "advisory_days_public": 87,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "tiff",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-36849.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11225-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-36849",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-36849"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57496",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-18",
    "osv": "2026-06-18"
   },
   "refs": "ghsa:GHSA-hxpf-9xvq-wph8;osv:PyPI:netlicensing-mcp",
   "description": "netlicensing-mcp: REST Path Traversal Bypasses Token Redaction",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netlicensing-mcp",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hxpf-9xvq-wph8",
    "osv": "https://osv.dev/list?q=CVE-2026-57496"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54683",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-18",
    "osv": "2026-06-18"
   },
   "refs": "ghsa:GHSA-jr45-52cw-69h5;osv:Maven:nl.nl-portal:documenten-api",
   "description": "NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nl.nl-portal",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-jr45-52cw-69h5",
    "osv": "https://osv.dev/list?q=CVE-2026-54683"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57441",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-18",
    "osv": "2026-06-18"
   },
   "refs": "ghsa:GHSA-j99q-93c9-h869;osv:npm:@bitbonsai/mcpvault",
   "description": "MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@bitbonsai/mcpvault",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-j99q-93c9-h869",
    "osv": "https://osv.dev/list?q=CVE-2026-57441"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57209",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-18",
    "osv": "2026-06-18"
   },
   "refs": "ghsa:GHSA-4jgr-pg2m-m988;osv:Go:github.com/dadrus/heimdall",
   "description": "Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/dadrus/heimdall",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-4jgr-pg2m-m988",
    "osv": "https://osv.dev/list?q=CVE-2026-57209"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57210",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-18",
    "osv": "2026-06-18"
   },
   "refs": "ghsa:GHSA-38x9-25wx-7fg2;osv:Go:https://github.com/dadrus/heimdall",
   "description": "Heimdall: IP Spoofing via Unvalidated Forwarding Headers",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "https",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-38x9-25wx-7fg2",
    "osv": "https://osv.dev/list?q=CVE-2026-57210"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57569",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-vj35-v9x5-vrxh",
   "description": "LycheeOrg/Lychee repository advisory GHSA-vj35-v9x5-vrxh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-vj35-v9x5-vrxh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57568",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-pgfr-x389-5p2h",
   "description": "LycheeOrg/Lychee repository advisory GHSA-pgfr-x389-5p2h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-pgfr-x389-5p2h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55587",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:aliasvault/aliasvault\tGHSA-f99p-jfhr-6ffc",
   "description": "aliasvault/aliasvault repository advisory GHSA-f99p-jfhr-6ffc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/aliasvault/aliasvault/security/advisories/GHSA-f99p-jfhr-6ffc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47168",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-7q78-jjr9-mqcg",
   "description": "espocrm/espocrm repository advisory GHSA-7q78-jjr9-mqcg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-7q78-jjr9-mqcg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46708",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-mqp6-23xq-7q3r",
   "description": "espocrm/espocrm repository advisory GHSA-mqp6-23xq-7q3r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-mqp6-23xq-7q3r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46694",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-cg9f-34hj-p238",
   "description": "espocrm/espocrm repository advisory GHSA-cg9f-34hj-p238",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-cg9f-34hj-p238"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46691",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-rrcj-rhc2-ch5q",
   "description": "espocrm/espocrm repository advisory GHSA-rrcj-rhc2-ch5q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-rrcj-rhc2-ch5q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55222",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:ilbers/isar\tGHSA-rq66-pfw5-whqq",
   "description": "ilbers/isar repository advisory GHSA-rq66-pfw5-whqq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ilbers/isar/security/advisories/GHSA-rq66-pfw5-whqq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55486",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-975w-g9gj-xq48",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-975w-g9gj-xq48",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-975w-g9gj-xq48"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55465",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-v5h4-qrx3-qg3h",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-v5h4-qrx3-qg3h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-v5h4-qrx3-qg3h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55463",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-h5m9-fpvw-qr36",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-h5m9-fpvw-qr36",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-h5m9-fpvw-qr36"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55459",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-7vrv-qh6g-gfx7",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-7vrv-qh6g-gfx7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-7vrv-qh6g-gfx7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55457",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-4qpq-f4r6-7cc6",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-4qpq-f4r6-7cc6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-4qpq-f4r6-7cc6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55444",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-763m-wjm9-6873",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-763m-wjm9-6873",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-763m-wjm9-6873"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55442",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-2r24-qxpf-cj65",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-2r24-qxpf-cj65",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-2r24-qxpf-cj65"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46652",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-r386-2frm-w3v6",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-r386-2frm-w3v6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-r386-2frm-w3v6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46651",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-79jg-3m2m-jgc8",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-79jg-3m2m-jgc8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-79jg-3m2m-jgc8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46347",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-hw9w-7r6g-2fjc",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-hw9w-7r6g-2fjc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-hw9w-7r6g-2fjc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46346",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:intranda/goobi-viewer-core\tGHSA-gj5g-4rxf-8rmq",
   "description": "intranda/goobi-viewer-core repository advisory GHSA-gj5g-4rxf-8rmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-gj5g-4rxf-8rmq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53918",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:openwrt/odhcpd\tGHSA-44ff-jcwh-wgc2",
   "description": "openwrt/odhcpd repository advisory GHSA-44ff-jcwh-wgc2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/odhcpd/security/advisories/GHSA-44ff-jcwh-wgc2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53920",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:openwrt/odhcpd\tGHSA-p769-5v73-pc4f",
   "description": "openwrt/odhcpd repository advisory GHSA-p769-5v73-pc4f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/odhcpd/security/advisories/GHSA-p769-5v73-pc4f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53921",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:openwrt/odhcpd\tGHSA-7fwx-hhrg-3496",
   "description": "openwrt/odhcpd repository advisory GHSA-7fwx-hhrg-3496",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58491",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-18"
   },
   "refs": "ghsa-repos:warp-tech/warpgate\tGHSA-3c3w-75j2-7h74",
   "description": "warp-tech/warpgate repository advisory GHSA-3c3w-75j2-7h74",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/warp-tech/warpgate/security/advisories/GHSA-3c3w-75j2-7h74"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41083",
   "state": "RESERVED",
   "public_date": "2026-06-18",
   "sources": "alpine,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-06-18"
   },
   "refs": "alpine:ocaml;osv:opam:ocaml",
   "description": "Windows command execution via filename quotes.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 89,
   "clock_known": true,
   "hours_public": 2136,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-18",
   "advisory_days_public": 89,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ocaml",
   "ecosystem": "opam",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-41083",
    "osv": "https://osv.dev/list?q=CVE-2026-41083"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57168",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-19",
    "osv": "2026-06-19"
   },
   "refs": "ghsa:GHSA-h3m5-97jq-qjrf;osv:Maven:io.openremote:openremote-manager",
   "description": "OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.openremote",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-h3m5-97jq-qjrf",
    "osv": "https://osv.dev/list?q=CVE-2026-57168"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57442",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-19",
    "osv": "2026-06-19"
   },
   "refs": "ghsa:GHSA-9c83-rr99-vfwj;osv:npm:@bitbonsai/mcpvault",
   "description": "MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@bitbonsai/mcpvault",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-9c83-rr99-vfwj",
    "osv": "https://osv.dev/list?q=CVE-2026-57442"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55414",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-19",
    "osv": "2026-06-19"
   },
   "refs": "ghsa:GHSA-xm3x-9cfw-jhx4;osv:Maven:nl.nl-portal:form",
   "description": "NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nl.nl-portal",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-xm3x-9cfw-jhx4",
    "osv": "https://osv.dev/list?q=CVE-2026-55414"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55375",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-19",
    "osv": "2026-06-19"
   },
   "refs": "ghsa:GHSA-37pm-83g7-r22v;osv:Packagist:jleehr/canto-saas-api",
   "description": "canto-saas-api: OAuth credentials exposed in URL query string and exception messages",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "jleehr/canto-saas-api",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-37pm-83g7-r22v",
    "osv": "https://osv.dev/list?q=CVE-2026-55375"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55374",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-19",
    "osv": "2026-06-19"
   },
   "refs": "ghsa:GHSA-9qfv-wgh2-m6p8;osv:Packagist:jleehr/canto-saas-api",
   "description": "canto-saas-api: Authenticated API requests can be redirected via unencoded path variables",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "jleehr/canto-saas-api",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-9qfv-wgh2-m6p8",
    "osv": "https://osv.dev/list?q=CVE-2026-55374"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49442",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-19",
    "csaf": "2026-06-21"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2018\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2018.json;ghsa-repos:Cacti/cacti\tGHSA-m7v2-f3xw-3qh7",
   "description": "Cacti/cacti repository advisory GHSA-m7v2-f3xw-3qh7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2018.json",
    "ghsa-repos": "https://github.com/Cacti/cacti/security/advisories/GHSA-m7v2-f3xw-3qh7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58504",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-19"
   },
   "refs": "ghsa-repos:jgraph/drawio\tGHSA-c76x-r78m-phwx",
   "description": "jgraph/drawio repository advisory GHSA-c76x-r78m-phwx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jgraph/drawio/security/advisories/GHSA-c76x-r78m-phwx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58255",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-19"
   },
   "refs": "ghsa-repos:jhuckaby/Cronicle\tGHSA-9xpg-9w3g-mpwj",
   "description": "jhuckaby/Cronicle repository advisory GHSA-9xpg-9w3g-mpwj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jhuckaby/Cronicle/security/advisories/GHSA-9xpg-9w3g-mpwj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58202",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-19"
   },
   "refs": "ghsa-repos:open-reception/appointment-booking-software\tGHSA-w5g9-g2p4-2g4m",
   "description": "open-reception/appointment-booking-software repository advisory GHSA-w5g9-g2p4-2g4m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-w5g9-g2p4-2g4m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58496",
   "state": "RESERVED",
   "public_date": "2026-06-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-19"
   },
   "refs": "ghsa-repos:thorvg/thorvg\tGHSA-crfw-c34f-vqrj",
   "description": "thorvg/thorvg repository advisory GHSA-crfw-c34f-vqrj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 88,
   "clock_known": true,
   "hours_public": 2112,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-19",
   "advisory_days_public": 88,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/thorvg/thorvg/security/advisories/GHSA-crfw-c34f-vqrj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44179",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-06-22",
    "ghsa-repos": "2026-06-21",
    "osv": "2026-06-22"
   },
   "refs": "ghsa-repos:xwikisas/xwiki-pro-macros\tGHSA-w56x-9778-rppx;ghsa:GHSA-w56x-9778-rppx;osv:Maven:com.xwiki.pro:xwiki-pro-macros",
   "description": "xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "com.xwiki.pro",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-w56x-9778-rppx",
    "ghsa-repos": "https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-w56x-9778-rppx",
    "osv": "https://osv.dev/list?q=CVE-2026-44179"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59959",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:HappySeaFox/sail\tGHSA-5g8g-g347-84m8",
   "description": "HappySeaFox/sail repository advisory GHSA-5g8g-g347-84m8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HappySeaFox/sail/security/advisories/GHSA-5g8g-g347-84m8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59967",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:TandoorRecipes/recipes\tGHSA-4vw7-c646-g23w",
   "description": "TandoorRecipes/recipes repository advisory GHSA-4vw7-c646-g23w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-4vw7-c646-g23w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59970",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:TandoorRecipes/recipes\tGHSA-wq4h-2r8x-cv65",
   "description": "TandoorRecipes/recipes repository advisory GHSA-wq4h-2r8x-cv65",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-wq4h-2r8x-cv65"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59962",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:TandoorRecipes/recipes\tGHSA-4x57-2q4q-xwpp",
   "description": "TandoorRecipes/recipes repository advisory GHSA-4x57-2q4q-xwpp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-4x57-2q4q-xwpp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59963",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:TandoorRecipes/recipes\tGHSA-cqj3-64qw-4w52",
   "description": "TandoorRecipes/recipes repository advisory GHSA-cqj3-64qw-4w52",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-cqj3-64qw-4w52"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59966",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:TandoorRecipes/recipes\tGHSA-f2gw-c2c7-59v7",
   "description": "TandoorRecipes/recipes repository advisory GHSA-f2gw-c2c7-59v7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-f2gw-c2c7-59v7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50539",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-p4pg-v57g-7jf6",
   "description": "xibosignage/xibo-cms repository advisory GHSA-p4pg-v57g-7jf6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-p4pg-v57g-7jf6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50541",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-v6xr-pmg9-qpmv",
   "description": "xibosignage/xibo-cms repository advisory GHSA-v6xr-pmg9-qpmv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-v6xr-pmg9-qpmv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52729",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-7j3h-48f7-w4fr",
   "description": "xibosignage/xibo-cms repository advisory GHSA-7j3h-48f7-w4fr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-7j3h-48f7-w4fr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50542",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-wj8r-32gf-6f5f",
   "description": "xibosignage/xibo-cms repository advisory GHSA-wj8r-32gf-6f5f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-wj8r-32gf-6f5f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50543",
   "state": "RESERVED",
   "public_date": "2026-06-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-21"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-737f-mfxg-jv9q",
   "description": "xibosignage/xibo-cms repository advisory GHSA-737f-mfxg-jv9q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 86,
   "clock_known": true,
   "hours_public": 2064,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-21",
   "advisory_days_public": 86,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-737f-mfxg-jv9q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54604",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-06-22"
   },
   "refs": "debian:openslide;ubuntu-osv:UBUNTU-CVE-2026-54604",
   "description": "openslide",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "openslide",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-54604",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-54604"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83812",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:ChurchCRM/CRM\tGHSA-8rv4-2mxp-gh5w",
   "description": "ChurchCRM/CRM repository advisory GHSA-8rv4-2mxp-gh5w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ChurchCRM/CRM/security/advisories/GHSA-8rv4-2mxp-gh5w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61611",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-48vf-fwx6-2ph6",
   "description": "LycheeOrg/Lychee repository advisory GHSA-48vf-fwx6-2ph6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-48vf-fwx6-2ph6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61610",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-qcqq-p4pq-7r77",
   "description": "LycheeOrg/Lychee repository advisory GHSA-qcqq-p4pq-7r77",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-qcqq-p4pq-7r77"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61575",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-w2g8-p296-r5g9",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-w2g8-p296-r5g9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-w2g8-p296-r5g9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61573",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-p9x3-679g-pwf5",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-p9x3-679g-pwf5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-p9x3-679g-pwf5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61572",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-cvhm-j9cp-8w59",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-cvhm-j9cp-8w59",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-cvhm-j9cp-8w59"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61571",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-297p-4mj8-28wm",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-297p-4mj8-28wm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-297p-4mj8-28wm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61569",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-2rrq-xf8q-3qpf",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-2rrq-xf8q-3qpf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-2rrq-xf8q-3qpf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61567",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-rf63-6vwm-wv8p",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-rf63-6vwm-wv8p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-rf63-6vwm-wv8p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61564",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:WWBN/AVideo-Encoder\tGHSA-xrj3-cqm8-r992",
   "description": "WWBN/AVideo-Encoder repository advisory GHSA-xrj3-cqm8-r992",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-xrj3-cqm8-r992"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61554",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:jm33-m0/emp3r0r\tGHSA-4595-rvpx-4q34",
   "description": "jm33-m0/emp3r0r repository advisory GHSA-4595-rvpx-4q34",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-4595-rvpx-4q34"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61612",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-22"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-798p-78g2-v556",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-798p-78g2-v556",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-798p-78g2-v556"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54634",
   "state": "RESERVED",
   "public_date": "2026-06-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-22"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11089-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11089-1.json",
   "description": "CVE-2026-54634",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 85,
   "clock_known": true,
   "hours_public": 2040,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-22",
   "advisory_days_public": 85,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11089-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55556",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "alas,csaf,debian,ghsa-repos",
   "feed_count": 4,
   "dates": {
    "alas": "2026-06-25",
    "ghsa-repos": "2026-06-23",
    "csaf": "2026-06-23"
   },
   "refs": "alas:CVE-2026-55556;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2045\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2045.json;debian:rsyslog;ghsa-repos:rsyslog/rsyslog\tGHSA-947w-69ph-mc2r",
   "description": "The issue is in the HTTP Basic Authentication parser used by imhttp.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "rsyslog",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-55556.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2045.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-55556",
    "ghsa-repos": "https://github.com/rsyslog/rsyslog/security/advisories/GHSA-947w-69ph-mc2r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45049",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-23",
    "osv": "2026-06-23"
   },
   "refs": "ghsa:GHSA-r9pv-5rpp-vm8g;osv:Maven:org.openidentityplatform.openam:openam-federation",
   "description": "OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.openidentityplatform.openam",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-r9pv-5rpp-vm8g",
    "osv": "https://osv.dev/list?q=CVE-2026-45049"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83811",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:ChurchCRM/CRM\tGHSA-3g57-j655-gjv3",
   "description": "ChurchCRM/CRM repository advisory GHSA-3g57-j655-gjv3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ChurchCRM/CRM/security/advisories/GHSA-3g57-j655-gjv3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61719",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-qm7p-cprp-f974",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-qm7p-cprp-f974",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-qm7p-cprp-f974"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61673",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-83p7-cx5x-7g34",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-83p7-cx5x-7g34",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-83p7-cx5x-7g34"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61671",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-rf87-2prr-f2p2",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-rf87-2prr-f2p2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-rf87-2prr-f2p2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44344",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-8rj2-88v5-mx6w",
   "description": "chamilo/chamilo-lms repository advisory GHSA-8rj2-88v5-mx6w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-8rj2-88v5-mx6w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45141",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-p2qq-wjp2-j334",
   "description": "chamilo/chamilo-lms repository advisory GHSA-p2qq-wjp2-j334",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-p2qq-wjp2-j334"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45145",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-pr59-4rm7-ghwx",
   "description": "chamilo/chamilo-lms repository advisory GHSA-pr59-4rm7-ghwx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-pr59-4rm7-ghwx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45144",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-9833-c7cj-x9xm",
   "description": "chamilo/chamilo-lms repository advisory GHSA-9833-c7cj-x9xm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-9833-c7cj-x9xm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61730",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-pm2w-mmc3-h8hc",
   "description": "socfortress/CoPilot repository advisory GHSA-pm2w-mmc3-h8hc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-pm2w-mmc3-h8hc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61729",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-x8gc-f8p4-frc2",
   "description": "socfortress/CoPilot repository advisory GHSA-x8gc-f8p4-frc2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-x8gc-f8p4-frc2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61728",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-8hqj-cqcc-5f6w",
   "description": "socfortress/CoPilot repository advisory GHSA-8hqj-cqcc-5f6w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-8hqj-cqcc-5f6w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61708",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-6j26-wcv6-gp3f",
   "description": "socfortress/CoPilot repository advisory GHSA-6j26-wcv6-gp3f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-6j26-wcv6-gp3f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61707",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-23"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-7q83-228r-wfh5",
   "description": "socfortress/CoPilot repository advisory GHSA-7q83-228r-wfh5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-7q83-228r-wfh5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11704",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-11704",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11705",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-11705",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12546",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-12546",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52895",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-52895",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52896",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-52896",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52897",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-52897",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52898",
   "state": "RESERVED",
   "public_date": "2026-06-23",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json",
   "description": "CVE-2026-52898",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 84,
   "clock_known": true,
   "hours_public": 2016,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-23",
   "advisory_days_public": 84,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2055.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46499",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:CollaboraOnline/online\tGHSA-27j2-3cqv-cc5q",
   "description": "CollaboraOnline/online repository advisory GHSA-27j2-3cqv-cc5q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CollaboraOnline/online/security/advisories/GHSA-27j2-3cqv-cc5q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48164",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:CollaboraOnline/online\tGHSA-wgmm-q3ch-64jj",
   "description": "CollaboraOnline/online repository advisory GHSA-wgmm-q3ch-64jj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CollaboraOnline/online/security/advisories/GHSA-wgmm-q3ch-64jj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61838",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-735c-2wqc-x29r",
   "description": "LycheeOrg/Lychee repository advisory GHSA-735c-2wqc-x29r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-735c-2wqc-x29r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55600",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-qqrh-jjhg-vv5r",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-qqrh-jjhg-vv5r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-qqrh-jjhg-vv5r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61806",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:frappe/lms\tGHSA-xjj9-h64v-254g",
   "description": "frappe/lms repository advisory GHSA-xjj9-h64v-254g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/lms/security/advisories/GHSA-xjj9-h64v-254g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61805",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:frappe/lms\tGHSA-4566-2phx-68gh",
   "description": "frappe/lms repository advisory GHSA-4566-2phx-68gh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/lms/security/advisories/GHSA-4566-2phx-68gh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61803",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:frappe/lms\tGHSA-g5jj-q8m7-359c",
   "description": "frappe/lms repository advisory GHSA-g5jj-q8m7-359c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/lms/security/advisories/GHSA-g5jj-q8m7-359c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39375",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:frappe/lms\tGHSA-9fqj-95wr-6hm6",
   "description": "frappe/lms repository advisory GHSA-9fqj-95wr-6hm6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/lms/security/advisories/GHSA-9fqj-95wr-6hm6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50000",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:freedomofpress/securedrop\tGHSA-78xq-8jf3-gpfx",
   "description": "freedomofpress/securedrop repository advisory GHSA-78xq-8jf3-gpfx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freedomofpress/securedrop/security/advisories/GHSA-78xq-8jf3-gpfx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61749",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:inventree/InvenTree\tGHSA-568x-qh23-wh8g",
   "description": "inventree/InvenTree repository advisory GHSA-568x-qh23-wh8g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/inventree/InvenTree/security/advisories/GHSA-568x-qh23-wh8g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61748",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:inventree/InvenTree\tGHSA-7w96-99fj-8g7x",
   "description": "inventree/InvenTree repository advisory GHSA-7w96-99fj-8g7x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/inventree/InvenTree/security/advisories/GHSA-7w96-99fj-8g7x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61746",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:inventree/InvenTree\tGHSA-45f6-v6jq-99f7",
   "description": "inventree/InvenTree repository advisory GHSA-45f6-v6jq-99f7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/inventree/InvenTree/security/advisories/GHSA-45f6-v6jq-99f7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61747",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:inventree/InvenTree\tGHSA-xjpv-cwpw-7qx8",
   "description": "inventree/InvenTree repository advisory GHSA-xjpv-cwpw-7qx8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/inventree/InvenTree/security/advisories/GHSA-xjpv-cwpw-7qx8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61745",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:inventree/InvenTree\tGHSA-c9wp-mw98-gfrj",
   "description": "inventree/InvenTree repository advisory GHSA-c9wp-mw98-gfrj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/inventree/InvenTree/security/advisories/GHSA-c9wp-mw98-gfrj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61744",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:inventree/InvenTree\tGHSA-6pm3-m334-mr4j",
   "description": "inventree/InvenTree repository advisory GHSA-6pm3-m334-mr4j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/inventree/InvenTree/security/advisories/GHSA-6pm3-m334-mr4j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-27844",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-3q35-m6xv-23gj",
   "description": "owncloud/security-advisories repository advisory GHSA-3q35-m6xv-23gj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-3q35-m6xv-23gj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61739",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-c6jc-rh4j-wg88",
   "description": "socfortress/CoPilot repository advisory GHSA-c6jc-rh4j-wg88",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-c6jc-rh4j-wg88"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61738",
   "state": "RESERVED",
   "public_date": "2026-06-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-24"
   },
   "refs": "ghsa-repos:socfortress/CoPilot\tGHSA-q3g8-3cf7-744f",
   "description": "socfortress/CoPilot repository advisory GHSA-q3g8-3cf7-744f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 83,
   "clock_known": true,
   "hours_public": 1992,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-24",
   "advisory_days_public": 83,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/socfortress/CoPilot/security/advisories/GHSA-q3g8-3cf7-744f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-13324",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,debian,redhat,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-06-29",
    "redhat": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-13324\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13324.json;debian:geary;redhat:CVE-2026-13324;ubuntu-osv:UBUNTU-CVE-2026-13324",
   "description": "geary",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "geary",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13324.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-13324",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-13324",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-13324"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46560",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-06-25",
    "osv": "2026-06-25"
   },
   "refs": "ghsa:GHSA-386j-6m86-78f9;osv:Maven:org.openidentityplatform.openam:openam-radius",
   "description": "OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.openidentityplatform.openam",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-386j-6m86-78f9",
    "osv": "https://osv.dev/list?q=CVE-2026-46560"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55098",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:Basekick-Labs/arc\tGHSA-93cm-2v4m-c56c",
   "description": "Basekick-Labs/arc repository advisory GHSA-93cm-2v4m-c56c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Basekick-Labs/arc/security/advisories/GHSA-93cm-2v4m-c56c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62179",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-mxmx-rh57-jx58",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-mxmx-rh57-jx58",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-mxmx-rh57-jx58"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62181",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-cv3g-hj65-pcfh",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-cv3g-hj65-pcfh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cv3g-hj65-pcfh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62176",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-g6j7-pffp-8whg",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-g6j7-pffp-8whg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g6j7-pffp-8whg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62170",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-q7m5-3jmv-vm48",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-q7m5-3jmv-vm48",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-q7m5-3jmv-vm48"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62171",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-4r3p-w3mc-5v34",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-4r3p-w3mc-5v34",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4r3p-w3mc-5v34"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62167",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-4gfv-wg42-7jw5",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-4gfv-wg42-7jw5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4gfv-wg42-7jw5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62166",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-4xxv-6wmf-xf45",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-4xxv-6wmf-xf45",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4xxv-6wmf-xf45"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62163",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:MervinPraison/PraisonAI\tGHSA-qjw5-xwrp-xwpq",
   "description": "MervinPraison/PraisonAI repository advisory GHSA-qjw5-xwrp-xwpq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qjw5-xwrp-xwpq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57193",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-r6c2-hwc2-j4mp",
   "description": "asterisk/asterisk repository advisory GHSA-r6c2-hwc2-j4mp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-r6c2-hwc2-j4mp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57203",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:asterisk/asterisk\tGHSA-xgj6-2gc5-5x9c",
   "description": "asterisk/asterisk repository advisory GHSA-xgj6-2gc5-5x9c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-xgj6-2gc5-5x9c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57190",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-ph27-3m5q-mj5m",
   "description": "asterisk/asterisk repository advisory GHSA-ph27-3m5q-mj5m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-ph27-3m5q-mj5m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57197",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-8jhw-m2hg-vp3h",
   "description": "asterisk/asterisk repository advisory GHSA-8jhw-m2hg-vp3h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-8jhw-m2hg-vp3h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57188",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-mxgm-8c6f-5p8f",
   "description": "asterisk/asterisk repository advisory GHSA-mxgm-8c6f-5p8f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-mxgm-8c6f-5p8f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57191",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:asterisk/asterisk\tGHSA-589g-qgf8-m6mx",
   "description": "asterisk/asterisk repository advisory GHSA-589g-qgf8-m6mx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-589g-qgf8-m6mx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57199",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-q9fr-m7g8-6ph5",
   "description": "asterisk/asterisk repository advisory GHSA-q9fr-m7g8-6ph5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-q9fr-m7g8-6ph5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57201",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-x348-j6c9-77f3",
   "description": "asterisk/asterisk repository advisory GHSA-x348-j6c9-77f3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-x348-j6c9-77f3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57192",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-qf8j-jp7h-c5hx",
   "description": "asterisk/asterisk repository advisory GHSA-qf8j-jp7h-c5hx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-qf8j-jp7h-c5hx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57195",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:asterisk/asterisk\tGHSA-3rhj-hhw7-m6fw",
   "description": "asterisk/asterisk repository advisory GHSA-3rhj-hhw7-m6fw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-3rhj-hhw7-m6fw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57196",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-4pgv-j3mr-3rcp",
   "description": "asterisk/asterisk repository advisory GHSA-4pgv-j3mr-3rcp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-4pgv-j3mr-3rcp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57185",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-8jw3-ccr9-xrmf",
   "description": "asterisk/asterisk repository advisory GHSA-8jw3-ccr9-xrmf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-8jw3-ccr9-xrmf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57189",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-j2mm-57pq-jh94",
   "description": "asterisk/asterisk repository advisory GHSA-j2mm-57pq-jh94",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-j2mm-57pq-jh94"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57198",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:asterisk/asterisk\tGHSA-vfhr-r9x9-c687",
   "description": "asterisk/asterisk repository advisory GHSA-vfhr-r9x9-c687",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-vfhr-r9x9-c687"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57202",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-vrfp-mg3q-3959",
   "description": "asterisk/asterisk repository advisory GHSA-vrfp-mg3q-3959",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-vrfp-mg3q-3959"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57184",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-746q-794h-cc7f",
   "description": "asterisk/asterisk repository advisory GHSA-746q-794h-cc7f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-746q-794h-cc7f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57200",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-wcvv-g26m-wx5c",
   "description": "asterisk/asterisk repository advisory GHSA-wcvv-g26m-wx5c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-wcvv-g26m-wx5c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57187",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:asterisk/asterisk\tGHSA-g8q2-p36q-94f6",
   "description": "asterisk/asterisk repository advisory GHSA-g8q2-p36q-94f6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-g8q2-p36q-94f6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57194",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:asterisk/asterisk\tGHSA-3g56-cgrh-95p5",
   "description": "asterisk/asterisk repository advisory GHSA-3g56-cgrh-95p5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-3g56-cgrh-95p5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57186",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-06-25",
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2094\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json;ghsa-repos:asterisk/asterisk\tGHSA-h5hv-jmgj-92q2",
   "description": "asterisk/asterisk repository advisory GHSA-h5hv-jmgj-92q2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2094.json",
    "ghsa-repos": "https://github.com/asterisk/asterisk/security/advisories/GHSA-h5hv-jmgj-92q2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62162",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:cardano-scaling/hydra\tGHSA-gfpc-m687-p7h5",
   "description": "cardano-scaling/hydra repository advisory GHSA-gfpc-m687-p7h5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cardano-scaling/hydra/security/advisories/GHSA-gfpc-m687-p7h5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57493",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-r55g-3hcc-6jx7",
   "description": "error311/FileRise repository advisory GHSA-r55g-3hcc-6jx7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-r55g-3hcc-6jx7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57492",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-g555-3rg9-wrq8",
   "description": "error311/FileRise repository advisory GHSA-g555-3rg9-wrq8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-g555-3rg9-wrq8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57491",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-c4g2-8fg6-5xrr",
   "description": "error311/FileRise repository advisory GHSA-c4g2-8fg6-5xrr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-c4g2-8fg6-5xrr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57490",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-cx7g-xhj8-8cx3",
   "description": "error311/FileRise repository advisory GHSA-cx7g-xhj8-8cx3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-cx7g-xhj8-8cx3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57489",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-98pg-w3jp-r8fv",
   "description": "error311/FileRise repository advisory GHSA-98pg-w3jp-r8fv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-98pg-w3jp-r8fv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61801",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:moby/sys\tGHSA-mjcv-p78q-w5fw",
   "description": "moby/sys repository advisory GHSA-mjcv-p78q-w5fw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62298",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:mouse07410/asn1c\tGHSA-rcj5-gcvg-x796",
   "description": "mouse07410/asn1c repository advisory GHSA-rcj5-gcvg-x796",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mouse07410/asn1c/security/advisories/GHSA-rcj5-gcvg-x796"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62247",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:supabase/realtime\tGHSA-rcr8-2525-4r7p",
   "description": "supabase/realtime repository advisory GHSA-rcr8-2525-4r7p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/supabase/realtime/security/advisories/GHSA-rcr8-2525-4r7p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61525",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-25"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-xp9w-hhf3-vfxx",
   "description": "zammad/zammad repository advisory GHSA-xp9w-hhf3-vfxx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-xp9w-hhf3-vfxx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-13173",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2085\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2085.json",
   "description": "CVE-2025-13173",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-2613",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2085\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2085.json",
   "description": "CVE-2026-2613",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-4052",
   "state": "RESERVED",
   "public_date": "2026-06-25",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2085\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2085.json",
   "description": "CVE-2026-4052",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 82,
   "clock_known": true,
   "hours_public": 1968,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-25",
   "advisory_days_public": 82,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2085.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62679",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-j5ff-34x8-xxqg",
   "description": "LycheeOrg/Lychee repository advisory GHSA-j5ff-34x8-xxqg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-j5ff-34x8-xxqg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62308",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:Quenary/tugtainer\tGHSA-c2h5-ppv9-7vrq",
   "description": "Quenary/tugtainer repository advisory GHSA-c2h5-ppv9-7vrq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62364",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:WeblateOrg/wlc\tGHSA-3mqq-hv9c-85hc",
   "description": "WeblateOrg/wlc repository advisory GHSA-3mqq-hv9c-85hc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61850",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:akuity/kargo\tGHSA-wp4p-hr79-q4g8",
   "description": "akuity/kargo repository advisory GHSA-wp4p-hr79-q4g8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/akuity/kargo/security/advisories/GHSA-wp4p-hr79-q4g8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62302",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:franklioxygen/MyTube\tGHSA-rwwf-29mq-5j43",
   "description": "franklioxygen/MyTube repository advisory GHSA-rwwf-29mq-5j43",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/franklioxygen/MyTube/security/advisories/GHSA-rwwf-29mq-5j43"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62301",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:franklioxygen/MyTube\tGHSA-hcm6-w6x8-6jhr",
   "description": "franklioxygen/MyTube repository advisory GHSA-hcm6-w6x8-6jhr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/franklioxygen/MyTube/security/advisories/GHSA-hcm6-w6x8-6jhr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55493",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:kohler/hotcrp\tGHSA-x3g6-4c5h-7p29",
   "description": "kohler/hotcrp repository advisory GHSA-x3g6-4c5h-7p29",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kohler/hotcrp/security/advisories/GHSA-x3g6-4c5h-7p29"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62333",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:openvm-org/openvm\tGHSA-396x-v8w4-9x82",
   "description": "openvm-org/openvm repository advisory GHSA-396x-v8w4-9x82",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openvm-org/openvm/security/advisories/GHSA-396x-v8w4-9x82"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62334",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:openvm-org/openvm\tGHSA-j29p-wr24-hp4f",
   "description": "openvm-org/openvm repository advisory GHSA-j29p-wr24-hp4f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openvm-org/openvm/security/advisories/GHSA-j29p-wr24-hp4f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62335",
   "state": "RESERVED",
   "public_date": "2026-06-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-26"
   },
   "refs": "ghsa-repos:openvm-org/openvm\tGHSA-w82q-w67c-67wv",
   "description": "openvm-org/openvm repository advisory GHSA-w82q-w67c-67wv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 81,
   "clock_known": true,
   "hours_public": 1944,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-26",
   "advisory_days_public": 81,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openvm-org/openvm/security/advisories/GHSA-w82q-w67c-67wv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40573",
   "state": "RESERVED",
   "public_date": "2026-06-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-27"
   },
   "refs": "ghsa-repos:MinecAnton209/NovumOS\tGHSA-rq9v-wxp3-ffrr",
   "description": "MinecAnton209/NovumOS repository advisory GHSA-rq9v-wxp3-ffrr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 80,
   "clock_known": true,
   "hours_public": 1920,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-27",
   "advisory_days_public": 80,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MinecAnton209/NovumOS/security/advisories/GHSA-rq9v-wxp3-ffrr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-13606",
   "state": "RESERVED",
   "public_date": "2026-06-28",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-30",
    "redhat": "2026-06-28",
    "csaf": "2026-07-01"
   },
   "refs": "alas:CVE-2026-13606;csaf:SUSE Product Security Team\tCVE-2026-13606\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-13606.json;debian:graphicsmagick;redhat:CVE-2026-13606;ubuntu-osv:UBUNTU-CVE-2026-13606",
   "description": "A flaw was found in GraphicsMagick's Photo CD (PCD) decoder.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 79,
   "clock_known": true,
   "hours_public": 1896,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-28",
   "advisory_days_public": 79,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "graphicsmagick",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-13606.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-13606.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-13606",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-13606",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-13606"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62966",
   "state": "RESERVED",
   "public_date": "2026-06-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-28"
   },
   "refs": "ghsa-repos:ESP32Async/ESPAsyncWebServer\tGHSA-8m8p-vhxc-jmjw",
   "description": "ESP32Async/ESPAsyncWebServer repository advisory GHSA-8m8p-vhxc-jmjw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 79,
   "clock_known": true,
   "hours_public": 1896,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-28",
   "advisory_days_public": 79,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ESP32Async/ESPAsyncWebServer/security/advisories/GHSA-8m8p-vhxc-jmjw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75608",
   "state": "RESERVED",
   "public_date": "2026-06-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-28"
   },
   "refs": "ghsa-repos:blakeblackshear/frigate\tGHSA-mgh5-cr9h-g6hr",
   "description": "blakeblackshear/frigate repository advisory GHSA-mgh5-cr9h-g6hr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 79,
   "clock_known": true,
   "hours_public": 1896,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-28",
   "advisory_days_public": 79,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/blakeblackshear/frigate/security/advisories/GHSA-mgh5-cr9h-g6hr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75607",
   "state": "RESERVED",
   "public_date": "2026-06-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-28"
   },
   "refs": "ghsa-repos:blakeblackshear/frigate\tGHSA-r5fm-h944-8chq",
   "description": "blakeblackshear/frigate repository advisory GHSA-r5fm-h944-8chq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 79,
   "clock_known": true,
   "hours_public": 1896,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-28",
   "advisory_days_public": 79,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/blakeblackshear/frigate/security/advisories/GHSA-r5fm-h944-8chq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62965",
   "state": "RESERVED",
   "public_date": "2026-06-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-28"
   },
   "refs": "ghsa-repos:sabnzbd/sabnzbd\tGHSA-hxwh-mmrg-p8f5",
   "description": "sabnzbd/sabnzbd repository advisory GHSA-hxwh-mmrg-p8f5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 79,
   "clock_known": true,
   "hours_public": 1896,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-28",
   "advisory_days_public": 79,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-hxwh-mmrg-p8f5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-6425",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-29"
   },
   "refs": "alas:CVE-2026-6425;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-6425",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-6425.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-6425",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-6425"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48003",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-29"
   },
   "refs": "alas:CVE-2026-48003;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-48003",
   "description": "Incorrect loop bounds in vnc_update_freq result in iterating past the last row and past the last column in the VNC stats array.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-48003.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-48003",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-48003"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48002",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-29"
   },
   "refs": "alas:CVE-2026-48002;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-48002",
   "description": "Incorrect calculation of the boundary condition when tracking lossy rectangles in the worker thread will result in an OOB write which can corrupt further worker state, and/or trigger any guard pages that may lie beyond the VncWorker struct.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-48002.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-48002",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-48002"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48915",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-29"
   },
   "refs": "alas:CVE-2026-48915;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-48915",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-48915.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-48915",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-48915"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-8343",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-29"
   },
   "refs": "alas:CVE-2026-8343;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-8343",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-8343.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-8343",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-8343"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48004",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "alas,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-07-01",
    "ubuntu-osv": "2026-06-29",
    "csaf": "2026-07-07"
   },
   "refs": "alas:CVE-2026-48004;csaf:SUSE Product Security Team\tSUSE-SU-2026:22550-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_22550-1.json;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-48004",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-48004.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_22550-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-48004",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-48004"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61552",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa-repos": "2026-06-29"
   },
   "refs": "debian:icinga2;ghsa-repos:Icinga/icinga2\tGHSA-jgqj-x5j9-vgcm;ubuntu-osv:UBUNTU-CVE-2026-61552;ubuntu:CVE-2026-61552",
   "description": "icinga2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "icinga2",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61552",
    "ghsa-repos": "https://github.com/Icinga/icinga2/security/advisories/GHSA-jgqj-x5j9-vgcm",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61552",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61552"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61551",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa-repos": "2026-06-29"
   },
   "refs": "debian:icinga2;ghsa-repos:Icinga/icinga2\tGHSA-wh38-wg57-5w7g;ubuntu-osv:UBUNTU-CVE-2026-61551;ubuntu:CVE-2026-61551",
   "description": "icinga2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "icinga2",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61551",
    "ghsa-repos": "https://github.com/Icinga/icinga2/security/advisories/GHSA-wh38-wg57-5w7g",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61551",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61551"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61550",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa-repos": "2026-06-29"
   },
   "refs": "debian:icinga2;ghsa-repos:Icinga/icinga2\tGHSA-vj39-ww8j-vvx5;ubuntu-osv:UBUNTU-CVE-2026-61550;ubuntu:CVE-2026-61550",
   "description": "icinga2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "icinga2",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61550",
    "ghsa-repos": "https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61550",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61550"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63115",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-29"
   },
   "refs": "ghsa-repos:TryGhost/ActivityPub\tGHSA-mm4q-93gr-5mwc",
   "description": "TryGhost/ActivityPub repository advisory GHSA-mm4q-93gr-5mwc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TryGhost/ActivityPub/security/advisories/GHSA-mm4q-93gr-5mwc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55146",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-29"
   },
   "refs": "ghsa-repos:aces/Loris\tGHSA-c9q6-5f24-p7mj",
   "description": "aces/Loris repository advisory GHSA-c9q6-5f24-p7mj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/aces/Loris/security/advisories/GHSA-c9q6-5f24-p7mj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55147",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-29"
   },
   "refs": "ghsa-repos:aces/Loris\tGHSA-m48r-jv24-jjcx",
   "description": "aces/Loris repository advisory GHSA-m48r-jv24-jjcx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/aces/Loris/security/advisories/GHSA-m48r-jv24-jjcx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62347",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-29"
   },
   "refs": "ghsa-repos:element-hq/element-call\tGHSA-wpww-g4f9-vg8x",
   "description": "element-hq/element-call repository advisory GHSA-wpww-g4f9-vg8x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/element-hq/element-call/security/advisories/GHSA-wpww-g4f9-vg8x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59993",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-29"
   },
   "refs": "ghsa-repos:h2o/picotls\tGHSA-2xcv-h2pg-m99c",
   "description": "h2o/picotls repository advisory GHSA-2xcv-h2pg-m99c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/h2o/picotls/security/advisories/GHSA-2xcv-h2pg-m99c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50760",
   "state": "RESERVED",
   "public_date": "2026-06-29",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-29"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2124\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2124.json",
   "description": "CVE-2026-50760",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 78,
   "clock_known": true,
   "hours_public": 1872,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-29",
   "advisory_days_public": 78,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2124.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63201",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:CESNET/netopeer2\tGHSA-25gm-4x89-7r2q",
   "description": "CESNET/netopeer2 repository advisory GHSA-25gm-4x89-7r2q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CESNET/netopeer2/security/advisories/GHSA-25gm-4x89-7r2q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61726",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:TandoorRecipes/recipes\tGHSA-wjf3-fq5w-7j7w",
   "description": "TandoorRecipes/recipes repository advisory GHSA-wjf3-fq5w-7j7w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-wjf3-fq5w-7j7w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63416",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:jgraph/drawio\tGHSA-3pq9-9hg4-ggfw",
   "description": "jgraph/drawio repository advisory GHSA-3pq9-9hg4-ggfw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jgraph/drawio/security/advisories/GHSA-3pq9-9hg4-ggfw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63373",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:jgraph/drawio\tGHSA-mcj5-3pww-7g49",
   "description": "jgraph/drawio repository advisory GHSA-mcj5-3pww-7g49",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jgraph/drawio/security/advisories/GHSA-mcj5-3pww-7g49"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63334",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:jgraph/drawio\tGHSA-3v4h-8r2c-m8c5",
   "description": "jgraph/drawio repository advisory GHSA-3v4h-8r2c-m8c5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jgraph/drawio/security/advisories/GHSA-3v4h-8r2c-m8c5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63393",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:opensearch-project/sql\tGHSA-r8cv-xvqm-4qj4",
   "description": "opensearch-project/sql repository advisory GHSA-r8cv-xvqm-4qj4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opensearch-project/sql/security/advisories/GHSA-r8cv-xvqm-4qj4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63386",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:sunnyadn/js-toml\tGHSA-3g82-77xr-68x5",
   "description": "sunnyadn/js-toml repository advisory GHSA-3g82-77xr-68x5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sunnyadn/js-toml/security/advisories/GHSA-3g82-77xr-68x5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63330",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:warp-tech/warpgate\tGHSA-2q37-6vxr-26jr",
   "description": "warp-tech/warpgate repository advisory GHSA-2q37-6vxr-26jr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/warp-tech/warpgate/security/advisories/GHSA-2q37-6vxr-26jr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63329",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-06-30"
   },
   "refs": "ghsa-repos:warp-tech/warpgate\tGHSA-862h-v6cc-9757",
   "description": "warp-tech/warpgate repository advisory GHSA-862h-v6cc-9757",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/warp-tech/warpgate/security/advisories/GHSA-862h-v6cc-9757"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63430",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-06-30"
   },
   "refs": "osv:crates.io:ammonia",
   "description": "mXSS in ammonia via MathML `annotation-xml` encoding strip",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ammonia",
   "ecosystem": "crates.io",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-63430"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-31323",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-30"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2026-31323\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-31323.json",
   "description": "CVE-2026-31323",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-31323.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-15660",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-30",
    "zdi": "2026-07-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2140\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2140.json;zdi:ZDI-26-423",
   "description": "CVE-2025-15660",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2140.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-423/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-13135",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-06-30",
    "zdi": "2026-07-15"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2140\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2140.json;zdi:ZDI-26-424",
   "description": "CVE-2026-13135",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2140.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-424/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-13136",
   "state": "RESERVED",
   "public_date": "2026-06-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-06-30"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2140\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2140.json",
   "description": "CVE-2026-13136",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 77,
   "clock_known": true,
   "hours_public": 1848,
   "clock_origin": "advisory",
   "advisory_date": "2026-06-30",
   "advisory_days_public": 77,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2140.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46487",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-01",
    "osv": "2026-07-01"
   },
   "refs": "ghsa:GHSA-582q-v28r-7cxr;osv:Maven:org.geonetwork-opensource:geonetwork",
   "description": "GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.geonetwork-opensource",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-582q-v28r-7cxr",
    "osv": "https://osv.dev/list?q=CVE-2026-46487"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39379",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-01",
    "osv": "2026-07-01"
   },
   "refs": "ghsa:GHSA-2v4m-fw6c-g78f;osv:Maven:org.geonetwork-opensource:geonetwork",
   "description": "GeoNetwork has reflected XSS through client-side template injection",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.geonetwork-opensource",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-2v4m-fw6c-g78f",
    "osv": "https://osv.dev/list?q=CVE-2026-39379"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63441",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:Bubka/2FAuth\tGHSA-wc8m-7c5g-xrrc",
   "description": "Bubka/2FAuth repository advisory GHSA-wc8m-7c5g-xrrc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Bubka/2FAuth/security/advisories/GHSA-wc8m-7c5g-xrrc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63440",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:Bubka/2FAuth\tGHSA-22mh-gmrh-gpwg",
   "description": "Bubka/2FAuth repository advisory GHSA-22mh-gmrh-gpwg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Bubka/2FAuth/security/advisories/GHSA-22mh-gmrh-gpwg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63439",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:Bubka/2FAuth\tGHSA-mh8r-74x2-r457",
   "description": "Bubka/2FAuth repository advisory GHSA-mh8r-74x2-r457",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Bubka/2FAuth/security/advisories/GHSA-mh8r-74x2-r457"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63438",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:Bubka/2FAuth\tGHSA-r9xx-45m8-mw24",
   "description": "Bubka/2FAuth repository advisory GHSA-r9xx-45m8-mw24",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Bubka/2FAuth/security/advisories/GHSA-r9xx-45m8-mw24"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63437",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:Bubka/2FAuth\tGHSA-m52c-63g8-qg5c",
   "description": "Bubka/2FAuth repository advisory GHSA-m52c-63g8-qg5c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Bubka/2FAuth/security/advisories/GHSA-m52c-63g8-qg5c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63494",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:WWBN/AVideo\tGHSA-g9x9-q7qj-6mv5",
   "description": "WWBN/AVideo repository advisory GHSA-g9x9-q7qj-6mv5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo/security/advisories/GHSA-g9x9-q7qj-6mv5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63492",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:WWBN/AVideo\tGHSA-j44m-77cc-p3cc",
   "description": "WWBN/AVideo repository advisory GHSA-j44m-77cc-p3cc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WWBN/AVideo/security/advisories/GHSA-j44m-77cc-p3cc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45146",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-prqp-8x29-cr88",
   "description": "chamilo/chamilo-lms repository advisory GHSA-prqp-8x29-cr88",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-prqp-8x29-cr88"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53940",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:conda/conda\tGHSA-9m8m-c4j3-rj2c",
   "description": "conda/conda repository advisory GHSA-9m8m-c4j3-rj2c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/conda/conda/security/advisories/GHSA-9m8m-c4j3-rj2c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63433",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:franklioxygen/MyTube\tGHSA-9qxv-p8j9-gv5r",
   "description": "franklioxygen/MyTube repository advisory GHSA-9qxv-p8j9-gv5r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/franklioxygen/MyTube/security/advisories/GHSA-9qxv-p8j9-gv5r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63434",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:franklioxygen/MyTube\tGHSA-h5xx-g8fc-crr7",
   "description": "franklioxygen/MyTube repository advisory GHSA-h5xx-g8fc-crr7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/franklioxygen/MyTube/security/advisories/GHSA-h5xx-g8fc-crr7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63432",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:horilla/horilla-hr\tGHSA-9p83-4w63-7c24",
   "description": "horilla/horilla-hr repository advisory GHSA-9p83-4w63-7c24",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/horilla/horilla-hr/security/advisories/GHSA-9p83-4w63-7c24"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63431",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:horilla/horilla-hr\tGHSA-c38j-fg3w-7rph",
   "description": "horilla/horilla-hr repository advisory GHSA-c38j-fg3w-7rph",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/horilla/horilla-hr/security/advisories/GHSA-c38j-fg3w-7rph"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63442",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:opnsense/core\tGHSA-2v2x-m4j7-76pv",
   "description": "opnsense/core repository advisory GHSA-2v2x-m4j7-76pv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-2v2x-m4j7-76pv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58394",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-8pgr-x852-qx4j",
   "description": "opnsense/core repository advisory GHSA-8pgr-x852-qx4j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-8pgr-x852-qx4j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58395",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-98h6-479q-9q3w",
   "description": "opnsense/core repository advisory GHSA-98h6-479q-9q3w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-98h6-479q-9q3w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58392",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-h793-67jm-j4m5",
   "description": "opnsense/core repository advisory GHSA-h793-67jm-j4m5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-h793-67jm-j4m5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58391",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-2xrm-p255-p43h",
   "description": "opnsense/core repository advisory GHSA-2xrm-p255-p43h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-2xrm-p255-p43h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57155",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-wjqq-rfmm-v5h3",
   "description": "opnsense/core repository advisory GHSA-wjqq-rfmm-v5h3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-wjqq-rfmm-v5h3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58390",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:opnsense/core\tGHSA-26cj-h9rj-g5pf",
   "description": "opnsense/core repository advisory GHSA-26cj-h9rj-g5pf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-26cj-h9rj-g5pf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58393",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-2m9v-p7r9-gfcw",
   "description": "opnsense/core repository advisory GHSA-2m9v-p7r9-gfcw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-2m9v-p7r9-gfcw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57154",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-01",
    "csaf": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2177\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json;ghsa-repos:opnsense/core\tGHSA-fq94-cxvc-9r7w",
   "description": "opnsense/core repository advisory GHSA-fq94-cxvc-9r7w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2177.json",
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-fq94-cxvc-9r7w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63497",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:titraio/titra\tGHSA-cphv-qx83-x397",
   "description": "titraio/titra repository advisory GHSA-cphv-qx83-x397",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/titraio/titra/security/advisories/GHSA-cphv-qx83-x397"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63502",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:yeti-platform/yeti\tGHSA-4q3w-w2g5-8wqq",
   "description": "yeti-platform/yeti repository advisory GHSA-4q3w-w2g5-8wqq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/yeti-platform/yeti/security/advisories/GHSA-4q3w-w2g5-8wqq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63500",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:yeti-platform/yeti\tGHSA-6xf2-8436-rgvf",
   "description": "yeti-platform/yeti repository advisory GHSA-6xf2-8436-rgvf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/yeti-platform/yeti/security/advisories/GHSA-6xf2-8436-rgvf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63489",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:yeti-platform/yeti\tGHSA-vw33-fwfx-6m9p",
   "description": "yeti-platform/yeti repository advisory GHSA-vw33-fwfx-6m9p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/yeti-platform/yeti/security/advisories/GHSA-vw33-fwfx-6m9p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63482",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-01"
   },
   "refs": "ghsa-repos:yeti-platform/yeti\tGHSA-34r4-95hx-gxqr",
   "description": "yeti-platform/yeti repository advisory GHSA-34r4-95hx-gxqr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/yeti-platform/yeti/security/advisories/GHSA-34r4-95hx-gxqr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-24081",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "csaf,samsung",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-09-08",
    "samsung": "2026-07-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;samsung:SMR-Jul-2026",
   "description": "CVE-2026-24081",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28585",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-07-01"
   },
   "refs": "samsung:SMR-Jul-2026",
   "description": "Samsung SMR Jul 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28632",
   "state": "RESERVED",
   "public_date": "2026-07-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-07-01"
   },
   "refs": "samsung:SMR-Jul-2026",
   "description": "Samsung SMR Jul 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 76,
   "clock_known": true,
   "hours_public": 1824,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-01",
   "advisory_days_public": 76,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12184",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "alas,alpine,csaf,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-07-06",
    "ubuntu-osv": "2026-07-03",
    "ghsa-repos": "2026-07-02",
    "csaf": "2026-07-12"
   },
   "refs": "alas:CVE-2026-12184;alpine:php83;csaf:SUSE Product Security Team\topenSUSE-SU-2026:21308-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21308-1.json;debian:php8.2;ghsa-repos:php/php-src\tGHSA-mhmq-mmqj-2v39;ubuntu-osv:UBUNTU-CVE-202",
   "description": "PHP: Failure to setup TLS with a remote server can result in a remote DoS",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "php83",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-12184.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-12184",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21308-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12184",
    "ghsa-repos": "https://github.com/php/php-src/security/advisories/GHSA-mhmq-mmqj-2v39",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12184"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54617",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-02",
    "osv": "2026-07-02"
   },
   "refs": "ghsa:GHSA-5g75-477j-2c2f;osv:Maven:pro.gravit.launcher:launchserver-api",
   "description": "LaunchServer FileServerHandler has an unauthenticated path traversal issue",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "pro.gravit.launcher",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-5g75-477j-2c2f",
    "osv": "https://osv.dev/list?q=CVE-2026-54617"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63011",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:Intermesh/groupoffice\tGHSA-4m9w-3p93-6cwx",
   "description": "Intermesh/groupoffice repository advisory GHSA-4m9w-3p93-6cwx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Intermesh/groupoffice/security/advisories/GHSA-4m9w-3p93-6cwx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63010",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:Intermesh/groupoffice\tGHSA-jw34-6g49-r6cw",
   "description": "Intermesh/groupoffice repository advisory GHSA-jw34-6g49-r6cw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Intermesh/groupoffice/security/advisories/GHSA-jw34-6g49-r6cw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63653",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:Intermesh/groupoffice\tGHSA-3cp5-q6fp-mqf5",
   "description": "Intermesh/groupoffice repository advisory GHSA-3cp5-q6fp-mqf5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Intermesh/groupoffice/security/advisories/GHSA-3cp5-q6fp-mqf5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64668",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:mcdope/pam_usb\tGHSA-7583-9cqv-j9rf",
   "description": "mcdope/pam_usb repository advisory GHSA-7583-9cqv-j9rf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mcdope/pam_usb/security/advisories/GHSA-7583-9cqv-j9rf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64669",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:mcdope/pam_usb\tGHSA-gc4c-v52c-2v34",
   "description": "mcdope/pam_usb repository advisory GHSA-gc4c-v52c-2v34",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mcdope/pam_usb/security/advisories/GHSA-gc4c-v52c-2v34"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64667",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:mcdope/pam_usb\tGHSA-gc6f-5hpq-ghxh",
   "description": "mcdope/pam_usb repository advisory GHSA-gc6f-5hpq-ghxh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mcdope/pam_usb/security/advisories/GHSA-gc6f-5hpq-ghxh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64666",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:mcdope/pam_usb\tGHSA-ffx6-xjp6-x33g",
   "description": "mcdope/pam_usb repository advisory GHSA-ffx6-xjp6-x33g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mcdope/pam_usb/security/advisories/GHSA-ffx6-xjp6-x33g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64686",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:opensearch-project/OpenSearch-Dashboards\tGHSA-6qp6-3675-ffr3",
   "description": "opensearch-project/OpenSearch-Dashboards repository advisory GHSA-6qp6-3675-ffr3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opensearch-project/OpenSearch-Dashboards/security/advisories/GHSA-6qp6-3675-ffr3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71490",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-02"
   },
   "refs": "ghsa-repos:opnsense/core\tGHSA-p9pr-782r-w2xw",
   "description": "opnsense/core repository advisory GHSA-p9pr-782r-w2xw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opnsense/core/security/advisories/GHSA-p9pr-782r-w2xw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-46642",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2189\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2189.json",
   "description": "CVE-2025-46642",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2189.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56084",
   "state": "RESERVED",
   "public_date": "2026-07-02",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2189\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2189.json",
   "description": "CVE-2026-56084",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 75,
   "clock_known": true,
   "hours_public": 1800,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-02",
   "advisory_days_public": 75,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2189.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61810",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-03"
   },
   "refs": "ghsa-repos:DMTF/libspdm\tGHSA-chjj-xvqx-c8w4",
   "description": "DMTF/libspdm repository advisory GHSA-chjj-xvqx-c8w4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/DMTF/libspdm/security/advisories/GHSA-chjj-xvqx-c8w4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61637",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-03"
   },
   "refs": "ghsa-repos:Icinga/icingaweb2\tGHSA-w7c2-xjv9-q8fv",
   "description": "Icinga/icingaweb2 repository advisory GHSA-w7c2-xjv9-q8fv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Icinga/icingaweb2/security/advisories/GHSA-w7c2-xjv9-q8fv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61619",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-03"
   },
   "refs": "ghsa-repos:coreruleset/coreruleset\tGHSA-f5qm-3h4p-8qhg",
   "description": "coreruleset/coreruleset repository advisory GHSA-f5qm-3h4p-8qhg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/coreruleset/coreruleset/security/advisories/GHSA-f5qm-3h4p-8qhg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62971",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-03"
   },
   "refs": "ghsa-repos:coreruleset/coreruleset\tGHSA-6jp8-c2w2-x7wr",
   "description": "coreruleset/coreruleset repository advisory GHSA-6jp8-c2w2-x7wr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/coreruleset/coreruleset/security/advisories/GHSA-6jp8-c2w2-x7wr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65825",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-03"
   },
   "refs": "ghsa-repos:open-reception/appointment-booking-software\tGHSA-v4q4-xmqf-gmq8",
   "description": "open-reception/appointment-booking-software repository advisory GHSA-v4q4-xmqf-gmq8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-v4q4-xmqf-gmq8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65824",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-03"
   },
   "refs": "ghsa-repos:open-reception/appointment-booking-software\tGHSA-hvcx-8476-rwv6",
   "description": "open-reception/appointment-booking-software repository advisory GHSA-hvcx-8476-rwv6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-hvcx-8476-rwv6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58331",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58331\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58331.json",
   "description": "moodle: arbitrary file read risk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58331.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58332",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58332\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58332.json",
   "description": "moodle: Email-based MFA bypass",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58332.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58333",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58333\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58333.json",
   "description": "moodle: Arbitrary file read risk in backup restore",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58333.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58334",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58334\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58334.json",
   "description": "moodle: RCE risk via admin presets import",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58334.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58335",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58335\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58335.json",
   "description": "moodle: Missing group access checks in grade web services",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58335.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58336",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58336\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58336.json",
   "description": "moodle: IDOR allows arbitrary comment deletion",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58336.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58337",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58337\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58337.json",
   "description": "moodle: CSRF risk in user homepage preference setting",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58337.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58338",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58338\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58338.json",
   "description": "moodle: CSRF risk in user profile page reset",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58338.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58339",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58339\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58339.json",
   "description": "moodle: Reflected XSS via Feedback import error message",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58339.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58340",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58340\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58340.json",
   "description": "moodle: CSRF and XSS in grade item idnumber editing",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58340.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58342",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58342\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58342.json",
   "description": "moodle: CSRF risk when adding quiz section headings",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58342.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58344",
   "state": "RESERVED",
   "public_date": "2026-07-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-03"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58344\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58344.json",
   "description": "moodle: CSRF risk in quiz attempt regrading",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 74,
   "clock_known": true,
   "hours_public": 1776,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-03",
   "advisory_days_public": 74,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58344.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61723",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-27",
    "ghsa-repos": "2026-07-04"
   },
   "refs": "debian:fluidsynth;ghsa-repos:FluidSynth/fluidsynth\tGHSA-r4mc-v3p8-pv47;ubuntu-osv:UBUNTU-CVE-2026-61723",
   "description": "]DLS ptbl chunk integer overflow]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fluidsynth",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61723",
    "ghsa-repos": "https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-r4mc-v3p8-pv47",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61723"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61721",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-27",
    "ghsa-repos": "2026-07-04"
   },
   "refs": "debian:fluidsynth;ghsa-repos:FluidSynth/fluidsynth\tGHSA-59ph-rx8r-8p4j;ubuntu-osv:UBUNTU-CVE-2026-61721",
   "description": "[heap-based buffer overrun for DLS samples]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fluidsynth",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61721",
    "ghsa-repos": "https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-59ph-rx8r-8p4j",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61721"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61714",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-27",
    "ghsa-repos": "2026-07-04"
   },
   "refs": "debian:fluidsynth;ghsa-repos:FluidSynth/fluidsynth\tGHSA-976m-35rw-h3m6;ubuntu-osv:UBUNTU-CVE-2026-61714",
   "description": "[heap-based buffer overflow in MIDI player]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fluidsynth",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61714",
    "ghsa-repos": "https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61714"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61722",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-27",
    "ghsa-repos": "2026-07-04"
   },
   "refs": "debian:fluidsynth;ghsa-repos:FluidSynth/fluidsynth\tGHSA-hp72-35pr-6h6r;ubuntu-osv:UBUNTU-CVE-2026-61722",
   "description": "[DLS articulation chunk integer overflow]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fluidsynth",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61722",
    "ghsa-repos": "https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-hp72-35pr-6h6r",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61722"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58264",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "csaf,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-27",
    "ghsa-repos": "2026-07-04",
    "csaf": "2026-07-08"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11211-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11211-1.json;debian:fluidsynth;ghsa-repos:FluidSynth/fluidsynth\tGHSA-mqmq-w63q-cj94;ubuntu-osv:UBUNTU-CVE-2026-58264",
   "description": "[heap-based buffer overrun in command handler]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fluidsynth",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11211-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58264",
    "ghsa-repos": "https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58264"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61720",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-27",
    "ghsa-repos": "2026-07-04"
   },
   "refs": "debian:fluidsynth;ghsa-repos:FluidSynth/fluidsynth\tGHSA-rmc4-c8hw-455w;ubuntu-osv:UBUNTU-CVE-2026-61720",
   "description": "[SF2 DMOD chunk integer underflow]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fluidsynth",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61720",
    "ghsa-repos": "https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-rmc4-c8hw-455w",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61720"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68548",
   "state": "RESERVED",
   "public_date": "2026-07-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-04"
   },
   "refs": "ghsa-repos:xyproto/algernon\tGHSA-vm84-8c4p-64hx",
   "description": "xyproto/algernon repository advisory GHSA-vm84-8c4p-64hx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 73,
   "clock_known": true,
   "hours_public": 1752,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-04",
   "advisory_days_public": 73,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xyproto/algernon/security/advisories/GHSA-vm84-8c4p-64hx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58498",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-4p4w-m434-jrhj",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-4p4w-m434-jrhj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-4p4w-m434-jrhj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58265",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-j66x-fr38-r7m5",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-j66x-fr38-r7m5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-j66x-fr38-r7m5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64675",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-mmg6-p4pr-cj6h",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-mmg6-p4pr-cj6h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-mmg6-p4pr-cj6h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52790",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-jr7p-rm2x-739x",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-jr7p-rm2x-739x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-jr7p-rm2x-739x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52789",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-4rf9-4vgq-5gcw",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-4rf9-4vgq-5gcw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-4rf9-4vgq-5gcw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52788",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-rf83-3rr5-v4mj",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-rf83-3rr5-v4mj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-rf83-3rr5-v4mj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52786",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-c4q6-7827-mfg6",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-c4q6-7827-mfg6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-c4q6-7827-mfg6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52787",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-4fgg-fghm-jm43",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-4fgg-fghm-jm43",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-4fgg-fghm-jm43"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49990",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-8759-hx7g-94qx",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-8759-hx7g-94qx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-8759-hx7g-94qx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47710",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-2xm5-gjpc-9m6q",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-2xm5-gjpc-9m6q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-2xm5-gjpc-9m6q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47711",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-vrpm-9gm2-x552",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-vrpm-9gm2-x552",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-vrpm-9gm2-x552"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47259",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-9w9m-w7w5-rrv3",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-9w9m-w7w5-rrv3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-9w9m-w7w5-rrv3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47258",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-rjmv-3mcm-r83j",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-rjmv-3mcm-r83j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-rjmv-3mcm-r83j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47257",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-x6pp-3pf3-f87r",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-x6pp-3pf3-f87r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-x6pp-3pf3-f87r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45265",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-v3gx-mwrp-xvh5",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-v3gx-mwrp-xvh5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-v3gx-mwrp-xvh5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45341",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-fv2r-c2m2-7qhh",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-fv2r-c2m2-7qhh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-fv2r-c2m2-7qhh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46674",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-8384-pwhh-cxjh",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-8384-pwhh-cxjh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-8384-pwhh-cxjh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46676",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-2fwp-32cj-g3x4",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-2fwp-32cj-g3x4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-2fwp-32cj-g3x4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46677",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-rv5h-cxwq-q3mh",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-rv5h-cxwq-q3mh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-rv5h-cxwq-q3mh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47217",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-wjw5-q9g6-2764",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-wjw5-q9g6-2764",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-wjw5-q9g6-2764"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49341",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-7r8r-2rj2-5wvr",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-7r8r-2rj2-5wvr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-7r8r-2rj2-5wvr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68908",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:mz-automation/libiec61850\tGHSA-7qg8-hm25-rv5v",
   "description": "mz-automation/libiec61850 repository advisory GHSA-7qg8-hm25-rv5v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7qg8-hm25-rv5v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68907",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:mz-automation/libiec61850\tGHSA-7v2x-39mw-2979",
   "description": "mz-automation/libiec61850 repository advisory GHSA-7v2x-39mw-2979",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7v2x-39mw-2979"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68906",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:mz-automation/libiec61850\tGHSA-f7xm-q62q-22cx",
   "description": "mz-automation/libiec61850 repository advisory GHSA-f7xm-q62q-22cx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/libiec61850/security/advisories/GHSA-f7xm-q62q-22cx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57446",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-05"
   },
   "refs": "ghsa-repos:mz-automation/libiec61850\tGHSA-cxgr-7v9h-fj9p",
   "description": "mz-automation/libiec61850 repository advisory GHSA-cxgr-7v9h-fj9p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/libiec61850/security/advisories/GHSA-cxgr-7v9h-fj9p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-66366",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2210\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2210.json",
   "description": "CVE-2025-66366",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2210.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-66367",
   "state": "RESERVED",
   "public_date": "2026-07-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2210\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2210.json",
   "description": "CVE-2025-66367",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 72,
   "clock_known": true,
   "hours_public": 1728,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-05",
   "advisory_days_public": 72,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2210.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69186",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-08-11",
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa-repos": "2026-07-06",
    "csaf": "2026-08-25"
   },
   "refs": "alas:CVE-2026-69186;csaf:SUSE Product Security Team\tCVE-2026-69186\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-69186.json;debian:c-ares;ghsa-repos:c-ares/c-ares\tGHSA-jv8r-gqr9-68wj;ubuntu-osv:UBUNTU-CVE-2026-69186;ubuntu:CVE-2026-691",
   "description": "Memory-amplification denial of service via unvalidated DNS header record counts",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "c-ares",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-69186.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-69186.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-69186",
    "ghsa-repos": "https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-69186",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-69186"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69184",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-08-11",
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa-repos": "2026-07-06",
    "csaf": "2026-08-25"
   },
   "refs": "alas:CVE-2026-69184;csaf:SUSE Product Security Team\tCVE-2026-69184\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-69184.json;debian:c-ares;ghsa-repos:c-ares/c-ares\tGHSA-pjmc-gx33-gc76;ubuntu-osv:UBUNTU-CVE-2026-69184;ubuntu:CVE-2026-691",
   "description": "CPU-exhaustion denial of service via unbounded DNS name compression pointer chains",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "c-ares",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-69184.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-69184.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-69184",
    "ghsa-repos": "https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-69184",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-69184"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54161",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "csaf,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-06",
    "csaf": "2026-07-24"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11367-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11367-1.json;debian:nut;ubuntu-osv:UBUNTU-CVE-2026-54161",
   "description": "upsmon: remote OS command injection (RCE) via attacker-controlled ups.alarm in NOTIFYCMD execution",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nut",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11367-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-54161",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-54161"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54640",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-06",
    "osv": "2026-07-06"
   },
   "refs": "ghsa:GHSA-7v6w-c3f4-9wpq;osv:Maven:io.openremote:openremote-agent",
   "description": "OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.openremote",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-7v6w-c3f4-9wpq",
    "osv": "https://osv.dev/list?q=CVE-2026-54640"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54641",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-06",
    "osv": "2026-07-06"
   },
   "refs": "ghsa:GHSA-xqr9-4wvv-gvch;osv:Maven:io.openremote:openremote-manager",
   "description": "OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.openremote",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-xqr9-4wvv-gvch",
    "osv": "https://osv.dev/list?q=CVE-2026-54641"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55786",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-06",
    "osv": "2026-07-06"
   },
   "refs": "ghsa:GHSA-h9f9-h6gm-wc85;osv:PyPI:flyto-core",
   "description": "flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "flyto-core",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-h9f9-h6gm-wc85",
    "osv": "https://osv.dev/list?q=CVE-2026-55786"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55787",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-06",
    "osv": "2026-07-06"
   },
   "refs": "ghsa:GHSA-794r-5rp2-fpg8;osv:PyPI:flyto-core",
   "description": "flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "flyto-core",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-794r-5rp2-fpg8",
    "osv": "https://osv.dev/list?q=CVE-2026-55787"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56660",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-q5rx-gppg-768r",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-q5rx-gppg-768r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-q5rx-gppg-768r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56661",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-r7v8-mx29-5q8h",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-r7v8-mx29-5q8h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-r7v8-mx29-5q8h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56662",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-2rxv-4g4m-573w",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-2rxv-4g4m-573w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-2rxv-4g4m-573w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69187",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-27h8-4v64-8v85",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-27h8-4v64-8v85",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-27h8-4v64-8v85"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69188",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-vxf4-mrgm-vp43",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-vxf4-mrgm-vp43",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-vxf4-mrgm-vp43"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61675",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-c6vj-372g-m3cw",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-c6vj-372g-m3cw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-c6vj-372g-m3cw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61676",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-f732-866c-g3hc",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-f732-866c-g3hc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f732-866c-g3hc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61680",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-fjwm-mmjp-c6vm",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-fjwm-mmjp-c6vm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-fjwm-mmjp-c6vm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61677",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:LabRedesCefetRJ/WeGIA\tGHSA-pvhq-2cf3-xmch",
   "description": "LabRedesCefetRJ/WeGIA repository advisory GHSA-pvhq-2cf3-xmch",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-pvhq-2cf3-xmch"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61851",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-cp8j-2xwc-hxg8",
   "description": "chartbrew/chartbrew repository advisory GHSA-cp8j-2xwc-hxg8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-cp8j-2xwc-hxg8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61743",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-9537-vm84-j26f",
   "description": "chartbrew/chartbrew repository advisory GHSA-9537-vm84-j26f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-9537-vm84-j26f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65980",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-5jgv-45cw-hc53",
   "description": "chartbrew/chartbrew repository advisory GHSA-5jgv-45cw-hc53",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-5jgv-45cw-hc53"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61852",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-4923-m569-jc42",
   "description": "chartbrew/chartbrew repository advisory GHSA-4923-m569-jc42",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-4923-m569-jc42"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54589",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-6m7q-jmp7-3vw8",
   "description": "chartbrew/chartbrew repository advisory GHSA-6m7q-jmp7-3vw8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-6m7q-jmp7-3vw8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54349",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-4wj7-9gq7-mrr2",
   "description": "chartbrew/chartbrew repository advisory GHSA-4wj7-9gq7-mrr2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-4wj7-9gq7-mrr2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62267",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:matrix-org/matrix-hookshot\tGHSA-j286-3cjc-8f39",
   "description": "matrix-org/matrix-hookshot repository advisory GHSA-j286-3cjc-8f39",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/matrix-org/matrix-hookshot/security/advisories/GHSA-j286-3cjc-8f39"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65963",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:pi-hole/FTL\tGHSA-8j7w-m3cr-6q6x",
   "description": "pi-hole/FTL repository advisory GHSA-8j7w-m3cr-6q6x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pi-hole/FTL/security/advisories/GHSA-8j7w-m3cr-6q6x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65964",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:pi-hole/FTL\tGHSA-g7v8-8q8f-hprp",
   "description": "pi-hole/FTL repository advisory GHSA-g7v8-8q8f-hprp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pi-hole/FTL/security/advisories/GHSA-g7v8-8q8f-hprp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71304",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:pi-hole/FTL\tGHSA-w8cr-2cwg-92cg",
   "description": "pi-hole/FTL repository advisory GHSA-w8cr-2cwg-92cg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pi-hole/FTL/security/advisories/GHSA-w8cr-2cwg-92cg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65966",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:pi-hole/FTL\tGHSA-r5vh-5q82-jg7q",
   "description": "pi-hole/FTL repository advisory GHSA-r5vh-5q82-jg7q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pi-hole/FTL/security/advisories/GHSA-r5vh-5q82-jg7q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-62165",
   "state": "RESERVED",
   "public_date": "2026-07-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-06"
   },
   "refs": "ghsa-repos:pi-hole/FTL\tGHSA-q6fm-xwxf-37r5",
   "description": "pi-hole/FTL repository advisory GHSA-q6fm-xwxf-37r5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 71,
   "clock_known": true,
   "hours_public": 1704,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-06",
   "advisory_days_public": 71,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pi-hole/FTL/security/advisories/GHSA-q6fm-xwxf-37r5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45016",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-07",
    "osv": "2026-07-07"
   },
   "refs": "ghsa:GHSA-c8m7-r2jv-rw63;osv:Packagist:egroupware/egroupware",
   "description": "EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "egroupware/egroupware",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-c8m7-r2jv-rw63",
    "osv": "https://osv.dev/list?q=CVE-2026-45016"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71538",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:CycloneDX/cyclonedx-node-npm\tGHSA-q69g-4hcv-6jg4",
   "description": "CycloneDX/cyclonedx-node-npm repository advisory GHSA-q69g-4hcv-6jg4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CycloneDX/cyclonedx-node-npm/security/advisories/GHSA-q69g-4hcv-6jg4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61581",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:DataDog/datadog-agent\tGHSA-h8qx-4jh5-pf43",
   "description": "DataDog/datadog-agent repository advisory GHSA-h8qx-4jh5-pf43",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/DataDog/datadog-agent/security/advisories/GHSA-h8qx-4jh5-pf43"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55169",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:OSC/ondemand\tGHSA-pj66-qf5q-g7g5",
   "description": "OSC/ondemand repository advisory GHSA-pj66-qf5q-g7g5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OSC/ondemand/security/advisories/GHSA-pj66-qf5q-g7g5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55172",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:OSC/ondemand\tGHSA-wqv4-4vj3-rgh5",
   "description": "OSC/ondemand repository advisory GHSA-wqv4-4vj3-rgh5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OSC/ondemand/security/advisories/GHSA-wqv4-4vj3-rgh5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55171",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:OSC/ondemand\tGHSA-3wm4-r2jj-43pp",
   "description": "OSC/ondemand repository advisory GHSA-3wm4-r2jj-43pp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OSC/ondemand/security/advisories/GHSA-3wm4-r2jj-43pp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61528",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-7fhg-337c-qvf7",
   "description": "chamilo/chamilo-lms repository advisory GHSA-7fhg-337c-qvf7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-7fhg-337c-qvf7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61532",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-97gp-5f3j-vwqr",
   "description": "chamilo/chamilo-lms repository advisory GHSA-97gp-5f3j-vwqr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-97gp-5f3j-vwqr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55503",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-xfhv-qg8r-rc7w",
   "description": "chamilo/chamilo-lms repository advisory GHSA-xfhv-qg8r-rc7w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-xfhv-qg8r-rc7w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61583",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-853c-q5q4-jm2c",
   "description": "chamilo/chamilo-lms repository advisory GHSA-853c-q5q4-jm2c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-853c-q5q4-jm2c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61582",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-qqwp-55vx-w4gp",
   "description": "chamilo/chamilo-lms repository advisory GHSA-qqwp-55vx-w4gp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-qqwp-55vx-w4gp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61578",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-39qq-f7xc-9w6q",
   "description": "chamilo/chamilo-lms repository advisory GHSA-39qq-f7xc-9w6q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-39qq-f7xc-9w6q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45142",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-wjxh-pvwh-h84p",
   "description": "chamilo/chamilo-lms repository advisory GHSA-wjxh-pvwh-h84p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-wjxh-pvwh-h84p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71483",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:horilla/horilla-hr\tGHSA-rw86-x8hq-xgwh",
   "description": "horilla/horilla-hr repository advisory GHSA-rw86-x8hq-xgwh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69197",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-07"
   },
   "refs": "ghsa-repos:umbraco/Umbraco-CMS\tGHSA-wr57-hqmp-fgvh",
   "description": "umbraco/Umbraco-CMS repository advisory GHSA-wr57-hqmp-fgvh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wr57-hqmp-fgvh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-13465",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-07"
   },
   "refs": "csaf:SUSE Product Security Team\tESEA-2026:0136\thttps://ftp.suse.com/pub/projects/security/csaf/esea-2026_0136.json",
   "description": "CVE-2026-13465",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/esea-2026_0136.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-8408",
   "state": "RESERVED",
   "public_date": "2026-07-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-07"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2232\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2232.json",
   "description": "CVE-2026-8408",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 70,
   "clock_known": true,
   "hours_public": 1680,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-07",
   "advisory_days_public": 70,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2232.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50588",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50588",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50588",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50588",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50588"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49300",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-49300",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-49300",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49300",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49300"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50580",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50580",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50580",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50580",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50580"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50585",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50585",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50585",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50585",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50585"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50586",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50586",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50586",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50586",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50586"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50581",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50581",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50581",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50581",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50581"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54441",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-54441",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-54441",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-54441",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-54441"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50579",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50579",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50579",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50579",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50579"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50640",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-08"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11215-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50640",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50640",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11215-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50640",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50640"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77239",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:ArnasDon/wacrm\tGHSA-34q7-fv77-625j",
   "description": "ArnasDon/wacrm repository advisory GHSA-34q7-fv77-625j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ArnasDon/wacrm/security/advisories/GHSA-34q7-fv77-625j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77240",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:ArnasDon/wacrm\tGHSA-fg5p-2qc3-jmxr",
   "description": "ArnasDon/wacrm repository advisory GHSA-fg5p-2qc3-jmxr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ArnasDon/wacrm/security/advisories/GHSA-fg5p-2qc3-jmxr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75506",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:OliveTin/OliveTin\tGHSA-vc6p-m6vx-6cwq",
   "description": "OliveTin/OliveTin repository advisory GHSA-vc6p-m6vx-6cwq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-vc6p-m6vx-6cwq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61584",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-6qwh-9m43-gx3q",
   "description": "chamilo/chamilo-lms repository advisory GHSA-6qwh-9m43-gx3q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-6qwh-9m43-gx3q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55504",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-ppw9-gf4r-5c39",
   "description": "chamilo/chamilo-lms repository advisory GHSA-ppw9-gf4r-5c39",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-ppw9-gf4r-5c39"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54747",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-jv7g-9ff9-6cc5",
   "description": "chamilo/chamilo-lms repository advisory GHSA-jv7g-9ff9-6cc5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-jv7g-9ff9-6cc5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69131",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:django-cms/django-filer\tGHSA-vf85-8ff2-3r9w",
   "description": "django-cms/django-filer repository advisory GHSA-vf85-8ff2-3r9w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/django-cms/django-filer/security/advisories/GHSA-vf85-8ff2-3r9w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69138",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:django-cms/djangocms-versioning\tGHSA-5g9x-qwh5-33x4",
   "description": "django-cms/djangocms-versioning repository advisory GHSA-5g9x-qwh5-33x4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/django-cms/djangocms-versioning/security/advisories/GHSA-5g9x-qwh5-33x4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71863",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:freedomofpress/securedrop\tGHSA-rqwh-4873-322p",
   "description": "freedomofpress/securedrop repository advisory GHSA-rqwh-4873-322p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freedomofpress/securedrop/security/advisories/GHSA-rqwh-4873-322p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73971",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:music-assistant/server\tGHSA-cjp7-8r57-vc8f",
   "description": "music-assistant/server repository advisory GHSA-cjp7-8r57-vc8f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/music-assistant/server/security/advisories/GHSA-cjp7-8r57-vc8f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61657",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:ndsev/zserio\tGHSA-m257-f4fp-gr9f",
   "description": "ndsev/zserio repository advisory GHSA-m257-f4fp-gr9f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ndsev/zserio/security/advisories/GHSA-m257-f4fp-gr9f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75510",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:novuhq/novu\tGHSA-8gr3-5j6f-25gp",
   "description": "novuhq/novu repository advisory GHSA-8gr3-5j6f-25gp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/novuhq/novu/security/advisories/GHSA-8gr3-5j6f-25gp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75517",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:novuhq/novu\tGHSA-jh6r-hjhp-wh2h",
   "description": "novuhq/novu repository advisory GHSA-jh6r-hjhp-wh2h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/novuhq/novu/security/advisories/GHSA-jh6r-hjhp-wh2h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75511",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:novuhq/novu\tGHSA-pg9q-8v57-hqph",
   "description": "novuhq/novu repository advisory GHSA-pg9q-8v57-hqph",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/novuhq/novu/security/advisories/GHSA-pg9q-8v57-hqph"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75524",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:open-reception/appointment-booking-software\tGHSA-q452-m9pf-qj9j",
   "description": "open-reception/appointment-booking-software repository advisory GHSA-q452-m9pf-qj9j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-q452-m9pf-qj9j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75525",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:open-reception/appointment-booking-software\tGHSA-qc72-9fg9-h66h",
   "description": "open-reception/appointment-booking-software repository advisory GHSA-qc72-9fg9-h66h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-qc72-9fg9-h66h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75597",
   "state": "RESERVED",
   "public_date": "2026-07-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-08"
   },
   "refs": "ghsa-repos:pyload/pyload\tGHSA-j92p-c242-7hfx",
   "description": "pyload/pyload repository advisory GHSA-j92p-c242-7hfx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 69,
   "clock_known": true,
   "hours_public": 1656,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-08",
   "advisory_days_public": 69,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pyload/pyload/security/advisories/GHSA-j92p-c242-7hfx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49863",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-49863",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49863",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49863"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45093",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-09",
    "ghsa-repos": "2026-09-08"
   },
   "refs": "debian:fastdds;ghsa-repos:eProsima/Fast-DDS\tGHSA-3733-fqj8-39fx;ubuntu-osv:UBUNTU-CVE-2026-45093",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45093",
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3733-fqj8-39fx",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45093"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45096",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-09",
    "ghsa-repos": "2026-09-08"
   },
   "refs": "debian:fastdds;ghsa-repos:eProsima/Fast-DDS\tGHSA-j2w9-582m-j57r;ubuntu-osv:UBUNTU-CVE-2026-45096",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45096",
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-j2w9-582m-j57r",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45096"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45098",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-45098",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45098",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45098"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45094",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-09",
    "ghsa-repos": "2026-09-08"
   },
   "refs": "debian:fastdds;ghsa-repos:eProsima/Fast-DDS\tGHSA-rg6h-2jch-hwjx;ubuntu-osv:UBUNTU-CVE-2026-45094",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45094",
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-rg6h-2jch-hwjx",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45094"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53589",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-53589",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53589",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53589"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45095",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-09",
    "ghsa-repos": "2026-09-08"
   },
   "refs": "debian:fastdds;ghsa-repos:eProsima/Fast-DDS\tGHSA-r4gh-qh7w-jxqf;ubuntu-osv:UBUNTU-CVE-2026-45095",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45095",
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-r4gh-qh7w-jxqf",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45095"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53588",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-53588",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53588",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53588"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45092",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-09",
    "ghsa-repos": "2026-09-08"
   },
   "refs": "debian:fastdds;ghsa-repos:eProsima/Fast-DDS\tGHSA-mvxp-mfh8-hhv5;ubuntu-osv:UBUNTU-CVE-2026-45092",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45092",
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-mvxp-mfh8-hhv5",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45092"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55063",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-55063",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-55063",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-55063"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53590",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-53590",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-53590",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-53590"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49861",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-49861",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49861",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49861"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45097",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ghsa-repos,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-09",
    "ghsa-repos": "2026-07-22"
   },
   "refs": "debian:fastdds;ghsa-repos:eProsima/Fast-DDS\tGHSA-93m4-rx65-p7rj;ubuntu-osv:UBUNTU-CVE-2026-45097",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-45097",
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-93m4-rx65-p7rj",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-45097"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49862",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-09"
   },
   "refs": "debian:fastdds;ubuntu-osv:UBUNTU-CVE-2026-49862",
   "description": "fastdds",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "fastdds",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49862",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49862"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55252",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-09",
    "osv": "2026-07-09"
   },
   "refs": "ghsa:GHSA-h5g6-xmh4-hc37;osv:Go:github.com/openrundev/openrun",
   "description": "OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/openrundev/openrun",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-h5g6-xmh4-hc37",
    "osv": "https://osv.dev/list?q=CVE-2026-55252"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75600",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:FreePBX/security-reporting\tGHSA-79rg-3xp6-rqq6",
   "description": "FreePBX/security-reporting repository advisory GHSA-79rg-3xp6-rqq6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FreePBX/security-reporting/security/advisories/GHSA-79rg-3xp6-rqq6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76099",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:docker/mcp-gateway\tGHSA-mqq5-qh4g-2g8g",
   "description": "docker/mcp-gateway repository advisory GHSA-mqq5-qh4g-2g8g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docker/mcp-gateway/security/advisories/GHSA-mqq5-qh4g-2g8g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76097",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:docker/mcp-gateway\tGHSA-m5m2-mrxf-7j7q",
   "description": "docker/mcp-gateway repository advisory GHSA-m5m2-mrxf-7j7q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docker/mcp-gateway/security/advisories/GHSA-m5m2-mrxf-7j7q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76095",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:docker/mcp-gateway\tGHSA-6pq5-p7fc-7xhq",
   "description": "docker/mcp-gateway repository advisory GHSA-6pq5-p7fc-7xhq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docker/mcp-gateway/security/advisories/GHSA-6pq5-p7fc-7xhq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76094",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:docker/mcp-gateway\tGHSA-6m8f-w97w-99h7",
   "description": "docker/mcp-gateway repository advisory GHSA-6m8f-w97w-99h7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docker/mcp-gateway/security/advisories/GHSA-6m8f-w97w-99h7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76093",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:docker/mcp-gateway\tGHSA-625j-rw87-4ghr",
   "description": "docker/mcp-gateway repository advisory GHSA-625j-rw87-4ghr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docker/mcp-gateway/security/advisories/GHSA-625j-rw87-4ghr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76092",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:docker/mcp-gateway\tGHSA-g879-4j4f-6vj7",
   "description": "docker/mcp-gateway repository advisory GHSA-g879-4j4f-6vj7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docker/mcp-gateway/security/advisories/GHSA-g879-4j4f-6vj7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48728",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:glpi-project/glpi-inventory-plugin\tGHSA-xj72-9f7x-f4hm",
   "description": "glpi-project/glpi-inventory-plugin repository advisory GHSA-xj72-9f7x-f4hm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-inventory-plugin/security/advisories/GHSA-xj72-9f7x-f4hm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76812",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-vmrr-v4xp-42cx",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-vmrr-v4xp-42cx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-vmrr-v4xp-42cx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76896",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-3369-fmrv-vh4j",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-3369-fmrv-vh4j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-3369-fmrv-vh4j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76894",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-vqff-r82h-9crc",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-vqff-r82h-9crc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-vqff-r82h-9crc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76811",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-38f8-m897-jm7w",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-38f8-m897-jm7w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-38f8-m897-jm7w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76895",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-c499-9f77-93m8",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-c499-9f77-93m8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-c499-9f77-93m8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76897",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-v3j5-c4v8-4pjr",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-v3j5-c4v8-4pjr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-v3j5-c4v8-4pjr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76813",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:ondata/ckan-mcp-server\tGHSA-q5gv-wppg-53fv",
   "description": "ondata/ckan-mcp-server repository advisory GHSA-q5gv-wppg-53fv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-q5gv-wppg-53fv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66072",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-48hm-chgv-398r",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-48hm-chgv-398r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-48hm-chgv-398r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67237",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-2rf7-f6r6-8rwh",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-2rf7-f6r6-8rwh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-2rf7-f6r6-8rwh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67234",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-q286-p3m9-j69f",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-q286-p3m9-j69f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q286-p3m9-j69f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67236",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-88vh-gx85-p36m",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-88vh-gx85-p36m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-88vh-gx85-p36m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66073",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-6v53-r759-jrvx",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-6v53-r759-jrvx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6v53-r759-jrvx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66074",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-rg5q-vcgf-rfh7",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-rg5q-vcgf-rfh7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-rg5q-vcgf-rfh7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67235",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-q8g2-pc7m-m3jw",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-q8g2-pc7m-m3jw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q8g2-pc7m-m3jw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67233",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-7jc3-73v6-rjvc",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-7jc3-73v6-rjvc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-7jc3-73v6-rjvc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66075",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-g5v3-w5xg-62q2",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-g5v3-w5xg-62q2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-g5v3-w5xg-62q2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66078",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-j9m2-hw6x-rqr9",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-j9m2-hw6x-rqr9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j9m2-hw6x-rqr9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66077",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-rjcf-35r5-xw38",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-rjcf-35r5-xw38",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-rjcf-35r5-xw38"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66079",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-c66h-hf5j-8jf9",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-c66h-hf5j-8jf9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-c66h-hf5j-8jf9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67231",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-cw8c-4m83-9c6w",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-cw8c-4m83-9c6w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-cw8c-4m83-9c6w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67232",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-gmgx-hhg5-43gr",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-gmgx-hhg5-43gr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gmgx-hhg5-43gr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67230",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-7v63-j4gm-p4rh",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-7v63-j4gm-p4rh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-7v63-j4gm-p4rh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67218",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-34jw-rm7g-hph4",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-34jw-rm7g-hph4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-34jw-rm7g-hph4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66080",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-wg79-5449-m728",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-wg79-5449-m728",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wg79-5449-m728"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67219",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-m8pg-4x2h-jvgr",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-m8pg-4x2h-jvgr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-m8pg-4x2h-jvgr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67220",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-r3qr-4h63-mvj2",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-r3qr-4h63-mvj2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-r3qr-4h63-mvj2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67222",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-85jr-6rr2-j73r",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-85jr-6rr2-j73r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-85jr-6rr2-j73r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67221",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-x5h5-588r-cv55",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-x5h5-588r-cv55",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-x5h5-588r-cv55"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67404",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-37wx-r6q9-6fhj",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-37wx-r6q9-6fhj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-37wx-r6q9-6fhj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67224",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-h7cq-qrr8-7vgc",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-h7cq-qrr8-7vgc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h7cq-qrr8-7vgc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67225",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-c8c4-gvv4-8j3q",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-c8c4-gvv4-8j3q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-c8c4-gvv4-8j3q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67405",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-9c4f-rxxm-88q3",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-9c4f-rxxm-88q3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-9c4f-rxxm-88q3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67228",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-73qp-fwh4-2q5g",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-73qp-fwh4-2q5g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-73qp-fwh4-2q5g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66071",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-89p2-f5cv-x5cg",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-89p2-f5cv-x5cg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-89p2-f5cv-x5cg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67229",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-ggrw-qm45-hwpv",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-ggrw-qm45-hwpv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-ggrw-qm45-hwpv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66070",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-p3hp-v9wh-ghm7",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-p3hp-v9wh-ghm7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-p3hp-v9wh-ghm7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66068",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-9wm4-9m6g-w38x",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-9wm4-9m6g-w38x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-9wm4-9m6g-w38x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66069",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-fhwq-9rvh-prj2",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-fhwq-9rvh-prj2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-fhwq-9rvh-prj2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67238",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-x96j-244m-mrr2",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-x96j-244m-mrr2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-x96j-244m-mrr2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67240",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-59c5-553c-57m2",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-59c5-553c-57m2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-59c5-553c-57m2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66067",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-hwqx-2gfg-89qf",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-hwqx-2gfg-89qf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-hwqx-2gfg-89qf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66076",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-j45q-v7g2-82ph",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-j45q-v7g2-82ph",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j45q-v7g2-82ph"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62260",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-rjqv-xg3q-g423",
   "description": "samtools/htslib repository advisory GHSA-rjqv-xg3q-g423",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-rjqv-xg3q-g423"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62259",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-hg3g-v57p-459q",
   "description": "samtools/htslib repository advisory GHSA-hg3g-v57p-459q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-hg3g-v57p-459q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62258",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-2jx2-wm7f-rv9m",
   "description": "samtools/htslib repository advisory GHSA-2jx2-wm7f-rv9m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-2jx2-wm7f-rv9m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62257",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-6q7c-m967-9v37",
   "description": "samtools/htslib repository advisory GHSA-6q7c-m967-9v37",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-6q7c-m967-9v37"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62256",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-4hjq-r829-8c8v",
   "description": "samtools/htslib repository advisory GHSA-4hjq-r829-8c8v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-4hjq-r829-8c8v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62255",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-28r7-prwc-hf5c",
   "description": "samtools/htslib repository advisory GHSA-28r7-prwc-hf5c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-28r7-prwc-hf5c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63390",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:samtools/htslib\tGHSA-2wm6-8hgm-7g92",
   "description": "samtools/htslib repository advisory GHSA-2wm6-8hgm-7g92",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/samtools/htslib/security/advisories/GHSA-2wm6-8hgm-7g92"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76806",
   "state": "RESERVED",
   "public_date": "2026-07-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-09"
   },
   "refs": "ghsa-repos:solidtime-io/solidtime\tGHSA-cj49-589g-wp6j",
   "description": "solidtime-io/solidtime repository advisory GHSA-cj49-589g-wp6j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 68,
   "clock_known": true,
   "hours_public": 1632,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-09",
   "advisory_days_public": 68,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/solidtime-io/solidtime/security/advisories/GHSA-cj49-589g-wp6j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52054",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-13",
    "ghsa-repos": "2026-07-10"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-w626-q3p2-8762;ubuntu:CVE-2026-52054",
   "description": "[find_opt zero-length PPP option -- infinite loop]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52054",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-w626-q3p2-8762",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52054"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59956",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-hjfv-gvxc-qgvh",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-hjfv-gvxc-qgvh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-hjfv-gvxc-qgvh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59181",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-xh8r-vmqq-56pp",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-xh8r-vmqq-56pp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xh8r-vmqq-56pp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59156",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-xvwr-x6ch-v2fq",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-xvwr-x6ch-v2fq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xvwr-x6ch-v2fq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77292",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:JanssenProject/jans\tGHSA-8gmm-83qv-w67g",
   "description": "JanssenProject/jans repository advisory GHSA-8gmm-83qv-w67g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/JanssenProject/jans/security/advisories/GHSA-8gmm-83qv-w67g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77291",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:JanssenProject/jans\tGHSA-vxgw-mxhf-2m6f",
   "description": "JanssenProject/jans repository advisory GHSA-vxgw-mxhf-2m6f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/JanssenProject/jans/security/advisories/GHSA-vxgw-mxhf-2m6f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77290",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:JanssenProject/jans\tGHSA-9qw4-gwgf-3q27",
   "description": "JanssenProject/jans repository advisory GHSA-9qw4-gwgf-3q27",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/JanssenProject/jans/security/advisories/GHSA-9qw4-gwgf-3q27"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77328",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-m3xh-ccmh-x8rw",
   "description": "MapServer/MapServer repository advisory GHSA-m3xh-ccmh-x8rw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-m3xh-ccmh-x8rw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77327",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-7624-4mwh-9cxr",
   "description": "MapServer/MapServer repository advisory GHSA-7624-4mwh-9cxr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-7624-4mwh-9cxr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77326",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-4mwc-qc95-5959",
   "description": "MapServer/MapServer repository advisory GHSA-4mwc-qc95-5959",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-4mwc-qc95-5959"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77325",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-52rr-p4x5-2x6x",
   "description": "MapServer/MapServer repository advisory GHSA-52rr-p4x5-2x6x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-52rr-p4x5-2x6x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77323",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-288j-mhpj-gmmr",
   "description": "MapServer/MapServer repository advisory GHSA-288j-mhpj-gmmr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-288j-mhpj-gmmr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77324",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:MapServer/MapServer\tGHSA-35qh-49hm-5rcx",
   "description": "MapServer/MapServer repository advisory GHSA-35qh-49hm-5rcx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MapServer/MapServer/security/advisories/GHSA-35qh-49hm-5rcx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61702",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-10",
    "csaf": "2026-07-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2282\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2282.json;ghsa-repos:OpenPrinting/cups\tGHSA-gq9p-4w7m-2f5g",
   "description": "OpenPrinting/cups repository advisory GHSA-gq9p-4w7m-2f5g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2282.json",
    "ghsa-repos": "https://github.com/OpenPrinting/cups/security/advisories/GHSA-gq9p-4w7m-2f5g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77281",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:caddyserver/caddy\tGHSA-j8px-rmrx-76h9",
   "description": "caddyserver/caddy repository advisory GHSA-j8px-rmrx-76h9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68522",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:codidact/qpixel\tGHSA-9mhx-jr3h-2cvf",
   "description": "codidact/qpixel repository advisory GHSA-9mhx-jr3h-2cvf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/codidact/qpixel/security/advisories/GHSA-9mhx-jr3h-2cvf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77300",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:itflow-org/itflow\tGHSA-5g5j-37c8-hm7m",
   "description": "itflow-org/itflow repository advisory GHSA-5g5j-37c8-hm7m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/itflow-org/itflow/security/advisories/GHSA-5g5j-37c8-hm7m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75516",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-java-client\tGHSA-jh4v-gfqj-7rhx",
   "description": "rabbitmq/rabbitmq-java-client repository advisory GHSA-jh4v-gfqj-7rhx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-jh4v-gfqj-7rhx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59961",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:troglobit/mini-snmpd\tGHSA-c9g2-5ghh-8g8c",
   "description": "troglobit/mini-snmpd repository advisory GHSA-c9g2-5ghh-8g8c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/troglobit/mini-snmpd/security/advisories/GHSA-c9g2-5ghh-8g8c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59964",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-10"
   },
   "refs": "ghsa-repos:troglobit/uftpd\tGHSA-vqhc-mmjf-972h",
   "description": "troglobit/uftpd repository advisory GHSA-vqhc-mmjf-972h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/troglobit/uftpd/security/advisories/GHSA-vqhc-mmjf-972h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-15181",
   "state": "RESERVED",
   "public_date": "2026-07-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-10"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11247-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11247-1.json",
   "description": "CVE-2026-15181",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 67,
   "clock_known": true,
   "hours_public": 1608,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-10",
   "advisory_days_public": 67,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11247-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59968",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-11"
   },
   "refs": "ghsa-repos:Kovah/LinkAce\tGHSA-568c-jrfp-ffjg",
   "description": "Kovah/LinkAce repository advisory GHSA-568c-jrfp-ffjg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Kovah/LinkAce/security/advisories/GHSA-568c-jrfp-ffjg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77336",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-11"
   },
   "refs": "ghsa-repos:Zeecka/AperiSolve\tGHSA-f7j8-f987-jw98",
   "description": "Zeecka/AperiSolve repository advisory GHSA-f7j8-f987-jw98",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Zeecka/AperiSolve/security/advisories/GHSA-f7j8-f987-jw98"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58406",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-11",
    "csaf": "2026-07-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2281\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2281.json;ghsa-repos:avahi/avahi\tGHSA-8pmv-23p5-92mw",
   "description": "avahi/avahi repository advisory GHSA-8pmv-23p5-92mw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2281.json",
    "ghsa-repos": "https://github.com/avahi/avahi/security/advisories/GHSA-8pmv-23p5-92mw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59987",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-07-11",
    "csaf": "2026-07-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2281\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2281.json;ghsa-repos:avahi/avahi\tGHSA-4v6h-9g73-wm5j",
   "description": "avahi/avahi repository advisory GHSA-4v6h-9g73-wm5j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2281.json",
    "ghsa-repos": "https://github.com/avahi/avahi/security/advisories/GHSA-4v6h-9g73-wm5j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77294",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-11"
   },
   "refs": "ghsa-repos:liketrek/TREK\tGHSA-fmq9-ggh3-647p",
   "description": "liketrek/TREK repository advisory GHSA-fmq9-ggh3-647p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/liketrek/TREK/security/advisories/GHSA-fmq9-ggh3-647p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77293",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-11"
   },
   "refs": "ghsa-repos:liketrek/TREK\tGHSA-cjc5-722j-vvmf",
   "description": "liketrek/TREK repository advisory GHSA-cjc5-722j-vvmf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/liketrek/TREK/security/advisories/GHSA-cjc5-722j-vvmf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77320",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-11"
   },
   "refs": "ghsa-repos:liketrek/TREK\tGHSA-9hc8-p7gm-p7mx",
   "description": "liketrek/TREK repository advisory GHSA-9hc8-p7gm-p7mx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/liketrek/TREK/security/advisories/GHSA-9hc8-p7gm-p7mx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77321",
   "state": "RESERVED",
   "public_date": "2026-07-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-11"
   },
   "refs": "ghsa-repos:liketrek/TREK\tGHSA-qvw8-w937-vcmq",
   "description": "liketrek/TREK repository advisory GHSA-qvw8-w937-vcmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 66,
   "clock_known": true,
   "hours_public": 1584,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-11",
   "advisory_days_public": 66,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/liketrek/TREK/security/advisories/GHSA-qvw8-w937-vcmq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73154",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73154\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73154.json;debian:svxlink;redhat:CVE-2026-73154;ubuntu-osv:UBUNTU-CVE-2026-73154;ubuntu:CVE-2026-73154",
   "description": "[GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73154.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73154",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73154",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73154",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73154"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73153",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73153\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73153.json;debian:svxlink;redhat:CVE-2026-73153;ubuntu-osv:UBUNTU-CVE-2026-73153;ubuntu:CVE-2026-73153",
   "description": "[GHSA-624p-cp8x-6hp6: EchoLink RTCP/SDES: out-of-bounds read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73153.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73153",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73153",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73153",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73153"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73152",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73152\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73152.json;debian:svxlink;redhat:CVE-2026-73152;ubuntu-osv:UBUNTU-CVE-2026-73152;ubuntu:CVE-2026-73152",
   "description": "[GHSA-4g8q-rgxf-fmgf: EchoLink proxy: integer truncation in message length]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73152.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73152",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73152",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73152",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73152"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73151",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73151\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73151.json;debian:svxlink;redhat:CVE-2026-73151;ubuntu-osv:UBUNTU-CVE-2026-73151;ubuntu:CVE-2026-73151",
   "description": "[GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73151.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73151",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73151",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73151",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73151"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73150",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73150\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73150.json;debian:svxlink;redhat:CVE-2026-73150;ubuntu-osv:UBUNTU-CVE-2026-73150;ubuntu:CVE-2026-73150",
   "description": "[GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73150.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73150",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73150",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73150",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73150"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73148",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73148\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73148.json;debian:svxlink;redhat:CVE-2026-73148;ubuntu-osv:UBUNTU-CVE-2026-73148;ubuntu:CVE-2026-73148",
   "description": "[GHSA-6wgq-wg3w-jgvx: svxreflector: use-after-free write via dangling JSON reference]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73148.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73148",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73148",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73148",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73148"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73146",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73146\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73146.json;debian:svxlink;redhat:CVE-2026-73146;ubuntu-osv:UBUNTU-CVE-2026-73146;ubuntu:CVE-2026-73146",
   "description": "[GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73146.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73146",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73146",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73146",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73146"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73145",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-13",
    "csaf": "2026-07-13"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73145\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73145.json;debian:svxlink;redhat:CVE-2026-73145;ubuntu-osv:UBUNTU-CVE-2026-73145;ubuntu:CVE-2026-73145",
   "description": "[GHSA-58ph-q79f-7x9x: HTTP server: unbounded request accumulation]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73145.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73145",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73145",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73145",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73145"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59766",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-07-21",
    "ghsa-repos": "2026-07-13",
    "osv": "2026-07-21"
   },
   "refs": "ghsa-repos:go-gitea/gitea\tGHSA-qf2f-qh6p-7v89;ghsa:GHSA-qf2f-qh6p-7v89;osv:Go:code.gitea.io/gitea",
   "description": "Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "code.gitea.io/gitea",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-qf2f-qh6p-7v89",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-qf2f-qh6p-7v89",
    "osv": "https://osv.dev/list?q=CVE-2026-59766"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47677",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-c67f-gmxw-mj93;osv:Packagist:facturascripts/facturascripts",
   "description": "FacturaScripts: Account takeover of any 2FA-enabled user",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "facturascripts/facturascripts",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-c67f-gmxw-mj93",
    "osv": "https://osv.dev/list?q=CVE-2026-47677"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61668",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-vg99-gr89-qhw9;osv:PyPI:dirac",
   "description": "DIRAC: Pilot code downloaded over unverified HTTPS connection",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "dirac",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-vg99-gr89-qhw9",
    "osv": "https://osv.dev/list?q=CVE-2026-61668"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61667",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-m4m7-4cw8-62j6;osv:PyPI:dirac",
   "description": "DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "dirac",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-m4m7-4cw8-62j6",
    "osv": "https://osv.dev/list?q=CVE-2026-61667"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55372",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-4chg-4752-w88r;osv:Packagist:nukeviet/nukeviet",
   "description": "NukeViet: Pre-authentication SSRF via X-Forwarded-Host",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nukeviet/nukeviet",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-4chg-4752-w88r",
    "osv": "https://osv.dev/list?q=CVE-2026-55372"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54065",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-c9xg-64p9-f2jj;osv:Packagist:nukeviet/nukeviet",
   "description": "NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nukeviet/nukeviet",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-c9xg-64p9-f2jj",
    "osv": "https://osv.dev/list?q=CVE-2026-54065"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54064",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-465g-4q99-5x86;osv:Packagist:nukeviet/nukeviet",
   "description": "NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nukeviet/nukeviet",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-465g-4q99-5x86",
    "osv": "https://osv.dev/list?q=CVE-2026-54064"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49259",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-w2w5-w2pw-r929;osv:Packagist:nukeviet/nukeviet",
   "description": "NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nukeviet/nukeviet",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-w2w5-w2pw-r929",
    "osv": "https://osv.dev/list?q=CVE-2026-49259"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48118",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-mxpf-qgg6-v3ff;osv:Packagist:nukeviet/nukeviet",
   "description": "NukeViet: Unauthenticated Reflected XSS in Comment Module",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nukeviet/nukeviet",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-mxpf-qgg6-v3ff",
    "osv": "https://osv.dev/list?q=CVE-2026-48118"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45579",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-13",
    "osv": "2026-07-13"
   },
   "refs": "ghsa:GHSA-9jpv-c7p4-997x;osv:PyPI:dirac",
   "description": "DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "dirac",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-9jpv-c7p4-997x",
    "osv": "https://osv.dev/list?q=CVE-2026-45579"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77470",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-476v-jr53-8rxc",
   "description": "LycheeOrg/Lychee repository advisory GHSA-476v-jr53-8rxc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-476v-jr53-8rxc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77468",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-xg8r-4pm3-2h4f",
   "description": "LycheeOrg/Lychee repository advisory GHSA-xg8r-4pm3-2h4f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-xg8r-4pm3-2h4f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77467",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-6736-fhxv-3p79",
   "description": "LycheeOrg/Lychee repository advisory GHSA-6736-fhxv-3p79",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-6736-fhxv-3p79"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77466",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:LycheeOrg/Lychee\tGHSA-5wh2-hg7q-6hv3",
   "description": "LycheeOrg/Lychee repository advisory GHSA-5wh2-hg7q-6hv3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-5wh2-hg7q-6hv3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53574",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-qgm7-fc9g-fj75",
   "description": "espocrm/espocrm repository advisory GHSA-qgm7-fc9g-fj75",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-qgm7-fc9g-fj75"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61706",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:infracost/actions\tGHSA-whm3-8375-8m8j",
   "description": "infracost/actions repository advisory GHSA-whm3-8375-8m8j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/infracost/actions/security/advisories/GHSA-whm3-8375-8m8j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77396",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:pjsip/pjproject\tGHSA-6p2p-5wf8-h5hr",
   "description": "pjsip/pjproject repository advisory GHSA-6p2p-5wf8-h5hr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pjsip/pjproject/security/advisories/GHSA-6p2p-5wf8-h5hr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62662",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:pocket-id/pocket-id\tGHSA-q4xm-p75h-h9p3",
   "description": "pocket-id/pocket-id repository advisory GHSA-q4xm-p75h-h9p3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pocket-id/pocket-id/security/advisories/GHSA-q4xm-p75h-h9p3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61830",
   "state": "RESERVED",
   "public_date": "2026-07-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-13"
   },
   "refs": "ghsa-repos:rabbitmq/cluster-operator\tGHSA-c7f3-92gv-rj3w",
   "description": "rabbitmq/cluster-operator repository advisory GHSA-c7f3-92gv-rj3w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 64,
   "clock_known": true,
   "hours_public": 1536,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-13",
   "advisory_days_public": 64,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/cluster-operator/security/advisories/GHSA-c7f3-92gv-rj3w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61626",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-14"
   },
   "refs": "debian:libass;ubuntu-osv:UBUNTU-CVE-2026-61626",
   "description": "[GHSA-5gf7-wjfm-vmvm: Out-of-bounds bit clears for negative Matroska ReadOrder values]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libass",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61626",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61626"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50583",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-14"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11267-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50583",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50583",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50583",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50583"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50587",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-14"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11267-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50587",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50587",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50587",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50587"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50584",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-14"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11267-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50584",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50584",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50584",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50584"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54435",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-14"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11267-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-54435",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-54435",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-54435",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-54435"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61627",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-14"
   },
   "refs": "debian:libass;ubuntu-osv:UBUNTU-CVE-2026-61627",
   "description": "[GHSA-pjjp-65r7-ppgm: Out-of-bounds read and write in wrap_lines_measure]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libass",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61627",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61627"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50713",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-14"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11267-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-50713",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-50713",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50713",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50713"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35336",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-23",
    "csaf": "2026-07-14"
   },
   "refs": "alpine:mbedtls;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11267-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json;debian:mbedtls;ubuntu-osv:UBUNTU-CVE-2026-35336",
   "description": "mbedtls",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mbedtls",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-35336",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11267-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-35336",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-35336"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54446",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-x9vc-9ffq-p3gj;osv:PyPI:netlicensing-mcp",
   "description": "NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netlicensing-mcp",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-x9vc-9ffq-p3gj",
    "osv": "https://osv.dev/list?q=CVE-2026-54446"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50158",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-2c7f-fxww-6w6c;osv:Go:github.com/eat-pray-ai/yutu",
   "description": "yutu: Arbitrary File Write via MCP `caption-download` Tool",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/eat-pray-ai/yutu",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-2c7f-fxww-6w6c",
    "osv": "https://osv.dev/list?q=CVE-2026-50158"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50125",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-qw5r-ppcg-f8rj;osv:Go:github.com/StacklokLabs/mkp",
   "description": "MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/StacklokLabs/mkp",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-qw5r-ppcg-f8rj",
    "osv": "https://osv.dev/list?q=CVE-2026-50125"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45710",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-3x7p-v8hj-xh5m;osv:Packagist:facturascripts/facturascripts",
   "description": "FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "facturascripts/facturascripts",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-3x7p-v8hj-xh5m",
    "osv": "https://osv.dev/list?q=CVE-2026-45710"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45263",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-2p5x-4jr6-x5jg;osv:Packagist:facturascripts/facturascripts",
   "description": "FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "facturascripts/facturascripts",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-2p5x-4jr6-x5jg",
    "osv": "https://osv.dev/list?q=CVE-2026-45263"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45693",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-cv65-7cg8-r623;osv:Packagist:facturascripts/facturascripts",
   "description": "FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "facturascripts/facturascripts",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-cv65-7cg8-r623",
    "osv": "https://osv.dev/list?q=CVE-2026-45693"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45262",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-14",
    "osv": "2026-07-14"
   },
   "refs": "ghsa:GHSA-5qmh-x653-g8qj;osv:Packagist:facturascripts/facturascripts",
   "description": "FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "facturascripts/facturascripts",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-5qmh-x653-g8qj",
    "osv": "https://osv.dev/list?q=CVE-2026-45262"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77511",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:Taskosaur/Taskosaur\tGHSA-m586-9w8m-j724",
   "description": "Taskosaur/Taskosaur repository advisory GHSA-m586-9w8m-j724",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-m586-9w8m-j724"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77512",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:Taskosaur/Taskosaur\tGHSA-c6m7-2c78-p2m5",
   "description": "Taskosaur/Taskosaur repository advisory GHSA-c6m7-2c78-p2m5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-c6m7-2c78-p2m5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77510",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:Taskosaur/Taskosaur\tGHSA-97m3-fcc5-v5r2",
   "description": "Taskosaur/Taskosaur repository advisory GHSA-97m3-fcc5-v5r2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-97m3-fcc5-v5r2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77513",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:Taskosaur/Taskosaur\tGHSA-fjwc-33jp-r5xr",
   "description": "Taskosaur/Taskosaur repository advisory GHSA-fjwc-33jp-r5xr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-fjwc-33jp-r5xr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77514",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:Taskosaur/Taskosaur\tGHSA-2653-wx6f-7xv9",
   "description": "Taskosaur/Taskosaur repository advisory GHSA-2653-wx6f-7xv9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-2653-wx6f-7xv9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77509",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:Taskosaur/Taskosaur\tGHSA-48c6-42cv-7fqx",
   "description": "Taskosaur/Taskosaur repository advisory GHSA-48c6-42cv-7fqx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-48c6-42cv-7fqx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77475",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:dromara/MaxKey\tGHSA-2w2v-jphx-727v",
   "description": "dromara/MaxKey repository advisory GHSA-2w2v-jphx-727v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dromara/MaxKey/security/advisories/GHSA-2w2v-jphx-727v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62664",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-p7vh-cjpm-rmrq",
   "description": "error311/FileRise repository advisory GHSA-p7vh-cjpm-rmrq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-p7vh-cjpm-rmrq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61844",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-qpm8-pgmq-wxmh",
   "description": "error311/FileRise repository advisory GHSA-qpm8-pgmq-wxmh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-qpm8-pgmq-wxmh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61843",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-r787-5hp3-4874",
   "description": "error311/FileRise repository advisory GHSA-r787-5hp3-4874",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-r787-5hp3-4874"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55184",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-x5p5-8mxj-9wv6",
   "description": "espocrm/espocrm repository advisory GHSA-x5p5-8mxj-9wv6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-x5p5-8mxj-9wv6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55154",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-xrwp-2gph-985x",
   "description": "espocrm/espocrm repository advisory GHSA-xrwp-2gph-985x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-xrwp-2gph-985x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53575",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-f34h-xxmv-j9xp",
   "description": "espocrm/espocrm repository advisory GHSA-f34h-xxmv-j9xp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-f34h-xxmv-j9xp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59994",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-3rh4-9hcq-g79m",
   "description": "espocrm/espocrm repository advisory GHSA-3rh4-9hcq-g79m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-3rh4-9hcq-g79m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77613",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:opensearch-project/OpenSearch-Dashboards\tGHSA-wjg9-wg2q-394h",
   "description": "opensearch-project/OpenSearch-Dashboards repository advisory GHSA-wjg9-wg2q-394h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opensearch-project/OpenSearch-Dashboards/security/advisories/GHSA-wjg9-wg2q-394h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77571",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:orangehrm/orangehrm\tGHSA-qr4m-m725-637v",
   "description": "orangehrm/orangehrm repository advisory GHSA-qr4m-m725-637v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/orangehrm/orangehrm/security/advisories/GHSA-qr4m-m725-637v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77570",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:orangehrm/orangehrm\tGHSA-wqfp-gjm9-mwcp",
   "description": "orangehrm/orangehrm repository advisory GHSA-wqfp-gjm9-mwcp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/orangehrm/orangehrm/security/advisories/GHSA-wqfp-gjm9-mwcp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77569",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:orangehrm/orangehrm\tGHSA-p6vw-r6rx-pcc3",
   "description": "orangehrm/orangehrm repository advisory GHSA-p6vw-r6rx-pcc3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/orangehrm/orangehrm/security/advisories/GHSA-p6vw-r6rx-pcc3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77621",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:vectordotdev/vector\tGHSA-6342-xwvw-c637",
   "description": "vectordotdev/vector repository advisory GHSA-6342-xwvw-c637",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/vectordotdev/vector/security/advisories/GHSA-6342-xwvw-c637"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77620",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:vectordotdev/vector\tGHSA-qp6f-fpfx-4gg6",
   "description": "vectordotdev/vector repository advisory GHSA-qp6f-fpfx-4gg6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/vectordotdev/vector/security/advisories/GHSA-qp6f-fpfx-4gg6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77619",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:vectordotdev/vector\tGHSA-rrfg-9487-mhp6",
   "description": "vectordotdev/vector repository advisory GHSA-rrfg-9487-mhp6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/vectordotdev/vector/security/advisories/GHSA-rrfg-9487-mhp6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77572",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-14"
   },
   "refs": "ghsa-repos:veracrypt/VeraCrypt\tGHSA-9mgv-w2fw-3m78",
   "description": "veracrypt/VeraCrypt repository advisory GHSA-9mgv-w2fw-3m78",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/veracrypt/VeraCrypt/security/advisories/GHSA-9mgv-w2fw-3m78"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42491",
   "state": "RESERVED",
   "public_date": "2026-07-14",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-07-14"
   },
   "refs": "alpine:xen;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2359\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2359.json",
   "description": "CVE-2026-42491",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 63,
   "clock_known": true,
   "hours_public": 1512,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-14",
   "advisory_days_public": 63,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "xen",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-42491",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2359.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73147",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-15",
    "csaf": "2026-07-15"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73147\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73147.json;debian:svxlink;redhat:CVE-2026-73147;ubuntu-osv:UBUNTU-CVE-2026-73147;ubuntu:CVE-2026-73147",
   "description": "[GHSA-pc2g-2p95-4cr5: TCL command injection in reflector client]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73147.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73147",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73147",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73147",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73147"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73141",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-15",
    "csaf": "2026-07-15"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73141\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73141.json;debian:svxlink;redhat:CVE-2026-73141;ubuntu-osv:UBUNTU-CVE-2026-73141;ubuntu:CVE-2026-73141",
   "description": "[GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73141.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73141",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73141",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73141",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73141"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46570",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-21"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-46570\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46570.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-46570",
   "description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-46570",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46570.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-46570",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-46570"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42618",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-22"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-42618\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-42618.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-42618",
   "description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-42618",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-42618.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-42618",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-42618"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42617",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-22"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-42617\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-42617.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-42617",
   "description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-42617",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-42617.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-42617",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-42617"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46571",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-21"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-46571\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46571.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-46571",
   "description": "In NTFS-3G through 2026.2.25, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-46571",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46571.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-46571",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-46571"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46572",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-21"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-46572\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46572.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-46572",
   "description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-46572",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46572.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-46572",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-46572"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46569",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-21"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-46569\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46569.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-46569",
   "description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-46569",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-46569.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-46569",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-46569"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42616",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-15",
    "csaf": "2026-07-22"
   },
   "refs": "alpine:ntfs-3g;csaf:SUSE Product Security Team\tCVE-2026-42616\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-42616.json;debian:ntfs-3g;ubuntu-osv:UBUNTU-CVE-2026-42616",
   "description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in cat() in cat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ntfs-3g",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-42616",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-42616.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-42616",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-42616"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54504",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-6f5r-5672-72j7;osv:npm:@andrea9293/mcp-documentation-server",
   "description": "@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@andrea9293/mcp-documentation-server",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-6f5r-5672-72j7",
    "osv": "https://osv.dev/list?q=CVE-2026-54504"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50285",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-ggw3-5987-rx77;osv:Go:github.com/pomerium/pomerium",
   "description": "Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/pomerium/pomerium",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-ggw3-5987-rx77",
    "osv": "https://osv.dev/list?q=CVE-2026-50285"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54495",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-398h-7f66-3h4p;osv:Go:github.com/open-feature/open-feature-operator",
   "description": "open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/open-feature/open-feature-operator",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-398h-7f66-3h4p",
    "osv": "https://osv.dev/list?q=CVE-2026-54495"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62944",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-h2wf-967x-gxvw;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: Stored XSS in print_all_bug_page_word.php",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-h2wf-967x-gxvw",
    "osv": "https://osv.dev/list?q=CVE-2026-62944"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52883",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-4vpf-w7qv-5h3q;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-4vpf-w7qv-5h3q",
    "osv": "https://osv.dev/list?q=CVE-2026-52883"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52882",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-3v2j-6fw9-f57c;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-3v2j-6fw9-f57c",
    "osv": "https://osv.dev/list?q=CVE-2026-52882"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52881",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-vcrw-4xvv-jh49;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: Reflected XSS in admin/install.php via unescaped printf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-vcrw-4xvv-jh49",
    "osv": "https://osv.dev/list?q=CVE-2026-52881"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52847",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-77x8-3v3h-hrhv;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: Reflected XSS in admin/install.php",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-77x8-3v3h-hrhv",
    "osv": "https://osv.dev/list?q=CVE-2026-52847"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54451",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-rv48-qqj5-crxg;osv:Hex:protobuf",
   "description": "Protobuf: Unbounded recursion depth in embedded-message decoding",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "protobuf",
   "ecosystem": "Hex",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-rv48-qqj5-crxg",
    "osv": "https://osv.dev/list?q=CVE-2026-54451"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49280",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-m7ph-9558-mrx3;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: REST API unauthorized Issue status change",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-m7ph-9558-mrx3",
    "osv": "https://osv.dev/list?q=CVE-2026-49280"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49273",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-v84x-qvhg-f36r;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-v84x-qvhg-f36r",
    "osv": "https://osv.dev/list?q=CVE-2026-49273"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47142",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-15",
    "osv": "2026-07-15"
   },
   "refs": "ghsa:GHSA-mw6p-33vw-46cc;osv:Packagist:mantisbt/mantisbt",
   "description": "MantisBT: SQL Injection via history_order Configuration Value",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mantisbt/mantisbt",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-mw6p-33vw-46cc",
    "osv": "https://osv.dev/list?q=CVE-2026-47142"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-41582",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:Countly/countly-server\tGHSA-fqgp-6rm9-8696",
   "description": "Countly/countly-server repository advisory GHSA-fqgp-6rm9-8696",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Countly/countly-server/security/advisories/GHSA-fqgp-6rm9-8696"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42270",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:Countly/countly-server\tGHSA-86cv-qwp9-jwp3",
   "description": "Countly/countly-server repository advisory GHSA-86cv-qwp9-jwp3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Countly/countly-server/security/advisories/GHSA-86cv-qwp9-jwp3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42269",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:Countly/countly-server\tGHSA-5pmc-54j6-jcgq",
   "description": "Countly/countly-server repository advisory GHSA-5pmc-54j6-jcgq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Countly/countly-server/security/advisories/GHSA-5pmc-54j6-jcgq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44977",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:Countly/countly-server\tGHSA-jqp4-p86c-phxc",
   "description": "Countly/countly-server repository advisory GHSA-jqp4-p86c-phxc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Countly/countly-server/security/advisories/GHSA-jqp4-p86c-phxc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81502",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:RARgames/4gaBoards\tGHSA-jmxf-h386-fm2h",
   "description": "RARgames/4gaBoards repository advisory GHSA-jmxf-h386-fm2h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/RARgames/4gaBoards/security/advisories/GHSA-jmxf-h386-fm2h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81178",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:Syslifters/sysreptor\tGHSA-926c-j47w-8f9c",
   "description": "Syslifters/sysreptor repository advisory GHSA-926c-j47w-8f9c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Syslifters/sysreptor/security/advisories/GHSA-926c-j47w-8f9c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79920",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:ajenti/ajenti\tGHSA-j8xf-5fw2-f99q",
   "description": "ajenti/ajenti repository advisory GHSA-j8xf-5fw2-f99q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ajenti/ajenti/security/advisories/GHSA-j8xf-5fw2-f99q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77624",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:akuity/kargo\tGHSA-xx8h-gw9m-m95p",
   "description": "akuity/kargo repository advisory GHSA-xx8h-gw9m-m95p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/akuity/kargo/security/advisories/GHSA-xx8h-gw9m-m95p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77623",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:akuity/kargo\tGHSA-f72x-6fm6-94rq",
   "description": "akuity/kargo repository advisory GHSA-f72x-6fm6-94rq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/akuity/kargo/security/advisories/GHSA-f72x-6fm6-94rq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63348",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:conda/menuinst\tGHSA-fqh4-w37r-x339",
   "description": "conda/menuinst repository advisory GHSA-fqh4-w37r-x339",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/conda/menuinst/security/advisories/GHSA-fqh4-w37r-x339"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55080",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:element-hq/element-x-android\tGHSA-r4f9-46vw-v7g3",
   "description": "element-hq/element-x-android repository advisory GHSA-r4f9-46vw-v7g3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/element-hq/element-x-android/security/advisories/GHSA-r4f9-46vw-v7g3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62856",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-gh3r-jh6q-wrvj",
   "description": "freescout-help-desk/freescout repository advisory GHSA-gh3r-jh6q-wrvj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-gh3r-jh6q-wrvj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62855",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-9ph7-f3hc-95gg",
   "description": "freescout-help-desk/freescout repository advisory GHSA-9ph7-f3hc-95gg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9ph7-f3hc-95gg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62854",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-jpq8-j69f-mj98",
   "description": "freescout-help-desk/freescout repository advisory GHSA-jpq8-j69f-mj98",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-jpq8-j69f-mj98"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62852",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-w668-wq26-6c94",
   "description": "freescout-help-desk/freescout repository advisory GHSA-w668-wq26-6c94",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-w668-wq26-6c94"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62851",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-wqq7-4q7m-273v",
   "description": "freescout-help-desk/freescout repository advisory GHSA-wqq7-4q7m-273v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wqq7-4q7m-273v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62850",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-w2p9-3666-vw9j",
   "description": "freescout-help-desk/freescout repository advisory GHSA-w2p9-3666-vw9j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-w2p9-3666-vw9j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81173",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:matrix-org/matrix-hookshot\tGHSA-77cp-42c4-85vm",
   "description": "matrix-org/matrix-hookshot repository advisory GHSA-77cp-42c4-85vm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/matrix-org/matrix-hookshot/security/advisories/GHSA-77cp-42c4-85vm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63659",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:mz-automation/lib60870\tGHSA-fc2j-39h7-c7v9",
   "description": "mz-automation/lib60870 repository advisory GHSA-fc2j-39h7-c7v9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/mz-automation/lib60870/security/advisories/GHSA-fc2j-39h7-c7v9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65983",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:openemr/openemr\tGHSA-vv5j-6gjw-ffx9",
   "description": "openemr/openemr repository advisory GHSA-vv5j-6gjw-ffx9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openemr/openemr/security/advisories/GHSA-vv5j-6gjw-ffx9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77630",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:pupnp/pupnp\tGHSA-46ph-jff5-5h77",
   "description": "pupnp/pupnp repository advisory GHSA-46ph-jff5-5h77",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pupnp/pupnp/security/advisories/GHSA-46ph-jff5-5h77"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58273",
   "state": "RESERVED",
   "public_date": "2026-07-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-15"
   },
   "refs": "ghsa-repos:rucio/rucio\tGHSA-5j9r-fx4x-rpvg",
   "description": "rucio/rucio repository advisory GHSA-5j9r-fx4x-rpvg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 62,
   "clock_known": true,
   "hours_public": 1488,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-15",
   "advisory_days_public": 62,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rucio/rucio/security/advisories/GHSA-5j9r-fx4x-rpvg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73149",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-16",
    "csaf": "2026-07-16"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73149\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73149.json;debian:svxlink;redhat:CVE-2026-73149;ubuntu-osv:UBUNTU-CVE-2026-73149;ubuntu:CVE-2026-73149",
   "description": "[GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73149.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73149",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73149",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73149",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73149"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61540",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-cvj4-wrx6-rrff",
   "description": "EVerest/EVerest repository advisory GHSA-cvj4-wrx6-rrff",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-cvj4-wrx6-rrff"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63507",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-mwr9-98r5-gcqr",
   "description": "EVerest/EVerest repository advisory GHSA-mwr9-98r5-gcqr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-mwr9-98r5-gcqr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54170",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-pr66-c6c8-pc5v",
   "description": "EVerest/EVerest repository advisory GHSA-pr66-c6c8-pc5v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-pr66-c6c8-pc5v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63624",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-855p-r2x5-fv5q",
   "description": "EVerest/EVerest repository advisory GHSA-855p-r2x5-fv5q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-855p-r2x5-fv5q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54169",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-gggc-vwmj-53wp",
   "description": "EVerest/EVerest repository advisory GHSA-gggc-vwmj-53wp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-gggc-vwmj-53wp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40932",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-5c2x-34h2-3v55",
   "description": "EVerest/EVerest repository advisory GHSA-5c2x-34h2-3v55",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-5c2x-34h2-3v55"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42292",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:EVerest/EVerest\tGHSA-6rx6-q6r6-mmj5",
   "description": "EVerest/EVerest repository advisory GHSA-6rx6-q6r6-mmj5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/EVerest/EVerest/security/advisories/GHSA-6rx6-q6r6-mmj5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63013",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:NationalSecurityAgency/skills-service\tGHSA-67x3-r85f-822r",
   "description": "NationalSecurityAgency/skills-service repository advisory GHSA-67x3-r85f-822r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/NationalSecurityAgency/skills-service/security/advisories/GHSA-67x3-r85f-822r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63014",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:NationalSecurityAgency/skills-service\tGHSA-p527-vjfp-c43p",
   "description": "NationalSecurityAgency/skills-service repository advisory GHSA-p527-vjfp-c43p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/NationalSecurityAgency/skills-service/security/advisories/GHSA-p527-vjfp-c43p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49868",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:RIOT-OS/RIOT\tGHSA-p3fx-9qcg-jmcf",
   "description": "RIOT-OS/RIOT repository advisory GHSA-p3fx-9qcg-jmcf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-p3fx-9qcg-jmcf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62972",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-9hq3-w3pc-8385",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-9hq3-w3pc-8385",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-9hq3-w3pc-8385"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62977",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-mwj7-2v5r-v934",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-mwj7-2v5r-v934",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-mwj7-2v5r-v934"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62975",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-cf8g-hp9m-9fvv",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-cf8g-hp9m-9fvv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-cf8g-hp9m-9fvv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62976",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-32jj-x86x-w98w",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-32jj-x86x-w98w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-32jj-x86x-w98w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62974",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-2c8x-f46r-8phh",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-2c8x-f46r-8phh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-2c8x-f46r-8phh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62973",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:bacnet-stack/bacnet-stack\tGHSA-3xxw-jfwm-rq9c",
   "description": "bacnet-stack/bacnet-stack repository advisory GHSA-3xxw-jfwm-rq9c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-3xxw-jfwm-rq9c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64683",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:cryptomator/hub\tGHSA-hq3g-4c59-cgg7",
   "description": "cryptomator/hub repository advisory GHSA-hq3g-4c59-cgg7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cryptomator/hub/security/advisories/GHSA-hq3g-4c59-cgg7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64681",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:cryptomator/hub\tGHSA-p94x-9592-5r73",
   "description": "cryptomator/hub repository advisory GHSA-p94x-9592-5r73",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cryptomator/hub/security/advisories/GHSA-p94x-9592-5r73"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64674",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:cryptomator/hub\tGHSA-99p9-vhhj-2x98",
   "description": "cryptomator/hub repository advisory GHSA-99p9-vhhj-2x98",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cryptomator/hub/security/advisories/GHSA-99p9-vhhj-2x98"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56682",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:decolua/9router\tGHSA-32gc-64m7-hj7v",
   "description": "decolua/9router repository advisory GHSA-32gc-64m7-hj7v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/decolua/9router/security/advisories/GHSA-32gc-64m7-hj7v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56681",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:decolua/9router\tGHSA-5mj8-gf6m-fhw8",
   "description": "decolua/9router repository advisory GHSA-5mj8-gf6m-fhw8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/decolua/9router/security/advisories/GHSA-5mj8-gf6m-fhw8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83803",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:getsentry/sentry\tGHSA-xm86-7c47-gjm4",
   "description": "getsentry/sentry repository advisory GHSA-xm86-7c47-gjm4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/getsentry/sentry/security/advisories/GHSA-xm86-7c47-gjm4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77614",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:opencast/opencast\tGHSA-6f53-jp7x-gg7p",
   "description": "opencast/opencast repository advisory GHSA-6f53-jp7x-gg7p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opencast/opencast/security/advisories/GHSA-6f53-jp7x-gg7p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77615",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:opencast/opencast\tGHSA-m6c8-jcw2-5r25",
   "description": "opencast/opencast repository advisory GHSA-m6c8-jcw2-5r25",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76805",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:projectdiscovery/nuclei\tGHSA-jpvm-9frm-hjcq",
   "description": "projectdiscovery/nuclei repository advisory GHSA-jpvm-9frm-hjcq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpvm-9frm-hjcq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76804",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:projectdiscovery/nuclei\tGHSA-qgw5-7j4f-fg97",
   "description": "projectdiscovery/nuclei repository advisory GHSA-qgw5-7j4f-fg97",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-qgw5-7j4f-fg97"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76803",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:projectdiscovery/nuclei\tGHSA-xhmx-w2j4-rw3q",
   "description": "projectdiscovery/nuclei repository advisory GHSA-xhmx-w2j4-rw3q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-xhmx-w2j4-rw3q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76802",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:projectdiscovery/nuclei\tGHSA-jpf4-98qj-qr67",
   "description": "projectdiscovery/nuclei repository advisory GHSA-jpf4-98qj-qr67",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpf4-98qj-qr67"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76819",
   "state": "RESERVED",
   "public_date": "2026-07-16",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-16"
   },
   "refs": "ghsa-repos:projectdiscovery/nuclei\tGHSA-vxg7-f2jj-jmqm",
   "description": "projectdiscovery/nuclei repository advisory GHSA-vxg7-f2jj-jmqm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 61,
   "clock_known": true,
   "hours_public": 1464,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-16",
   "advisory_days_public": 61,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62321",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-17",
    "ghsa-repos": "2026-09-11"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-42mm-6m68-h9g2;ubuntu-osv:UBUNTU-CVE-2026-62321",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-11",
   "advisory_days_public": 4,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-62321",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-62321",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-42mm-6m68-h9g2",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-62321"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62319",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-17",
    "ghsa-repos": "2026-09-11"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-h2jj-64fr-9grq;ubuntu-osv:UBUNTU-CVE-2026-62319",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-11",
   "advisory_days_public": 4,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-62319",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-62319",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-h2jj-64fr-9grq",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-62319"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62318",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-17",
    "ghsa-repos": "2026-09-11"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-5wp7-47vr-j2mh;ubuntu-osv:UBUNTU-CVE-2026-62318",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-11",
   "advisory_days_public": 4,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-62318",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-62318",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-5wp7-47vr-j2mh",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-62318"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62320",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "alpine,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-07-17",
    "ghsa-repos": "2026-09-11"
   },
   "refs": "alpine:netatalk;debian:netatalk;ghsa-repos:Netatalk/netatalk\tGHSA-5gqf-6pmp-7932;ubuntu-osv:UBUNTU-CVE-2026-62320",
   "description": "netatalk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-11",
   "advisory_days_public": 4,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "netatalk",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-62320",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-62320",
    "ghsa-repos": "https://github.com/Netatalk/netatalk/security/advisories/GHSA-5gqf-6pmp-7932",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-62320"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55177",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-17",
    "osv": "2026-07-17"
   },
   "refs": "ghsa:GHSA-r95q-fp26-h3hc;osv:npm:@tak-ps/cloudtak",
   "description": "CloudTAK: Authenticated full-read SSRF in the /api/esri* routes \u2014 user-controlled URL fetched with no IP-classification guard",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@tak-ps/cloudtak",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-r95q-fp26-h3hc",
    "osv": "https://osv.dev/list?q=CVE-2026-55177"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54546",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-17",
    "osv": "2026-07-17"
   },
   "refs": "ghsa:GHSA-vqrw-qphh-p34v;osv:npm:@tak-ps/cloudtak",
   "description": "TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) \u2014 no IP-classification guard",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@tak-ps/cloudtak",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-vqrw-qphh-p34v",
    "osv": "https://osv.dev/list?q=CVE-2026-54546"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54547",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-17",
    "osv": "2026-07-17"
   },
   "refs": "ghsa:GHSA-2v2f-mvfg-ph56;osv:PyPI:meta-ads-mcp",
   "description": "meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "meta-ads-mcp",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-2v2f-mvfg-ph56",
    "osv": "https://osv.dev/list?q=CVE-2026-54547"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54549",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-17",
    "osv": "2026-07-17"
   },
   "refs": "ghsa:GHSA-45gf-fjxp-cjpq;osv:PyPI:meta-ads-mcp",
   "description": "meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "meta-ads-mcp",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-45gf-fjxp-cjpq",
    "osv": "https://osv.dev/list?q=CVE-2026-54549"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84360",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-vc32-4gwf-77xp",
   "description": "0xJacky/nginx-ui repository advisory GHSA-vc32-4gwf-77xp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-vc32-4gwf-77xp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84321",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-wq4w-vwvq-q3x9",
   "description": "0xJacky/nginx-ui repository advisory GHSA-wq4w-vwvq-q3x9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-wq4w-vwvq-q3x9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84320",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-jrq7-xrjx-pcfw",
   "description": "0xJacky/nginx-ui repository advisory GHSA-jrq7-xrjx-pcfw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-jrq7-xrjx-pcfw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84318",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-9jww-cxg5-rj9m",
   "description": "0xJacky/nginx-ui repository advisory GHSA-9jww-cxg5-rj9m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-9jww-cxg5-rj9m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84319",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-5r62-gj48-897x",
   "description": "0xJacky/nginx-ui repository advisory GHSA-5r62-gj48-897x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-5r62-gj48-897x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84317",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-76pm-mq2q-9gcr",
   "description": "0xJacky/nginx-ui repository advisory GHSA-76pm-mq2q-9gcr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-76pm-mq2q-9gcr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84316",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-cf23-7qxj-xmhr",
   "description": "0xJacky/nginx-ui repository advisory GHSA-cf23-7qxj-xmhr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-cf23-7qxj-xmhr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84313",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-gfrc-g87h-7h5w",
   "description": "0xJacky/nginx-ui repository advisory GHSA-gfrc-g87h-7h5w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-gfrc-g87h-7h5w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84315",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-5v7c-xpfp-p65m",
   "description": "0xJacky/nginx-ui repository advisory GHSA-5v7c-xpfp-p65m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-5v7c-xpfp-p65m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84314",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-2gc7-j998-5xx6",
   "description": "0xJacky/nginx-ui repository advisory GHSA-2gc7-j998-5xx6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-2gc7-j998-5xx6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84312",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:0xJacky/nginx-ui\tGHSA-44xr-mrhh-qm78",
   "description": "0xJacky/nginx-ui repository advisory GHSA-44xr-mrhh-qm78",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-44xr-mrhh-qm78"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62678",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:cline/kanban\tGHSA-33x2-jv8j-4cxv",
   "description": "cline/kanban repository advisory GHSA-33x2-jv8j-4cxv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cline/kanban/security/advisories/GHSA-33x2-jv8j-4cxv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77375",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:drakkan/sftpgo\tGHSA-q7pc-356p-hggc",
   "description": "drakkan/sftpgo repository advisory GHSA-q7pc-356p-hggc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/drakkan/sftpgo/security/advisories/GHSA-q7pc-356p-hggc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63340",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:eProsima/Fast-DDS\tGHSA-wv5q-wgv8-qh6v",
   "description": "eProsima/Fast-DDS repository advisory GHSA-wv5q-wgv8-qh6v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-wv5q-wgv8-qh6v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71860",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:kubeflow/hub\tGHSA-f85g-49hf-cp5c",
   "description": "kubeflow/hub repository advisory GHSA-f85g-49hf-cp5c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kubeflow/hub/security/advisories/GHSA-f85g-49hf-cp5c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63631",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:kubeflow/hub\tGHSA-r7g8-78wq-m666",
   "description": "kubeflow/hub repository advisory GHSA-r7g8-78wq-m666",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kubeflow/hub/security/advisories/GHSA-r7g8-78wq-m666"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85272",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:openedx/openedx-platform\tGHSA-6cmm-8875-5pcw",
   "description": "openedx/openedx-platform repository advisory GHSA-6cmm-8875-5pcw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openedx/openedx-platform/security/advisories/GHSA-6cmm-8875-5pcw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85271",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:openedx/openedx-platform\tGHSA-rv5w-f4r5-h77g",
   "description": "openedx/openedx-platform repository advisory GHSA-rv5w-f4r5-h77g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openedx/openedx-platform/security/advisories/GHSA-rv5w-f4r5-h77g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84975",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:pjsip/pjproject\tGHSA-382p-87mh-r3q8",
   "description": "pjsip/pjproject repository advisory GHSA-382p-87mh-r3q8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pjsip/pjproject/security/advisories/GHSA-382p-87mh-r3q8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85056",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:zitadel/zitadel\tGHSA-9993-rfwp-rhwf",
   "description": "zitadel/zitadel repository advisory GHSA-9993-rfwp-rhwf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zitadel/zitadel/security/advisories/GHSA-9993-rfwp-rhwf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85057",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-17"
   },
   "refs": "ghsa-repos:zitadel/zitadel\tGHSA-fgmf-7rf8-m6vf",
   "description": "zitadel/zitadel repository advisory GHSA-fgmf-7rf8-m6vf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zitadel/zitadel/security/advisories/GHSA-fgmf-7rf8-m6vf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-13412",
   "state": "RESERVED",
   "public_date": "2026-07-17",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-17"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11293-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11293-1.json",
   "description": "CVE-2026-13412",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 60,
   "clock_known": true,
   "hours_public": 1440,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-17",
   "advisory_days_public": 60,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11293-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57229",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21",
    "csaf": "2026-07-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11308-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json;debian:suricata;ghsa-repos:OISF/suricata\tGHSA-ph5p-pm8r-m355;ubuntu-osv:UBUNTU-CVE-2026-57229;ubuntu:CVE-2026-57229",
   "description": "[smtp: evasion due to incomplete state reset]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57229",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-ph5p-pm8r-m355",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57229",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57229"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57228",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21",
    "csaf": "2026-07-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11308-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json;debian:suricata;ghsa-repos:OISF/suricata\tGHSA-qxm4-q7vx-7xj4;ubuntu-osv:UBUNTU-CVE-2026-57228;ubuntu:CVE-2026-57228",
   "description": "[mime: buffer over read in quoted printable decoding]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57228",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-qxm4-q7vx-7xj4",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57228",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57228"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57227",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21",
    "csaf": "2026-07-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11308-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json;debian:suricata;ghsa-repos:OISF/suricata\tGHSA-7h2h-hpj2-9w6p;ubuntu-osv:UBUNTU-CVE-2026-57227;ubuntu:CVE-2026-57227",
   "description": "[mqtt: unbounded number of messages per tx]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57227",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-7h2h-hpj2-9w6p",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57227",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57227"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57224",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21",
    "csaf": "2026-07-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11308-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json;debian:suricata;ghsa-repos:OISF/suricata\tGHSA-m2vc-g65c-ph7m;ubuntu-osv:UBUNTU-CVE-2026-57224;ubuntu:CVE-2026-57224",
   "description": "[dhcp: unbounded tx growth with unidirectional traffic]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57224",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-m2vc-g65c-ph7m",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57224",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57224"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57222",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21",
    "csaf": "2026-07-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11308-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json;debian:suricata;ghsa-repos:OISF/suricata\tGHSA-2r8x-23fw-hgcg;ubuntu-osv:UBUNTU-CVE-2026-57222;ubuntu:CVE-2026-57222",
   "description": "[ippair: IPv4/IPv6 hash collision can reuse wrong IPPair state]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11308-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57222",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-2r8x-23fw-hgcg",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57222",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57222"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85740",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:HKUDS/LightRAG\tGHSA-vv3m-f8x4-7377",
   "description": "HKUDS/LightRAG repository advisory GHSA-vv3m-f8x4-7377",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-vv3m-f8x4-7377"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85734",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:HKUDS/LightRAG\tGHSA-frch-4w6v-q5xx",
   "description": "HKUDS/LightRAG repository advisory GHSA-frch-4w6v-q5xx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-frch-4w6v-q5xx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85725",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:HKUDS/LightRAG\tGHSA-c759-cx9p-mrwq",
   "description": "HKUDS/LightRAG repository advisory GHSA-c759-cx9p-mrwq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-c759-cx9p-mrwq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85709",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:HKUDS/LightRAG\tGHSA-hrmj-7rvj-4hg8",
   "description": "HKUDS/LightRAG repository advisory GHSA-hrmj-7rvj-4hg8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-hrmj-7rvj-4hg8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85990",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Leantime/leantime\tGHSA-54mm-6729-r5wp",
   "description": "Leantime/leantime repository advisory GHSA-54mm-6729-r5wp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Leantime/leantime/security/advisories/GHSA-54mm-6729-r5wp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85751",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Mailu/Mailu\tGHSA-rfhj-4wcq-74xg",
   "description": "Mailu/Mailu repository advisory GHSA-rfhj-4wcq-74xg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Mailu/Mailu/security/advisories/GHSA-rfhj-4wcq-74xg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42322",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Piwigo/Piwigo\tGHSA-7w97-5g4p-xqvv",
   "description": "Piwigo/Piwigo repository advisory GHSA-7w97-5g4p-xqvv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-7w97-5g4p-xqvv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44642",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Piwigo/Piwigo\tGHSA-6wj3-7fhw-gfpm",
   "description": "Piwigo/Piwigo repository advisory GHSA-6wj3-7fhw-gfpm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-6wj3-7fhw-gfpm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42324",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Piwigo/Piwigo\tGHSA-jhp4-7f82-8f6q",
   "description": "Piwigo/Piwigo repository advisory GHSA-jhp4-7f82-8f6q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-jhp4-7f82-8f6q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85750",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Piwigo/Piwigo\tGHSA-j9q6-q52g-g8jw",
   "description": "Piwigo/Piwigo repository advisory GHSA-j9q6-q52g-g8jw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-j9q6-q52g-g8jw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62262",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Piwigo/Piwigo\tGHSA-hq29-8hhx-5jwc",
   "description": "Piwigo/Piwigo repository advisory GHSA-hq29-8hhx-5jwc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-hq29-8hhx-5jwc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42323",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:Piwigo/Piwigo\tGHSA-7r67-9xhq-7p2c",
   "description": "Piwigo/Piwigo repository advisory GHSA-7r67-9xhq-7p2c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-7r67-9xhq-7p2c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67532",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:agentfront/frontmcp\tGHSA-hvvp-67p3-j379",
   "description": "agentfront/frontmcp repository advisory GHSA-hvvp-67p3-j379",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/agentfront/frontmcp/security/advisories/GHSA-hvvp-67p3-j379"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85738",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:liketrek/TREK\tGHSA-9hpq-mrpx-mcxg",
   "description": "liketrek/TREK repository advisory GHSA-9hpq-mrpx-mcxg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/liketrek/TREK/security/advisories/GHSA-9hpq-mrpx-mcxg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85727",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:maximmasiutin/TinyWeb\tGHSA-56x3-254q-j68q",
   "description": "maximmasiutin/TinyWeb repository advisory GHSA-56x3-254q-j68q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/maximmasiutin/TinyWeb/security/advisories/GHSA-56x3-254q-j68q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85728",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:maximmasiutin/TinyWeb\tGHSA-wxxh-8845-3c89",
   "description": "maximmasiutin/TinyWeb repository advisory GHSA-wxxh-8845-3c89",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/maximmasiutin/TinyWeb/security/advisories/GHSA-wxxh-8845-3c89"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85729",
   "state": "RESERVED",
   "public_date": "2026-07-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-18"
   },
   "refs": "ghsa-repos:maximmasiutin/TinyWeb\tGHSA-rprm-fpv2-mwwf",
   "description": "maximmasiutin/TinyWeb repository advisory GHSA-rprm-fpv2-mwwf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 59,
   "clock_known": true,
   "hours_public": 1416,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-18",
   "advisory_days_public": 59,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/maximmasiutin/TinyWeb/security/advisories/GHSA-rprm-fpv2-mwwf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86020",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-hxw4-frfg-f8jw",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-hxw4-frfg-f8jw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-hxw4-frfg-f8jw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86019",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-8fvw-xrgv-jq4w",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-8fvw-xrgv-jq4w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-8fvw-xrgv-jq4w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86018",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-2whx-2cx7-qvq6",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-2whx-2cx7-qvq6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-2whx-2cx7-qvq6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59188",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:Part-DB/Part-DB-server\tGHSA-2vhp-c958-m47j",
   "description": "Part-DB/Part-DB-server repository advisory GHSA-2vhp-c958-m47j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Part-DB/Part-DB-server/security/advisories/GHSA-2vhp-c958-m47j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57458",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:go-vikunja/vikunja\tGHSA-v3p6-34mc-hj7v",
   "description": "go-vikunja/vikunja repository advisory GHSA-v3p6-34mc-hj7v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-v3p6-34mc-hj7v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62376",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:go-vikunja/vikunja\tGHSA-r6w9-259g-gwrv",
   "description": "go-vikunja/vikunja repository advisory GHSA-r6w9-259g-gwrv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-r6w9-259g-gwrv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62367",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:go-vikunja/vikunja\tGHSA-xv7q-fvmc-jx96",
   "description": "go-vikunja/vikunja repository advisory GHSA-xv7q-fvmc-jx96",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xv7q-fvmc-jx96"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86016",
   "state": "RESERVED",
   "public_date": "2026-07-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-19"
   },
   "refs": "ghsa-repos:vnotex/vnote\tGHSA-vfhj-c636-h59x",
   "description": "vnotex/vnote repository advisory GHSA-vfhj-c636-h59x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 58,
   "clock_known": true,
   "hours_public": 1392,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-19",
   "advisory_days_public": 58,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/vnotex/vnote/security/advisories/GHSA-vfhj-c636-h59x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61548",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-24",
    "ubuntu-osv": "2026-07-20",
    "ghsa-repos": "2026-07-20",
    "csaf": "2026-07-29"
   },
   "refs": "alas:CVE-2026-61548;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11407-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11407-1.json;debian:rsyslog;ghsa-repos:rsyslog/rsyslog\tGHSA-8qmr-c66f-g368;ubuntu-osv:UBUNTU-CVE-2026-61548",
   "description": "rsyslog mmpstrucdata stack overflow The issue occurs while mmpstrucdata parses RFC 5424 structured-data parameter values.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "rsyslog",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61548.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11407-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61548",
    "ghsa-repos": "https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8qmr-c66f-g368",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61548"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63646",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-46p5-m7pq-82hm",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-46p5-m7pq-82hm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-46p5-m7pq-82hm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63647",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-9qg8-cm35-xqp4",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-9qg8-cm35-xqp4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-9qg8-cm35-xqp4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68543",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:FOSSBilling/FOSSBilling\tGHSA-fx78-6vx2-v4mr",
   "description": "FOSSBilling/FOSSBilling repository advisory GHSA-fx78-6vx2-v4mr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-fx78-6vx2-v4mr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68542",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:FOSSBilling/FOSSBilling\tGHSA-6w49-4398-7rw5",
   "description": "FOSSBilling/FOSSBilling repository advisory GHSA-6w49-4398-7rw5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-6w49-4398-7rw5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86062",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:HKUDS/LightRAG\tGHSA-xpjq-3w4w-w5wr",
   "description": "HKUDS/LightRAG repository advisory GHSA-xpjq-3w4w-w5wr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-xpjq-3w4w-w5wr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77476",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:dromara/MaxKey\tGHSA-rc95-ghv3-whw8",
   "description": "dromara/MaxKey repository advisory GHSA-rc95-ghv3-whw8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dromara/MaxKey/security/advisories/GHSA-rc95-ghv3-whw8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-82407",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:klever-io/klever-go\tGHSA-9wh6-9hq7-9688",
   "description": "klever-io/klever-go repository advisory GHSA-9wh6-9hq7-9688",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/klever-io/klever-go/security/advisories/GHSA-9wh6-9hq7-9688"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-82409",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:klever-io/klever-go\tGHSA-7c7c-373r-gfjj",
   "description": "klever-io/klever-go repository advisory GHSA-7c7c-373r-gfjj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/klever-io/klever-go/security/advisories/GHSA-7c7c-373r-gfjj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-82405",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:klever-io/klever-go\tGHSA-97cv-x867-6xhm",
   "description": "klever-io/klever-go repository advisory GHSA-97cv-x867-6xhm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/klever-io/klever-go/security/advisories/GHSA-97cv-x867-6xhm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-82406",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:klever-io/klever-go\tGHSA-26r5-4mm2-px5c",
   "description": "klever-io/klever-go repository advisory GHSA-26r5-4mm2-px5c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/klever-io/klever-go/security/advisories/GHSA-26r5-4mm2-px5c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86065",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:klever-io/klever-go\tGHSA-4fwh-wrm6-97xm",
   "description": "klever-io/klever-go repository advisory GHSA-4fwh-wrm6-97xm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/klever-io/klever-go/security/advisories/GHSA-4fwh-wrm6-97xm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86064",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:klever-io/klever-go\tGHSA-9v8p-frvj-2pcm",
   "description": "klever-io/klever-go repository advisory GHSA-9v8p-frvj-2pcm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/klever-io/klever-go/security/advisories/GHSA-9v8p-frvj-2pcm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86022",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:vnotex/vnote\tGHSA-6m2r-wm6v-c8qp",
   "description": "vnotex/vnote repository advisory GHSA-6m2r-wm6v-c8qp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/vnotex/vnote/security/advisories/GHSA-6m2r-wm6v-c8qp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76825",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-20"
   },
   "refs": "ghsa-repos:zopefoundation/RestrictedPython\tGHSA-hp3v-5vw7-fx9w",
   "description": "zopefoundation/RestrictedPython repository advisory GHSA-hp3v-5vw7-fx9w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-hp3v-5vw7-fx9w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-10631",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2429\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2429.json",
   "description": "CVE-2026-10631",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2429.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50054",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2429\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2429.json",
   "description": "CVE-2026-50054",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2429.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50055",
   "state": "RESERVED",
   "public_date": "2026-07-20",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-20"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2429\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2429.json",
   "description": "CVE-2026-50055",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 57,
   "clock_known": true,
   "hours_public": 1368,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-20",
   "advisory_days_public": 57,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2429.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63676",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "alas,alpine,csaf,debian,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-08-26",
    "ubuntu": "2026-08-27",
    "ubuntu-osv": "2026-08-27",
    "csaf": "2026-07-21"
   },
   "refs": "alas:CVE-2026-63676;alpine:perl-yaml;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11321-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11321-1.json;debian:libyaml-perl;ubuntu-osv:UBUNTU-CVE-2026-63676;ubuntu:CVE-2026-63676",
   "description": "Backtracking leads to exponential load time in libyaml library.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "perl-yaml",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63676.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-63676",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11321-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63676",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63676",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63676"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57226",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21"
   },
   "refs": "debian:suricata;ghsa-repos:OISF/suricata\tGHSA-p33j-r48q-3jcf;ubuntu-osv:UBUNTU-CVE-2026-57226;ubuntu:CVE-2026-57226",
   "description": "[detect/file_data: heap buffer overflow in SWF decompression depth handling]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57226",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-p33j-r48q-3jcf",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57226",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57226"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57225",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21"
   },
   "refs": "debian:suricata;ghsa-repos:OISF/suricata\tGHSA-vqqx-88xw-qqvc;ubuntu-osv:UBUNTU-CVE-2026-57225;ubuntu:CVE-2026-57225",
   "description": "[datasets: NULL dereference on unexpected ndjson files]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57225",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-vqqx-88xw-qqvc",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57225",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57225"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57223",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-09-14",
    "ubuntu-osv": "2026-09-14",
    "ghsa-repos": "2026-07-21"
   },
   "refs": "debian:suricata;ghsa-repos:OISF/suricata\tGHSA-jh8w-wf3f-58jp;ubuntu-osv:UBUNTU-CVE-2026-57223;ubuntu:CVE-2026-57223",
   "description": "[windows: unquoted LocalSystem service ImagePath]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-57223",
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-jh8w-wf3f-58jp",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-57223",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-57223"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63347",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-18",
    "ubuntu-osv": "2026-08-18",
    "ghsa-repos": "2026-07-21"
   },
   "refs": "debian:suricata-update;ghsa-repos:OISF/suricata-update\tGHSA-6v4p-4w5x-9fp2;ubuntu-osv:UBUNTU-CVE-2026-63347;ubuntu:CVE-2026-63347",
   "description": "suricata-update",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "suricata-update",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63347",
    "ghsa-repos": "https://github.com/OISF/suricata-update/security/advisories/GHSA-6v4p-4w5x-9fp2",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63347",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63347"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73143",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-21",
    "csaf": "2026-07-21"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73143\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73143.json;debian:svxlink;redhat:CVE-2026-73143;ubuntu-osv:UBUNTU-CVE-2026-73143;ubuntu:CVE-2026-73143",
   "description": "[GHSA-38fq-mrrg-8rmr: RtlTcp: malformed greeting causes daemon exit]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73143.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73143",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73143",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73143",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73143"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73142",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-21",
    "csaf": "2026-07-21"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73142\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73142.json;debian:svxlink;redhat:CVE-2026-73142;ubuntu-osv:UBUNTU-CVE-2026-73142;ubuntu:CVE-2026-73142",
   "description": "[GHSA-5xr9-fmm8-7p8x: remotetrx NetUplink: connection object leak DoS]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73142.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73142",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73142",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73142",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73142"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86059",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:Dokploy/dokploy\tGHSA-wx75-vxph-2m2f",
   "description": "Dokploy/dokploy repository advisory GHSA-wx75-vxph-2m2f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Dokploy/dokploy/security/advisories/GHSA-wx75-vxph-2m2f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63446",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-gjwr-75gq-877m",
   "description": "OISF/suricata repository advisory GHSA-gjwr-75gq-877m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-gjwr-75gq-877m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63451",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-6qwq-j83r-qp34",
   "description": "OISF/suricata repository advisory GHSA-6qwq-j83r-qp34",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-6qwq-j83r-qp34"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63447",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-w394-3g33-3jg9",
   "description": "OISF/suricata repository advisory GHSA-w394-3g33-3jg9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-w394-3g33-3jg9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63449",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-prqx-q74v-wxhv",
   "description": "OISF/suricata repository advisory GHSA-prqx-q74v-wxhv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-prqx-q74v-wxhv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63448",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-hvvj-c8xx-9g35",
   "description": "OISF/suricata repository advisory GHSA-hvvj-c8xx-9g35",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-hvvj-c8xx-9g35"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63452",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-j9cx-w9xm-5x84",
   "description": "OISF/suricata repository advisory GHSA-j9cx-w9xm-5x84",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-j9cx-w9xm-5x84"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63450",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-56wx-7hqh-wfgr",
   "description": "OISF/suricata repository advisory GHSA-56wx-7hqh-wfgr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-56wx-7hqh-wfgr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81179",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:Syslifters/sysreptor\tGHSA-9x2r-5pff-8w6c",
   "description": "Syslifters/sysreptor repository advisory GHSA-9x2r-5pff-8w6c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Syslifters/sysreptor/security/advisories/GHSA-9x2r-5pff-8w6c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63327",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:e107inc/e107\tGHSA-wcc5-8jrf-6q26",
   "description": "e107inc/e107 repository advisory GHSA-wcc5-8jrf-6q26",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/e107inc/e107/security/advisories/GHSA-wcc5-8jrf-6q26"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53627",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-p68f-rv24-mc54",
   "description": "glpi-project/glpi repository advisory GHSA-p68f-rv24-mc54",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-p68f-rv24-mc54"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45801",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-3vhr-7p54-cqhw",
   "description": "glpi-project/glpi repository advisory GHSA-3vhr-7p54-cqhw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-3vhr-7p54-cqhw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53628",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-2hf7-pw75-7wcp",
   "description": "glpi-project/glpi repository advisory GHSA-2hf7-pw75-7wcp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-2hf7-pw75-7wcp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55217",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-xm3v-3g6q-g9q8",
   "description": "glpi-project/glpi repository advisory GHSA-xm3v-3g6q-g9q8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49469",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-3cgm-rj32-hfwf",
   "description": "glpi-project/glpi repository advisory GHSA-3cgm-rj32-hfwf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-3cgm-rj32-hfwf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86072",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:kata-containers/kata-containers\tGHSA-7fhf-v3p3-rp56",
   "description": "kata-containers/kata-containers repository advisory GHSA-7fhf-v3p3-rp56",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kata-containers/kata-containers/security/advisories/GHSA-7fhf-v3p3-rp56"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49243",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-21"
   },
   "refs": "ghsa-repos:webmin/webmin\tGHSA-hv4w-p8jq-2rp5",
   "description": "webmin/webmin repository advisory GHSA-hv4w-p8jq-2rp5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/webmin/webmin/security/advisories/GHSA-hv4w-p8jq-2rp5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28311",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-21"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2467\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2467.json",
   "description": "CVE-2026-28311",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2467.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62686",
   "state": "RESERVED",
   "public_date": "2026-07-21",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-21"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2471\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2471.json",
   "description": "CVE-2026-62686",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 56,
   "clock_known": true,
   "hours_public": 1344,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-21",
   "advisory_days_public": 56,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2471.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16566",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "alas,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-07-27",
    "ubuntu-osv": "2026-07-27",
    "redhat": "2026-07-22",
    "csaf": "2026-07-22"
   },
   "refs": "alas:CVE-2026-16566;csaf:Red Hat Product Security\tCVE-2026-16566\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16566.json;debian:ansible;redhat:CVE-2026-16566;ubuntu-osv:UBUNTU-CVE-2026-16566",
   "description": "A flaw was found in the community.general Ansible collection's jenkins_credential module.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ansible",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-16566.html",
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16566.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-16566",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-16566",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-16566"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73144",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "redhat": "2026-07-22",
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-73144\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73144.json;debian:svxlink;redhat:CVE-2026-73144;ubuntu-osv:UBUNTU-CVE-2026-73144;ubuntu:CVE-2026-73144",
   "description": "[GHSA-qccg-7pw6-787v: FRN module: unbounded memory growth]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "svxlink",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73144.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73144",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73144",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73144",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73144"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55869",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-22",
    "csaf": "2026-07-23"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11357-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11357-1.json;debian:srt;ubuntu-osv:UBUNTU-CVE-2026-55869",
   "description": "[Heap-Based Buffer Overflow in KMREQ Handling]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "srt",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11357-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-55869",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-55869"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55868",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu-osv": "2026-07-22",
    "csaf": "2026-07-23"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11357-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11357-1.json;debian:srt;ubuntu-osv:UBUNTU-CVE-2026-55868",
   "description": "[Encryption State Machine Downgrade]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "srt",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11357-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-55868",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-55868"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67441",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:frangoteam/FUXA\tGHSA-8gwj-g6fx-96jr",
   "description": "frangoteam/FUXA repository advisory GHSA-8gwj-g6fx-96jr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frangoteam/FUXA/security/advisories/GHSA-8gwj-g6fx-96jr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77437",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:kiwitcms/Kiwi\tGHSA-554x-3chh-x3h9",
   "description": "kiwitcms/Kiwi repository advisory GHSA-554x-3chh-x3h9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-554x-3chh-x3h9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77435",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:kiwitcms/Kiwi\tGHSA-3qxv-9j3q-c68v",
   "description": "kiwitcms/Kiwi repository advisory GHSA-3qxv-9j3q-c68v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-3qxv-9j3q-c68v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77434",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:kiwitcms/Kiwi\tGHSA-cjrx-h8r2-jgc7",
   "description": "kiwitcms/Kiwi repository advisory GHSA-cjrx-h8r2-jgc7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-cjrx-h8r2-jgc7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77433",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:kiwitcms/Kiwi\tGHSA-gcwf-c25f-p9rv",
   "description": "kiwitcms/Kiwi repository advisory GHSA-gcwf-c25f-p9rv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-gcwf-c25f-p9rv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77412",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-4v58-74mf-rjx3",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-4v58-74mf-rjx3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77410",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-r9c8-gcjp-xfwh",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-r9c8-gcjp-xfwh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77411",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-c5pq-fr2g-9jpf",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-c5pq-fr2g-9jpf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-c5pq-fr2g-9jpf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77409",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-wxx3-cj7g-w73j",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-wxx3-cj7g-w73j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-wxx3-cj7g-w73j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77408",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-j497-x9hr-x34x",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-j497-x9hr-x34x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77407",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-27gv-rfvv-22mv",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-27gv-rfvv-22mv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-27gv-rfvv-22mv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77406",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-rm6m-hrcw-jw33",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-rm6m-hrcw-jw33",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-rm6m-hrcw-jw33"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77404",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-465g-fh3v-9jw4",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-465g-fh3v-9jw4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-465g-fh3v-9jw4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77405",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-33mj-cw25-m34h",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-33mj-cw25-m34h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-33mj-cw25-m34h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77403",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/amqp091-go\tGHSA-xwwf-m8fg-p9q2",
   "description": "rabbitmq/amqp091-go repository advisory GHSA-xwwf-m8fg-p9q2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62360",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/cluster-operator\tGHSA-hvjc-whr9-649f",
   "description": "rabbitmq/cluster-operator repository advisory GHSA-hvjc-whr9-649f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/cluster-operator/security/advisories/GHSA-hvjc-whr9-649f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67239",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-xm9p-57xv-vxwc",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-xm9p-57xv-vxwc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-xm9p-57xv-vxwc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67242",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-rrj4-g94f-rqj9",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-rrj4-g94f-rqj9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-rrj4-g94f-rqj9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67223",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-9x7r-g78c-5835",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-9x7r-g78c-5835",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-9x7r-g78c-5835"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67241",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-rg2g-289m-xhhw",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-rg2g-289m-xhhw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-rg2g-289m-xhhw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86036",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-22"
   },
   "refs": "ghsa-repos:weechat/weechat\tGHSA-68ff-gq39-pqjm",
   "description": "weechat/weechat repository advisory GHSA-68ff-gq39-pqjm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/weechat/weechat/security/advisories/GHSA-68ff-gq39-pqjm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61781",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61781",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61817",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61817",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61818",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61818",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61819",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61819",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61820",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61820",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61821",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61821",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61822",
   "state": "RESERVED",
   "public_date": "2026-07-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-22"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2493\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json",
   "description": "CVE-2026-61822",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 55,
   "clock_known": true,
   "hours_public": 1320,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-22",
   "advisory_days_public": 55,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2493.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67533",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:agentfront/frontmcp\tGHSA-8q49-2h5h-434x",
   "description": "agentfront/frontmcp repository advisory GHSA-8q49-2h5h-434x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/agentfront/frontmcp/security/advisories/GHSA-8q49-2h5h-434x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64856",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-p4c7-8jm2-m88q",
   "description": "error311/FileRise repository advisory GHSA-p4c7-8jm2-m88q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-p4c7-8jm2-m88q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67416",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-p35w-6mx2-q4pc",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-p35w-6mx2-q4pc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-p35w-6mx2-q4pc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67414",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-w6mq-4qpx-v7mh",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-w6mq-4qpx-v7mh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-w6mq-4qpx-v7mh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67415",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-8mpg-qw9r-m5cr",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-8mpg-qw9r-m5cr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-8mpg-qw9r-m5cr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67408",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-2hm4-4438-49q8",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-2hm4-4438-49q8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-2hm4-4438-49q8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67409",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-qw3h-qqm9-jrw8",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-qw3h-qqm9-jrw8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-qw3h-qqm9-jrw8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61837",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-w9hf-476r-443x",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-w9hf-476r-443x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-w9hf-476r-443x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67226",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-34c7-r8w9-5wv8",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-34c7-r8w9-5wv8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-34c7-r8w9-5wv8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67227",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-q7x8-97rh-cr24",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-q7x8-97rh-cr24",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q7x8-97rh-cr24"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67413",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-chxf-3hfg-j8f7",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-chxf-3hfg-j8f7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-chxf-3hfg-j8f7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67412",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-42pc-678q-v8qj",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-42pc-678q-v8qj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-42pc-678q-v8qj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67410",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-f9f2-q3jf-wfj3",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-f9f2-q3jf-wfj3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f9f2-q3jf-wfj3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67406",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-q44f-9vc5-grh7",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-q44f-9vc5-grh7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q44f-9vc5-grh7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67407",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-q46v-hrvq-hp24",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-q46v-hrvq-hp24",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q46v-hrvq-hp24"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67411",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-4r6f-9cpw-f6g6",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-4r6f-9cpw-f6g6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-4r6f-9cpw-f6g6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62949",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-23"
   },
   "refs": "ghsa-repos:ronf/asyncssh\tGHSA-rw4j-r22c-9gc3",
   "description": "ronf/asyncssh repository advisory GHSA-rw4j-r22c-9gc3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ronf/asyncssh/security/advisories/GHSA-rw4j-r22c-9gc3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19496",
   "state": "RESERVED",
   "public_date": "2026-07-23",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-07-23",
    "csaf": "2026-07-23"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-19496\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19496.json;redhat:CVE-2026-19496",
   "description": "sources-api-go: SQL injection via sort_by value and raw query-param keys in list filtering",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 54,
   "clock_known": true,
   "hours_public": 1296,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-23",
   "advisory_days_public": 54,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-19496",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19496.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-19496"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48730",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:glpi-project/glpi-inventory-plugin\tGHSA-97vv-hxvv-9rw8",
   "description": "glpi-project/glpi-inventory-plugin repository advisory GHSA-97vv-hxvv-9rw8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-inventory-plugin/security/advisories/GHSA-97vv-hxvv-9rw8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86044",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:jupyterlab/jupyterlab-desktop\tGHSA-2mr8-962v-wc67",
   "description": "jupyterlab/jupyterlab-desktop repository advisory GHSA-2mr8-962v-wc67",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jupyterlab/jupyterlab-desktop/security/advisories/GHSA-2mr8-962v-wc67"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-54991",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:jupyterlab/jupyterlab-desktop\tGHSA-8cvf-4977-r95v",
   "description": "jupyterlab/jupyterlab-desktop repository advisory GHSA-8cvf-4977-r95v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jupyterlab/jupyterlab-desktop/security/advisories/GHSA-8cvf-4977-r95v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-55002",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:jupyterlab/jupyterlab-desktop\tGHSA-5c3f-5gj7-p9xh",
   "description": "jupyterlab/jupyterlab-desktop repository advisory GHSA-5c3f-5gj7-p9xh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jupyterlab/jupyterlab-desktop/security/advisories/GHSA-5c3f-5gj7-p9xh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50531",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/escalade\tGHSA-wmvj-p56r-vqfv",
   "description": "pluginsGLPI/escalade repository advisory GHSA-wmvj-p56r-vqfv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/escalade/security/advisories/GHSA-wmvj-p56r-vqfv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50537",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/fields\tGHSA-p3pf-5cr4-wrmr",
   "description": "pluginsGLPI/fields repository advisory GHSA-p3pf-5cr4-wrmr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/fields/security/advisories/GHSA-p3pf-5cr4-wrmr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46422",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/formcreator\tGHSA-vcvr-2r7j-p76h",
   "description": "pluginsGLPI/formcreator repository advisory GHSA-vcvr-2r7j-p76h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/formcreator/security/advisories/GHSA-vcvr-2r7j-p76h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52728",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/genericobject\tGHSA-6r3j-74pf-v7q5",
   "description": "pluginsGLPI/genericobject repository advisory GHSA-6r3j-74pf-v7q5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/genericobject/security/advisories/GHSA-6r3j-74pf-v7q5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50534",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/order\tGHSA-8xvx-g5rv-7mhj",
   "description": "pluginsGLPI/order repository advisory GHSA-8xvx-g5rv-7mhj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/order/security/advisories/GHSA-8xvx-g5rv-7mhj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50535",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/order\tGHSA-3w5w-pp6p-wwjh",
   "description": "pluginsGLPI/order repository advisory GHSA-3w5w-pp6p-wwjh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/order/security/advisories/GHSA-3w5w-pp6p-wwjh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50536",
   "state": "RESERVED",
   "public_date": "2026-07-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-24"
   },
   "refs": "ghsa-repos:pluginsGLPI/order\tGHSA-5wfj-g8vf-8xhq",
   "description": "pluginsGLPI/order repository advisory GHSA-5wfj-g8vf-8xhq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 53,
   "clock_known": true,
   "hours_public": 1272,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-24",
   "advisory_days_public": 53,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/pluginsGLPI/order/security/advisories/GHSA-5wfj-g8vf-8xhq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63120",
   "state": "RESERVED",
   "public_date": "2026-07-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-25"
   },
   "refs": "ghsa-repos:Aiven-Open/pghoard\tGHSA-rh99-q79h-vvx3",
   "description": "Aiven-Open/pghoard repository advisory GHSA-rh99-q79h-vvx3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 52,
   "clock_known": true,
   "hours_public": 1248,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-25",
   "advisory_days_public": 52,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-rh99-q79h-vvx3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-9672",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "alas,alpine,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-07-31",
    "ubuntu-osv": "2026-07-31",
    "redhat": "2026-07-26",
    "csaf": "2026-07-31"
   },
   "refs": "alas:CVE-2026-9672;alpine:php83;csaf:SUSE Product Security Team\tCVE-2026-9672\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-9672.json;debian:libgd2;redhat:CVE-2026-9672;ubuntu-osv:UBUNTU-CVE-2026-9672",
   "description": "php83",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "php83",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-9672.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-9672",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-9672.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-9672",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-9672",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-9672"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-30971",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:ZoneMinder/zoneminder\tGHSA-g66m-77fq-79v9",
   "description": "ZoneMinder/zoneminder repository advisory GHSA-g66m-77fq-79v9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-g66m-77fq-79v9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2024-43361",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:ZoneMinder/zoneminder\tGHSA-wgqf-6fjf-7gxw",
   "description": "ZoneMinder/zoneminder repository advisory GHSA-wgqf-6fjf-7gxw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-wgqf-6fjf-7gxw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28273",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:ZoneMinder/zoneminder\tGHSA-mvj8-mqqq-2w5f",
   "description": "ZoneMinder/zoneminder repository advisory GHSA-mvj8-mqqq-2w5f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mvj8-mqqq-2w5f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67534",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:agentfront/frontmcp\tGHSA-h8wf-g76c-wjwg",
   "description": "agentfront/frontmcp repository advisory GHSA-h8wf-g76c-wjwg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/agentfront/frontmcp/security/advisories/GHSA-h8wf-g76c-wjwg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68919",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-pp5x-wgv2-g37p",
   "description": "gocd/gocd repository advisory GHSA-pp5x-wgv2-g37p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-pp5x-wgv2-g37p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55870",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-5m25-5j77-c887",
   "description": "gocd/gocd repository advisory GHSA-5m25-5j77-c887",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-5m25-5j77-c887"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55632",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-57pf-j652-c3c9",
   "description": "gocd/gocd repository advisory GHSA-57pf-j652-c3c9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-57pf-j652-c3c9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55625",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-4557-94j8-5p66",
   "description": "gocd/gocd repository advisory GHSA-4557-94j8-5p66",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-4557-94j8-5p66"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55060",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-vqjf-7pf8-hgwr",
   "description": "gocd/gocd repository advisory GHSA-vqjf-7pf8-hgwr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-vqjf-7pf8-hgwr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52743",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-2x6r-h7h3-wqc4",
   "description": "gocd/gocd repository advisory GHSA-2x6r-h7h3-wqc4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-2x6r-h7h3-wqc4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52744",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-mvpm-hmc9-2q8p",
   "description": "gocd/gocd repository advisory GHSA-mvpm-hmc9-2q8p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52742",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-7xxx-fv46-vp7h",
   "description": "gocd/gocd repository advisory GHSA-7xxx-fv46-vp7h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-7xxx-fv46-vp7h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52740",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-9jfm-4f6v-79wh",
   "description": "gocd/gocd repository advisory GHSA-9jfm-4f6v-79wh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-9jfm-4f6v-79wh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52741",
   "state": "RESERVED",
   "public_date": "2026-07-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-26"
   },
   "refs": "ghsa-repos:gocd/gocd\tGHSA-hj3c-q23m-fxcg",
   "description": "gocd/gocd repository advisory GHSA-hj3c-q23m-fxcg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 51,
   "clock_known": true,
   "hours_public": 1224,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-26",
   "advisory_days_public": 51,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gocd/gocd/security/advisories/GHSA-hj3c-q23m-fxcg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16043",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-16043;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-16043",
   "description": "In QEMU's sysbus-xhci (USB 3.0 host controller) emulation (hw/usb/hcd-xhci.c, hw/usb/hcd-xhci-sysbus.c), an out-of-bounds heap access vulnerability exists in the xhci_sysbus_intr_ raise() function.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-16043.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-16043",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-16043"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-8348",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-8348;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-8348",
   "description": "In QEMU's 9pfs (virtio-9p) implementation, the TXATTRCREATE and TXATTRWALK request handlers do not limit the number of simultaneously open xattr FIDs. Each xattr FID allocates a host memory buffer for the extended attribute value.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-8348.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-8348",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-8348"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63319",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-63319;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63319",
   "description": "In QEMU's USB redirection (usbredir) implementation (hw/usb/redirect.c), a malicious usbredir peer can send an ep_info message that resets max_packet_size to 0 after bulk receiving has already started.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63319.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63319",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63319"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61475",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-61475;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-61475",
   "description": "In QEMU's VNC server implementation (ui/vnc.c), the vnc_refresh_lossy_rect() function contains an out-of-bounds write vulnerability when marking dirty bitmap rows during lossy tile refresh.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61475.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61475",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61475"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-15578",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-15578;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-15578",
   "description": "In QEMU's VNC server implementation (ui/vnc.c), the set_pixel_format() function does not properly validate the red_max, green_max, and blue_max fields from a client's SetPixelFormat message.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-15578.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-15578",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-15578"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-15705",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-15705;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-15705",
   "description": "In QEMU's USB redirection (usbredir) implementation, a use-after-free vulnerability exists in the usbredir_buffered_bulk_packet() function in hw/usb/redirect.c. When processing a multi-fragment buffered bulk packet that is split into max-packet-size chunks, only the final fragment owns the shared parser memory allocation (via free_on_destroy).",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-15705.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-15705",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-15705"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-9238",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "alas,debian,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "alas": "2026-07-29",
    "ubuntu-osv": "2026-07-27"
   },
   "refs": "alas:CVE-2026-9238;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-9238",
   "description": "In QEMU's 9pfs (virtio-9p) implementation, the v9fs_readdir() function does not properly constrain the memory allocation size for Treaddir responses.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-9238.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-9238",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-9238"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2023-37465",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-27",
    "osv": "2026-07-27"
   },
   "refs": "ghsa:GHSA-4j38-rw27-97gx;osv:Maven:org.xwiki.contrib:discussions-server",
   "description": "org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.xwiki.contrib",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-4j38-rw27-97gx",
    "osv": "https://osv.dev/list?q=CVE-2023-37465"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65837",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:CESNET/netopeer2\tGHSA-rf23-r5v9-x2ch",
   "description": "CESNET/netopeer2 repository advisory GHSA-rf23-r5v9-x2ch",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CESNET/netopeer2/security/advisories/GHSA-rf23-r5v9-x2ch"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79758",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-372w-6f3h-vcm4",
   "description": "Termix-SSH/Termix repository advisory GHSA-372w-6f3h-vcm4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-372w-6f3h-vcm4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79759",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-w4cf-69fj-g96f",
   "description": "Termix-SSH/Termix repository advisory GHSA-w4cf-69fj-g96f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-w4cf-69fj-g96f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79766",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-pr55-25gf-5f9v",
   "description": "Termix-SSH/Termix repository advisory GHSA-pr55-25gf-5f9v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-pr55-25gf-5f9v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79765",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-vx7c-4gxw-vr2h",
   "description": "Termix-SSH/Termix repository advisory GHSA-vx7c-4gxw-vr2h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-vx7c-4gxw-vr2h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79764",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-mwr3-35ph-pjqg",
   "description": "Termix-SSH/Termix repository advisory GHSA-mwr3-35ph-pjqg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-mwr3-35ph-pjqg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79763",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-x9h9-f7jc-8jwj",
   "description": "Termix-SSH/Termix repository advisory GHSA-x9h9-f7jc-8jwj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-x9h9-f7jc-8jwj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79762",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-685g-ccvv-6p8m",
   "description": "Termix-SSH/Termix repository advisory GHSA-685g-ccvv-6p8m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-685g-ccvv-6p8m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79761",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-p2g3-2xq3-23gx",
   "description": "Termix-SSH/Termix repository advisory GHSA-p2g3-2xq3-23gx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-p2g3-2xq3-23gx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79760",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:Termix-SSH/Termix\tGHSA-6hx3-9mgq-h9fj",
   "description": "Termix-SSH/Termix repository advisory GHSA-6hx3-9mgq-h9fj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Termix-SSH/Termix/security/advisories/GHSA-6hx3-9mgq-h9fj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65960",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:cilium/tetragon\tGHSA-6qqg-3qf7-p3v5",
   "description": "cilium/tetragon repository advisory GHSA-6qqg-3qf7-p3v5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cilium/tetragon/security/advisories/GHSA-6qqg-3qf7-p3v5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77427",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-g6p5-9cpq-mp5h",
   "description": "error311/FileRise repository advisory GHSA-g6p5-9cpq-mp5h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-g6p5-9cpq-mp5h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69194",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-rmwm-wq9g-583g",
   "description": "error311/FileRise repository advisory GHSA-rmwm-wq9g-583g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-rmwm-wq9g-583g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69193",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-5m63-83jf-gwx8",
   "description": "error311/FileRise repository advisory GHSA-5m63-83jf-gwx8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-5m63-83jf-gwx8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69191",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:error311/FileRise\tGHSA-p9qc-2r93-jccq",
   "description": "error311/FileRise repository advisory GHSA-p9qc-2r93-jccq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/error311/FileRise/security/advisories/GHSA-p9qc-2r93-jccq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55214",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-8v8p-w8mq-wqcg",
   "description": "glpi-project/glpi repository advisory GHSA-8v8p-w8mq-wqcg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-8v8p-w8mq-wqcg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57152",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-7v5q-w6f3-2v8p",
   "description": "glpi-project/glpi repository advisory GHSA-7v5q-w6f3-2v8p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-7v5q-w6f3-2v8p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53610",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-76v9-ch69-g67r",
   "description": "glpi-project/glpi repository advisory GHSA-76v9-ch69-g67r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-76v9-ch69-g67r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53629",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-cpcj-x335-5cmh",
   "description": "glpi-project/glpi repository advisory GHSA-cpcj-x335-5cmh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52848",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-hgr8-qvp5-mhch",
   "description": "glpi-project/glpi repository advisory GHSA-hgr8-qvp5-mhch",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-hgr8-qvp5-mhch"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53625",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-94rp-v9f2-5rj7",
   "description": "glpi-project/glpi repository advisory GHSA-94rp-v9f2-5rj7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-94rp-v9f2-5rj7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47678",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-v774-5g3p-vxg2",
   "description": "glpi-project/glpi repository advisory GHSA-v774-5g3p-vxg2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-v774-5g3p-vxg2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47679",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-x5r8-r6vj-79cw",
   "description": "glpi-project/glpi repository advisory GHSA-x5r8-r6vj-79cw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-x5r8-r6vj-79cw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48482",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-6whc-g4h2-98rm",
   "description": "glpi-project/glpi repository advisory GHSA-6whc-g4h2-98rm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53626",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-q9rc-v6vm-q5mm",
   "description": "glpi-project/glpi repository advisory GHSA-q9rc-v6vm-q5mm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-q9rc-v6vm-q5mm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49470",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi\tGHSA-mcv8-4hfg-5x2x",
   "description": "glpi-project/glpi repository advisory GHSA-mcv8-4hfg-5x2x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi/security/advisories/GHSA-mcv8-4hfg-5x2x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58199",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-g2hf-g56v-chfv",
   "description": "glpi-project/glpi-agent repository advisory GHSA-g2hf-g56v-chfv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-g2hf-g56v-chfv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52768",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-g2f7-8mp5-qw65",
   "description": "glpi-project/glpi-agent repository advisory GHSA-g2f7-8mp5-qw65",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-g2f7-8mp5-qw65"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49285",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-3974-4pff-75wp",
   "description": "glpi-project/glpi-agent repository advisory GHSA-3974-4pff-75wp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-3974-4pff-75wp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52764",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-r9rr-vpw9-p66x",
   "description": "glpi-project/glpi-agent repository advisory GHSA-r9rr-vpw9-p66x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-r9rr-vpw9-p66x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52765",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-4px8-6x8g-722x",
   "description": "glpi-project/glpi-agent repository advisory GHSA-4px8-6x8g-722x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-4px8-6x8g-722x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46615",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-fcgf-g6c2-g838",
   "description": "glpi-project/glpi-agent repository advisory GHSA-fcgf-g6c2-g838",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-fcgf-g6c2-g838"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45621",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-xqcp-72qc-36p2",
   "description": "glpi-project/glpi-agent repository advisory GHSA-xqcp-72qc-36p2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-xqcp-72qc-36p2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42187",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-2w23-rj57-xq9c",
   "description": "glpi-project/glpi-agent repository advisory GHSA-2w23-rj57-xq9c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-2w23-rj57-xq9c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-40936",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-27"
   },
   "refs": "ghsa-repos:glpi-project/glpi-agent\tGHSA-5379-v7xc-36m8",
   "description": "glpi-project/glpi-agent repository advisory GHSA-5379-v7xc-36m8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-5379-v7xc-36m8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18025",
   "state": "RESERVED",
   "public_date": "2026-07-27",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-27"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2531\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2531.json",
   "description": "CVE-2026-18025",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 50,
   "clock_known": true,
   "hours_public": 1200,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-27",
   "advisory_days_public": 50,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2531.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58221",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "alas,alpine,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-07-31",
    "ubuntu-osv": "2026-07-28",
    "redhat": "2026-07-28",
    "csaf": "2026-07-28"
   },
   "refs": "alas:CVE-2026-58221;alpine:samba;csaf:SUSE Product Security Team\tSUSE-SU-2026:3362-1\thttps://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_3362-1.json;debian:samba;redhat:CVE-2026-58221;ubuntu-osv:UBUNTU-CVE-2026-58221",
   "description": "Samba AD authenticated LDAP access domain takeover",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "samba",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58221.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-58221",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_3362-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58221",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-58221",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58221"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-6949",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "alas,alpine,csaf,debian,redhat,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-07-31",
    "ubuntu-osv": "2026-07-28",
    "redhat": "2026-07-28",
    "csaf": "2026-07-28"
   },
   "refs": "alas:CVE-2026-6949;alpine:samba;csaf:SUSE Product Security Team\tCVE-2026-6949\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-6949.json;debian:samba;redhat:CVE-2026-6949;ubuntu-osv:UBUNTU-CVE-2026-6949",
   "description": "TSIG packet with name compression can crash DNS",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "samba",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-6949.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-6949",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-6949.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-6949",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-6949",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-6949"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16633",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa,ghsa-repos,osv",
   "feed_count": 3,
   "dates": {
    "ghsa": "2026-08-06",
    "ghsa-repos": "2026-07-28",
    "osv": "2026-08-06"
   },
   "refs": "ghsa-repos:mozilla/pdf.js\tGHSA-hq66-cqwq-w95j;ghsa:GHSA-hq66-cqwq-w95j;osv:npm:pdfjs-dist",
   "description": "PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "pdfjs-dist",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hq66-cqwq-w95j",
    "ghsa-repos": "https://github.com/mozilla/pdf.js/security/advisories/GHSA-hq66-cqwq-w95j",
    "osv": "https://osv.dev/list?q=CVE-2026-16633"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62962",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:FOSSBilling/FOSSBilling\tGHSA-7xgv-rh36-hrr5",
   "description": "FOSSBilling/FOSSBilling repository advisory GHSA-7xgv-rh36-hrr5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-7xgv-rh36-hrr5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68544",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:FOSSBilling/FOSSBilling\tGHSA-rrp7-fvc6-xxrw",
   "description": "FOSSBilling/FOSSBilling repository advisory GHSA-rrp7-fvc6-xxrw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-rrp7-fvc6-xxrw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68545",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:FOSSBilling/FOSSBilling\tGHSA-pfm5-728g-h32p",
   "description": "FOSSBilling/FOSSBilling repository advisory GHSA-pfm5-728g-h32p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-pfm5-728g-h32p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84302",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-3rx9-fqgh-wfpc",
   "description": "discourse/discourse repository advisory GHSA-3rx9-fqgh-wfpc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-3rx9-fqgh-wfpc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59830",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-x6mf-p7cg-69rw",
   "description": "discourse/discourse repository advisory GHSA-x6mf-p7cg-69rw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-x6mf-p7cg-69rw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63130",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-jr5q-25fw-27f8",
   "description": "espocrm/espocrm repository advisory GHSA-jr5q-25fw-27f8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-jr5q-25fw-27f8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58197",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-28"
   },
   "refs": "ghsa-repos:stacklok/toolhive\tGHSA-qg2g-g9w3-m5h8",
   "description": "stacklok/toolhive repository advisory GHSA-qg2g-g9w3-m5h8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5047",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2562\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2562.json",
   "description": "CVE-2026-5047",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2562.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5048",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2562\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2562.json",
   "description": "CVE-2026-5048",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2562.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-5049",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2562\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2562.json",
   "description": "CVE-2026-5049",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2562.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58341",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58341\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58341.json",
   "description": "moodle: CSRF risk in group messaging state toggle",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58341.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58343",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58343\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58343.json",
   "description": "moodle: Missing capability checks in AI placement web services",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58343.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58345",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58345\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58345.json",
   "description": "moodle: Missing capability check in Assignment marker allocation",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58345.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58346",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58346\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58346.json",
   "description": "moodle: Blind SSRF risk in MNet peers function",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58346.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58347",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58347\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58347.json",
   "description": "moodle: DoS risk via user profile description",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58347.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58348",
   "state": "RESERVED",
   "public_date": "2026-07-28",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-28"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-58348\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58348.json",
   "description": "moodle: Missing capability checks in report builder fragment callbacks",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 49,
   "clock_known": true,
   "hours_public": 1176,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-28",
   "advisory_days_public": 49,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58348.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59986",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-29"
   },
   "refs": "debian:librabbitmq;ubuntu-osv:UBUNTU-CVE-2026-59986",
   "description": "librabbitmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "librabbitmq",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-59986",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-59986"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61547",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-29"
   },
   "refs": "debian:librabbitmq;ubuntu-osv:UBUNTU-CVE-2026-61547",
   "description": "librabbitmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "librabbitmq",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61547",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61547"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42178",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-29"
   },
   "refs": "ghsa-repos:OpenAEV-Platform/openaev\tGHSA-596j-9hrm-3mhg",
   "description": "OpenAEV-Platform/openaev repository advisory GHSA-596j-9hrm-3mhg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenAEV-Platform/openaev/security/advisories/GHSA-596j-9hrm-3mhg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42179",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-29"
   },
   "refs": "ghsa-repos:OpenAEV-Platform/openaev\tGHSA-74m8-76qm-2hv4",
   "description": "OpenAEV-Platform/openaev repository advisory GHSA-74m8-76qm-2hv4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenAEV-Platform/openaev/security/advisories/GHSA-74m8-76qm-2hv4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42182",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-29"
   },
   "refs": "ghsa-repos:OpenAEV-Platform/openaev\tGHSA-8vq3-w884-xj4c",
   "description": "OpenAEV-Platform/openaev repository advisory GHSA-8vq3-w884-xj4c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenAEV-Platform/openaev/security/advisories/GHSA-8vq3-w884-xj4c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71386",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "jvn,zdi",
   "feed_count": 2,
   "dates": {
    "jvn": "2026-07-31",
    "zdi": "2026-07-29"
   },
   "refs": "jvn:JVNDB-2026-026086;zdi:ZDI-26-497",
   "description": "Security Update for Trend Micro Trend Vision One (July 2026)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "jvn": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-026086.html",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-497/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-71387",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "jvn,zdi",
   "feed_count": 2,
   "dates": {
    "jvn": "2026-07-31",
    "zdi": "2026-07-29"
   },
   "refs": "jvn:JVNDB-2026-026086;zdi:ZDI-26-498",
   "description": "Security Update for Trend Micro Trend Vision One (July 2026)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "jvn": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-026086.html",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-498/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62660",
   "state": "RESERVED",
   "public_date": "2026-07-29",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-07-29"
   },
   "refs": "zdi:ZDI-26-496",
   "description": "ZDI advisory ZDI-26-496",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 48,
   "clock_known": true,
   "hours_public": 1152,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-29",
   "advisory_days_public": 48,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-496/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81499",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-6v6x-387m-rj4w;ubuntu-osv:UBUNTU-CVE-2026-81499;ubuntu:CVE-2026-81499",
   "description": "[GHSA-6v6x-387m-rj4w: Project restriction bypass on network address sets]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81499",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-6v6x-387m-rj4w",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81499",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81499"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81498",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-m3j6-p3v3-qmjv;ubuntu-osv:UBUNTU-CVE-2026-81498;ubuntu:CVE-2026-81498",
   "description": "incus",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81498",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-m3j6-p3v3-qmjv",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81498",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81498"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81497",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-4qxq-p5hm-3q3p;ubuntu-osv:UBUNTU-CVE-2026-81497;ubuntu:CVE-2026-81497",
   "description": "incus",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81497",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-4qxq-p5hm-3q3p",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81497",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81497"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81496",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-26gp-p5fw-3r2h;ubuntu-osv:UBUNTU-CVE-2026-81496;ubuntu:CVE-2026-81496",
   "description": "incus",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81496",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-26gp-p5fw-3r2h",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81496",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81496"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81495",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-67qw-68v3-36h6;ubuntu-osv:UBUNTU-CVE-2026-81495;ubuntu:CVE-2026-81495",
   "description": "incus",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81495",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-67qw-68v3-36h6",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81495",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81495"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81494",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-7fj9-65v4-rp7h;ubuntu-osv:UBUNTU-CVE-2026-81494;ubuntu:CVE-2026-81494",
   "description": "[GHSA-7fj9-65v4-rp7h: Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81494",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-7fj9-65v4-rp7h",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81494",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81494"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81493",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-07-30"
   },
   "refs": "debian:incus;ghsa-repos:lxc/incus\tGHSA-p2v3-6wvc-cv3p;ubuntu-osv:UBUNTU-CVE-2026-81493;ubuntu:CVE-2026-81493",
   "description": "incus",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81493",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81493",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81493"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77416",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:JanssenProject/jans\tGHSA-4c5w-cgpc-9h7m",
   "description": "JanssenProject/jans repository advisory GHSA-4c5w-cgpc-9h7m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/JanssenProject/jans/security/advisories/GHSA-4c5w-cgpc-9h7m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-42293",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:OpenAEV-Platform/openaev\tGHSA-c9pf-5gw2-mfv4",
   "description": "OpenAEV-Platform/openaev repository advisory GHSA-c9pf-5gw2-mfv4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenAEV-Platform/openaev/security/advisories/GHSA-c9pf-5gw2-mfv4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44360",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:OpenAEV-Platform/openaev\tGHSA-g5cm-55mg-67f6",
   "description": "OpenAEV-Platform/openaev repository advisory GHSA-g5cm-55mg-67f6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenAEV-Platform/openaev/security/advisories/GHSA-g5cm-55mg-67f6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44361",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:OpenAEV-Platform/openaev\tGHSA-j9wq-xj7h-c2qw",
   "description": "OpenAEV-Platform/openaev repository advisory GHSA-j9wq-xj7h-c2qw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenAEV-Platform/openaev/security/advisories/GHSA-j9wq-xj7h-c2qw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81180",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:Syslifters/sysreptor\tGHSA-wmf3-gv8j-7qp7",
   "description": "Syslifters/sysreptor repository advisory GHSA-wmf3-gv8j-7qp7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wmf3-gv8j-7qp7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46647",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:globaleaks/globaleaks-whistleblowing-software\tGHSA-m5xx-3qv7-37hj",
   "description": "globaleaks/globaleaks-whistleblowing-software repository advisory GHSA-m5xx-3qv7-37hj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70655",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:globaleaks/globaleaks-whistleblowing-software\tGHSA-9vhh-65v7-3xj6",
   "description": "globaleaks/globaleaks-whistleblowing-software repository advisory GHSA-9vhh-65v7-3xj6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-9vhh-65v7-3xj6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46648",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:globaleaks/globaleaks-whistleblowing-software\tGHSA-w88m-4vmc-pq9g",
   "description": "globaleaks/globaleaks-whistleblowing-software repository advisory GHSA-w88m-4vmc-pq9g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45020",
   "state": "RESERVED",
   "public_date": "2026-07-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-30"
   },
   "refs": "ghsa-repos:globaleaks/globaleaks-whistleblowing-software\tGHSA-x4cq-h872-f8wx",
   "description": "globaleaks/globaleaks-whistleblowing-software repository advisory GHSA-x4cq-h872-f8wx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 47,
   "clock_known": true,
   "hours_public": 1128,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-30",
   "advisory_days_public": 47,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-x4cq-h872-f8wx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12074",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "debian,ghsa,osv,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa": "2026-07-31",
    "osv": "2026-07-31"
   },
   "refs": "debian:nltk;ghsa:GHSA-xh95-f55m-82fw;osv:PyPI:nltk;ubuntu-osv:UBUNTU-CVE-2026-12074;ubuntu:CVE-2026-12074",
   "description": "nltk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nltk",
   "ecosystem": "PyPI",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12074",
    "ghsa": "https://github.com/advisories/GHSA-xh95-f55m-82fw",
    "osv": "https://osv.dev/list?q=CVE-2026-12074",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-12074",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12074"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12072",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "csaf,debian,ghsa,osv,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa": "2026-07-31",
    "osv": "2026-07-31",
    "csaf": "2026-08-06"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11469-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11469-1.json;debian:nltk;ghsa:GHSA-6hm5-jgcp-p838;osv:PyPI:nltk;ubuntu-osv:UBUNTU-CVE-2026-12072;ubuntu:CVE-2026-12072",
   "description": "nltk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nltk",
   "ecosystem": "PyPI",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11469-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12072",
    "ghsa": "https://github.com/advisories/GHSA-6hm5-jgcp-p838",
    "osv": "https://osv.dev/list?q=CVE-2026-12072",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-12072",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12072"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12061",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "debian,ghsa,osv,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13",
    "ghsa": "2026-07-31",
    "osv": "2026-07-31"
   },
   "refs": "debian:nltk;ghsa:GHSA-fg7f-2386-8897;osv:PyPI:nltk;ubuntu-osv:UBUNTU-CVE-2026-12061;ubuntu:CVE-2026-12061",
   "description": "nltk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nltk",
   "ecosystem": "PyPI",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12061",
    "ghsa": "https://github.com/advisories/GHSA-fg7f-2386-8897",
    "osv": "https://osv.dev/list?q=CVE-2026-12061",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-12061",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12061"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62268",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "debian,ubuntu-osv",
   "feed_count": 2,
   "dates": {
    "ubuntu-osv": "2026-07-31"
   },
   "refs": "debian:borgbackup;ubuntu-osv:UBUNTU-CVE-2026-62268",
   "description": "borgbackup",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "borgbackup",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-62268",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-62268"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12075",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-07-31",
    "osv": "2026-07-31"
   },
   "refs": "ghsa:GHSA-qvv7-cg9c-w4x3;osv:PyPI:nltk",
   "description": "Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nltk",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-qvv7-cg9c-w4x3",
    "osv": "https://osv.dev/list?q=CVE-2026-12075"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63218",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-v624-ccrf-9v97",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-v624-ccrf-9v97",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-v624-ccrf-9v97"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63217",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-m5xj-rrwv-g3q3",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-m5xj-rrwv-g3q3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-m5xj-rrwv-g3q3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63215",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-pmhw-r27f-w92m",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-pmhw-r27f-w92m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-pmhw-r27f-w92m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63214",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-gjgm-wrr6-hrmp",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-gjgm-wrr6-hrmp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-gjgm-wrr6-hrmp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63213",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-wfvr-mpq2-257w",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-wfvr-mpq2-257w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-wfvr-mpq2-257w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63111",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-gx3x-3f4c-cjmx",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-gx3x-3f4c-cjmx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-gx3x-3f4c-cjmx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61653",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-5m7h-v4v6-2r8h",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-5m7h-v4v6-2r8h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-5m7h-v4v6-2r8h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61651",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-7cj5-pc2f-9xgv",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-7cj5-pc2f-9xgv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-7cj5-pc2f-9xgv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61650",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-qmh9-m7g7-pxxp",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-qmh9-m7g7-pxxp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-qmh9-m7g7-pxxp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61649",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-r665-27q3-wvg8",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-r665-27q3-wvg8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-r665-27q3-wvg8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61648",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-07-31"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-pqq6-v2mj-hrm2",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-pqq6-v2mj-hrm2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-pqq6-v2mj-hrm2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63199",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-31"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11413-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11413-1.json",
   "description": "CVE-2026-63199",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11413-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63445",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-31"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11413-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11413-1.json",
   "description": "CVE-2026-63445",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11413-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63458",
   "state": "RESERVED",
   "public_date": "2026-07-31",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-07-31"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11413-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11413-1.json",
   "description": "CVE-2026-63458",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 46,
   "clock_known": true,
   "hours_public": 1104,
   "clock_origin": "advisory",
   "advisory_date": "2026-07-31",
   "advisory_days_public": 46,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11413-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65969",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-9mwc-fjgj-8wmq",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-9mwc-fjgj-8wmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9mwc-fjgj-8wmq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67549",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-3wxw-rqhw-j2w4",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-3wxw-rqhw-j2w4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3wxw-rqhw-j2w4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65970",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-v278-gpwr-r836",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-v278-gpwr-r836",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-v278-gpwr-r836"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63635",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-3c8w-9xvm-r6gf",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-3c8w-9xvm-r6gf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3c8w-9xvm-r6gf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63638",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-9hxv-jvgr-3x8g",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-9hxv-jvgr-3x8g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9hxv-jvgr-3x8g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63420",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-x877-h4xx-5m5j",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-x877-h4xx-5m5j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-x877-h4xx-5m5j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63422",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-xh5r-whph-qmc5",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-xh5r-whph-qmc5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xh5r-whph-qmc5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63419",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-01",
    "csaf": "2026-08-04"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11442-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json;ghsa-repos:AcademySoftwareFoundation/OpenImageIO\tGHSA-w6wc-gcf4-5pj2",
   "description": "AcademySoftwareFoundation/OpenImageIO repository advisory GHSA-w6wc-gcf4-5pj2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11442-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-w6wc-gcf4-5pj2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45518",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-09-01",
    "csaf": "2026-09-08",
    "samsung": "2026-08-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;osv:Android:platform/frameworks/base;samsung:SMR-Aug-2026",
   "description": "In tokenize of SQLiteTokenizer.java, there is a possible way to access voicemail information due to SQL injection.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/frameworks/base",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "osv": "https://osv.dev/list?q=CVE-2026-45518",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-15717",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-01"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11422-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11422-1.json",
   "description": "CVE-2026-15717",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11422-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18375",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-01"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-18375\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18375.json",
   "description": "pagure: Pagure: API ACL bypass allows unauthorized repository creation via browser session check",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18375.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18376",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-01"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-18376\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18376.json",
   "description": "koji: Koji SCM URL-Encoding Parser Differential (normpath bypass)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18376.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49885",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28645",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45522",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28667",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49880",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28591",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0022",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45513",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28665",
   "state": "RESERVED",
   "public_date": "2026-08-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-08-01"
   },
   "refs": "samsung:SMR-Aug-2026",
   "description": "Samsung SMR Aug 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 45,
   "clock_known": true,
   "hours_public": 1080,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-01",
   "advisory_days_public": 45,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59774",
   "state": "RESERVED",
   "public_date": "2026-08-02",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-02",
    "csaf": "2026-08-02"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2612\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2612.json;ghsa-repos:go-gitea/gitea\tGHSA-6v53-hr58-556r",
   "description": "go-gitea/gitea repository advisory GHSA-6v53-hr58-556r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 44,
   "clock_known": true,
   "hours_public": 1056,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-02",
   "advisory_days_public": 44,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-59774",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2612.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-6v53-hr58-556r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65828",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-x4f3-367g-m93g",
   "description": "zammad/zammad repository advisory GHSA-x4f3-367g-m93g",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-x4f3-367g-m93g"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63204",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-75j9-hpg4-j9f8",
   "description": "zammad/zammad repository advisory GHSA-75j9-hpg4-j9f8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-75j9-hpg4-j9f8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63205",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-pp8r-x7pp-5qj5",
   "description": "zammad/zammad repository advisory GHSA-pp8r-x7pp-5qj5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-pp8r-x7pp-5qj5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63208",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-qh8m-g5vr-7272",
   "description": "zammad/zammad repository advisory GHSA-qh8m-g5vr-7272",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-qh8m-g5vr-7272"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63206",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-fpwp-w2p4-hqg7",
   "description": "zammad/zammad repository advisory GHSA-fpwp-w2p4-hqg7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-fpwp-w2p4-hqg7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63006",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-33p2-cm7w-62g3",
   "description": "zammad/zammad repository advisory GHSA-33p2-cm7w-62g3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-33p2-cm7w-62g3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63216",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-r95m-ghj7-646x",
   "description": "zammad/zammad repository advisory GHSA-r95m-ghj7-646x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-r95m-ghj7-646x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61855",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-r957-vp26-563q",
   "description": "zammad/zammad repository advisory GHSA-r957-vp26-563q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-r957-vp26-563q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63207",
   "state": "RESERVED",
   "public_date": "2026-08-03",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-04",
    "csaf": "2026-08-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2641\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json;ghsa-repos:zammad/zammad\tGHSA-48h2-wv8r-fgp9",
   "description": "zammad/zammad repository advisory GHSA-48h2-wv8r-fgp9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 43,
   "clock_known": true,
   "hours_public": 1032,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-03",
   "advisory_days_public": 43,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2641.json",
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-48h2-wv8r-fgp9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62983",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-7whw-8467-78jp",
   "description": "chamilo/chamilo-lms repository advisory GHSA-7whw-8467-78jp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-7whw-8467-78jp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62307",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-7g97-jh3w-53wh",
   "description": "chamilo/chamilo-lms repository advisory GHSA-7g97-jh3w-53wh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-7g97-jh3w-53wh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62306",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-hg2v-955j-35c3",
   "description": "chamilo/chamilo-lms repository advisory GHSA-hg2v-955j-35c3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-hg2v-955j-35c3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62305",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-37fh-r78h-9vvr",
   "description": "chamilo/chamilo-lms repository advisory GHSA-37fh-r78h-9vvr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-37fh-r78h-9vvr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62304",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-9r7v-p62p-h9gc",
   "description": "chamilo/chamilo-lms repository advisory GHSA-9r7v-p62p-h9gc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-9r7v-p62p-h9gc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61786",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-35wp-xr4v-jg99",
   "description": "chamilo/chamilo-lms repository advisory GHSA-35wp-xr4v-jg99",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-35wp-xr4v-jg99"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61785",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-3v23-qp3p-p2xf",
   "description": "chamilo/chamilo-lms repository advisory GHSA-3v23-qp3p-p2xf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-3v23-qp3p-p2xf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61665",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-rpp3-vpc9-w3h2",
   "description": "chamilo/chamilo-lms repository advisory GHSA-rpp3-vpc9-w3h2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-rpp3-vpc9-w3h2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61661",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-7jqm-3829-36cm",
   "description": "chamilo/chamilo-lms repository advisory GHSA-7jqm-3829-36cm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-7jqm-3829-36cm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61660",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-9g35-w847-rpp8",
   "description": "chamilo/chamilo-lms repository advisory GHSA-9g35-w847-rpp8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-9g35-w847-rpp8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61659",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-9mpp-78g5-c22m",
   "description": "chamilo/chamilo-lms repository advisory GHSA-9mpp-78g5-c22m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-9mpp-78g5-c22m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61658",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-h24x-xw47-2wwx",
   "description": "chamilo/chamilo-lms repository advisory GHSA-h24x-xw47-2wwx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-h24x-xw47-2wwx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61656",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-vjmr-7vxh-wpg2",
   "description": "chamilo/chamilo-lms repository advisory GHSA-vjmr-7vxh-wpg2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-vjmr-7vxh-wpg2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61655",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-j9jg-h6cw-jj7v",
   "description": "chamilo/chamilo-lms repository advisory GHSA-j9jg-h6cw-jj7v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-j9jg-h6cw-jj7v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61624",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-x3j9-q879-46vr",
   "description": "chamilo/chamilo-lms repository advisory GHSA-x3j9-q879-46vr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-x3j9-q879-46vr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61623",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-rp64-899j-x9f6",
   "description": "chamilo/chamilo-lms repository advisory GHSA-rp64-899j-x9f6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-rp64-899j-x9f6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61622",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-2c5g-hrhg-44vg",
   "description": "chamilo/chamilo-lms repository advisory GHSA-2c5g-hrhg-44vg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-2c5g-hrhg-44vg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61615",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-mw74-xqfh-r8gj",
   "description": "chamilo/chamilo-lms repository advisory GHSA-mw74-xqfh-r8gj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-mw74-xqfh-r8gj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61603",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-94h4-9vrp-v3cv",
   "description": "chamilo/chamilo-lms repository advisory GHSA-94h4-9vrp-v3cv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-94h4-9vrp-v3cv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61602",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-66hv-22wg-x4q2",
   "description": "chamilo/chamilo-lms repository advisory GHSA-66hv-22wg-x4q2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-66hv-22wg-x4q2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61601",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-55mr-fcm3-5724",
   "description": "chamilo/chamilo-lms repository advisory GHSA-55mr-fcm3-5724",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-55mr-fcm3-5724"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61600",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-pjh4-mvwg-6jrm",
   "description": "chamilo/chamilo-lms repository advisory GHSA-pjh4-mvwg-6jrm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-pjh4-mvwg-6jrm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61587",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-j3jc-5rqc-qq2x",
   "description": "chamilo/chamilo-lms repository advisory GHSA-j3jc-5rqc-qq2x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-j3jc-5rqc-qq2x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61585",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-6wcp-8v36-m8hv",
   "description": "chamilo/chamilo-lms repository advisory GHSA-6wcp-8v36-m8hv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-6wcp-8v36-m8hv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61577",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-cg5h-j563-652j",
   "description": "chamilo/chamilo-lms repository advisory GHSA-cg5h-j563-652j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-cg5h-j563-652j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54748",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-99q5-mwrx-jq34",
   "description": "chamilo/chamilo-lms repository advisory GHSA-99q5-mwrx-jq34",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-99q5-mwrx-jq34"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61558",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-x579-vfgg-ff5w",
   "description": "chamilo/chamilo-lms repository advisory GHSA-x579-vfgg-ff5w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-x579-vfgg-ff5w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61538",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-2369-h4gx-5mfx",
   "description": "chamilo/chamilo-lms repository advisory GHSA-2369-h4gx-5mfx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-2369-h4gx-5mfx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54750",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-5vmm-46vr-72j8",
   "description": "chamilo/chamilo-lms repository advisory GHSA-5vmm-46vr-72j8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-5vmm-46vr-72j8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61537",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-p2pv-9wv4-pw66",
   "description": "chamilo/chamilo-lms repository advisory GHSA-p2pv-9wv4-pw66",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-p2pv-9wv4-pw66"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61533",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-65wx-4v4p-xph3",
   "description": "chamilo/chamilo-lms repository advisory GHSA-65wx-4v4p-xph3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-65wx-4v4p-xph3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61733",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-ch7g-4f23-9hm2",
   "description": "chamilo/chamilo-lms repository advisory GHSA-ch7g-4f23-9hm2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-ch7g-4f23-9hm2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61734",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-2fr5-c8p6-5hq6",
   "description": "chamilo/chamilo-lms repository advisory GHSA-2fr5-c8p6-5hq6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-2fr5-c8p6-5hq6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61531",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-438r-9jh4-mmfc",
   "description": "chamilo/chamilo-lms repository advisory GHSA-438r-9jh4-mmfc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-438r-9jh4-mmfc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61530",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-8423-5658-789h",
   "description": "chamilo/chamilo-lms repository advisory GHSA-8423-5658-789h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-8423-5658-789h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70644",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-vrcq-jx87-3rc6",
   "description": "owncloud/security-advisories repository advisory GHSA-vrcq-jx87-3rc6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-vrcq-jx87-3rc6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70645",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-qcf4-c9pm-c2ww",
   "description": "owncloud/security-advisories repository advisory GHSA-qcf4-c9pm-c2ww",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-qcf4-c9pm-c2ww"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59953",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-q9wg-cjf4-xwwc",
   "description": "owncloud/security-advisories repository advisory GHSA-q9wg-cjf4-xwwc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-q9wg-cjf4-xwwc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-55302",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-p325-hhcp-j884",
   "description": "owncloud/security-advisories repository advisory GHSA-p325-hhcp-j884",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-p325-hhcp-j884"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58274",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-7cmc-wrr6-qf82",
   "description": "owncloud/security-advisories repository advisory GHSA-7cmc-wrr6-qf82",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-7cmc-wrr6-qf82"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84465",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-m9ff-hjr3-93h4",
   "description": "zammad/zammad repository advisory GHSA-m9ff-hjr3-93h4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-m9ff-hjr3-93h4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84463",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-cxjg-4gmf-5xqc",
   "description": "zammad/zammad repository advisory GHSA-cxjg-4gmf-5xqc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-cxjg-4gmf-5xqc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84460",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-6vgm-xxp4-p6jv",
   "description": "zammad/zammad repository advisory GHSA-6vgm-xxp4-p6jv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-6vgm-xxp4-p6jv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84464",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-jvm2-cr58-4qxp",
   "description": "zammad/zammad repository advisory GHSA-jvm2-cr58-4qxp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-jvm2-cr58-4qxp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84462",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-gp3x-9xm8-rcj6",
   "description": "zammad/zammad repository advisory GHSA-gp3x-9xm8-rcj6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-gp3x-9xm8-rcj6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84461",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-6vh5-pfp2-5rmh",
   "description": "zammad/zammad repository advisory GHSA-6vh5-pfp2-5rmh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-6vh5-pfp2-5rmh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84458",
   "state": "RESERVED",
   "public_date": "2026-08-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-04"
   },
   "refs": "ghsa-repos:zammad/zammad\tGHSA-86cc-3ggh-mf2m",
   "description": "zammad/zammad repository advisory GHSA-86cc-3ggh-mf2m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 42,
   "clock_known": true,
   "hours_public": 1008,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-04",
   "advisory_days_public": 42,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zammad/zammad/security/advisories/GHSA-86cc-3ggh-mf2m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52682",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "alpine,csaf,debian,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu-osv": "2026-08-07",
    "csaf": "2026-08-05"
   },
   "refs": "alpine:dnsdist;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2683\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2683.json;debian:dnsdist;ubuntu-osv:UBUNTU-CVE-2026-52682",
   "description": "[A crafted DNS packet can cause increased memory and CPU consumption]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "dnsdist",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-52682",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2683.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52682",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-52682"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70650",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-p6vf-2xr7-mcf4",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-p6vf-2xr7-mcf4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-p6vf-2xr7-mcf4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54535",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:OpenSIPS/opensips\tGHSA-g97q-m2gv-f5vc",
   "description": "OpenSIPS/opensips repository advisory GHSA-g97q-m2gv-f5vc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenSIPS/opensips/security/advisories/GHSA-g97q-m2gv-f5vc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54539",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:OpenSIPS/opensips\tGHSA-hx7p-6j27-gjpv",
   "description": "OpenSIPS/opensips repository advisory GHSA-hx7p-6j27-gjpv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenSIPS/opensips/security/advisories/GHSA-hx7p-6j27-gjpv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62339",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:OpenSIPS/opensips\tGHSA-65mj-944f-fx48",
   "description": "OpenSIPS/opensips repository advisory GHSA-65mj-944f-fx48",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OpenSIPS/opensips/security/advisories/GHSA-65mj-944f-fx48"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69145",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-4fhr-x4wr-fwqg",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-4fhr-x4wr-fwqg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-4fhr-x4wr-fwqg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69144",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-j2r4-r4wh-339v",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-j2r4-r4wh-339v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-j2r4-r4wh-339v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69143",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-rc6r-hwhg-7pfg",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-rc6r-hwhg-7pfg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-rc6r-hwhg-7pfg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69142",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-pjc8-2w2x-xcgf",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-pjc8-2w2x-xcgf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-pjc8-2w2x-xcgf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69141",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-wphj-qjgj-4j23",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-wphj-qjgj-4j23",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-wphj-qjgj-4j23"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69140",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-xg3m-xvc9-j55j",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-xg3m-xvc9-j55j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-xg3m-xvc9-j55j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69137",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-72r3-24x4-j46c",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-72r3-24x4-j46c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-72r3-24x4-j46c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69136",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-3mjp-45mc-3256",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-3mjp-45mc-3256",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-3mjp-45mc-3256"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69135",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-gcc4-hvpc-cgvv",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-gcc4-hvpc-cgvv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-gcc4-hvpc-cgvv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69134",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-05"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-3phg-q9w9-4pqw",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-3phg-q9w9-4pqw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-3phg-q9w9-4pqw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61545",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-05",
    "csaf": "2026-08-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2685\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2685.json;ghsa-repos:nextcloud/security-advisories\tGHSA-vq3v-jv6f-6xp2",
   "description": "nextcloud/security-advisories repository advisory GHSA-vq3v-jv6f-6xp2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2685.json",
    "ghsa-repos": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vq3v-jv6f-6xp2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61527",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-05",
    "csaf": "2026-08-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2685\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2685.json;ghsa-repos:nextcloud/security-advisories\tGHSA-99gw-ww6p-f2rr",
   "description": "nextcloud/security-advisories repository advisory GHSA-99gw-ww6p-f2rr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2685.json",
    "ghsa-repos": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-99gw-ww6p-f2rr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-15268",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-05"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11455-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11455-1.json",
   "description": "CVE-2026-15268",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11455-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-17629",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2675\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2675.json",
   "description": "CVE-2026-17629",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2675.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-8506",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2675\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2675.json",
   "description": "CVE-2026-8506",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2675.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-9131",
   "state": "RESERVED",
   "public_date": "2026-08-05",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-05"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2675\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2675.json",
   "description": "CVE-2026-9131",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 41,
   "clock_known": true,
   "hours_public": 984,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-05",
   "advisory_days_public": 41,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2675.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71426",
   "state": "RESERVED",
   "public_date": "2026-08-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-06"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-559q-hqrv-m84x",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-559q-hqrv-m84x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 40,
   "clock_known": true,
   "hours_public": 960,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-06",
   "advisory_days_public": 40,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-559q-hqrv-m84x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87004",
   "state": "RESERVED",
   "public_date": "2026-08-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-06"
   },
   "refs": "ghsa-repos:Quenary/tugtainer\tGHSA-crjc-6vc7-xrfh",
   "description": "Quenary/tugtainer repository advisory GHSA-crjc-6vc7-xrfh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 40,
   "clock_known": true,
   "hours_public": 960,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-06",
   "advisory_days_public": 40,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87005",
   "state": "RESERVED",
   "public_date": "2026-08-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-06"
   },
   "refs": "ghsa-repos:siemens/linux-entra-sso\tGHSA-g9vc-5j77-f2cm",
   "description": "siemens/linux-entra-sso repository advisory GHSA-g9vc-5j77-f2cm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 40,
   "clock_known": true,
   "hours_public": 960,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-06",
   "advisory_days_public": 40,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/siemens/linux-entra-sso/security/advisories/GHSA-g9vc-5j77-f2cm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63625",
   "state": "RESERVED",
   "public_date": "2026-08-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-06"
   },
   "refs": "ghsa-repos:xwikisas/xwiki-pro-macros\tGHSA-22q9-227p-wx5j",
   "description": "xwikisas/xwiki-pro-macros repository advisory GHSA-22q9-227p-wx5j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 40,
   "clock_known": true,
   "hours_public": 960,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-06",
   "advisory_days_public": 40,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xwikisas/xwiki-pro-macros/security/advisories/GHSA-22q9-227p-wx5j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61703",
   "state": "RESERVED",
   "public_date": "2026-08-07",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-07",
    "csaf": "2026-08-26"
   },
   "refs": "alpine:openexr;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11612-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11612-1.json;ghsa-repos:AcademySoftwareFoundation/openexr\tGHSA-994f-rr2m-9r7x",
   "description": "AcademySoftwareFoundation/openexr repository advisory GHSA-994f-rr2m-9r7x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 39,
   "clock_known": true,
   "hours_public": 936,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-07",
   "advisory_days_public": 39,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "openexr",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-61703",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11612-1.json",
    "ghsa-repos": "https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-994f-rr2m-9r7x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71542",
   "state": "RESERVED",
   "public_date": "2026-08-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-07"
   },
   "refs": "ghsa-repos:GetSimpleCMS-CE/GetSimpleCMS-CE\tGHSA-vqfh-838q-xfqh",
   "description": "GetSimpleCMS-CE/GetSimpleCMS-CE repository advisory GHSA-vqfh-838q-xfqh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 39,
   "clock_known": true,
   "hours_public": 936,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-07",
   "advisory_days_public": 39,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-vqfh-838q-xfqh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85721",
   "state": "RESERVED",
   "public_date": "2026-08-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-09"
   },
   "refs": "ghsa-repos:AsyncHttpClient/async-http-client\tGHSA-7grg-jcf7-rpmx",
   "description": "AsyncHttpClient/async-http-client repository advisory GHSA-7grg-jcf7-rpmx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 37,
   "clock_known": true,
   "hours_public": 888,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-09",
   "advisory_days_public": 37,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-7grg-jcf7-rpmx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85719",
   "state": "RESERVED",
   "public_date": "2026-08-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-09"
   },
   "refs": "ghsa-repos:AsyncHttpClient/async-http-client\tGHSA-x5w6-vm3f-pp6f",
   "description": "AsyncHttpClient/async-http-client repository advisory GHSA-x5w6-vm3f-pp6f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 37,
   "clock_known": true,
   "hours_public": 888,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-09",
   "advisory_days_public": 37,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x5w6-vm3f-pp6f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85720",
   "state": "RESERVED",
   "public_date": "2026-08-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-09"
   },
   "refs": "ghsa-repos:AsyncHttpClient/async-http-client\tGHSA-xr57-gcx8-52hf",
   "description": "AsyncHttpClient/async-http-client repository advisory GHSA-xr57-gcx8-52hf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 37,
   "clock_known": true,
   "hours_public": 888,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-09",
   "advisory_days_public": 37,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-xr57-gcx8-52hf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85717",
   "state": "RESERVED",
   "public_date": "2026-08-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-09"
   },
   "refs": "ghsa-repos:AsyncHttpClient/async-http-client\tGHSA-f8m2-889x-vw4x",
   "description": "AsyncHttpClient/async-http-client repository advisory GHSA-f8m2-889x-vw4x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 37,
   "clock_known": true,
   "hours_public": 888,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-09",
   "advisory_days_public": 37,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f8m2-889x-vw4x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85716",
   "state": "RESERVED",
   "public_date": "2026-08-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-09"
   },
   "refs": "ghsa-repos:AsyncHttpClient/async-http-client\tGHSA-fj9w-c36g-h5x8",
   "description": "AsyncHttpClient/async-http-client repository advisory GHSA-fj9w-c36g-h5x8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 37,
   "clock_known": true,
   "hours_public": 888,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-09",
   "advisory_days_public": 37,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fj9w-c36g-h5x8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85718",
   "state": "RESERVED",
   "public_date": "2026-08-09",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-09"
   },
   "refs": "ghsa-repos:AsyncHttpClient/async-http-client\tGHSA-gcmv-gr82-6m8v",
   "description": "AsyncHttpClient/async-http-client repository advisory GHSA-gcmv-gr82-6m8v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 37,
   "clock_known": true,
   "hours_public": 888,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-09",
   "advisory_days_public": 37,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-gcmv-gr82-6m8v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61478",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-08-10",
    "ubuntu": "2026-08-13",
    "ubuntu-osv": "2026-08-13"
   },
   "refs": "alas:CVE-2026-61478;debian:libvirt;ubuntu-osv:UBUNTU-CVE-2026-61478;ubuntu:CVE-2026-61478",
   "description": "libvirt: Check for empty string condition and skip inclusion of the XML document context in the error message.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libvirt",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61478.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61478",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61478",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61478"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44639",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-10"
   },
   "refs": "ghsa-repos:nanomq/nanomq\tGHSA-6mwg-445v-2qrv",
   "description": "nanomq/nanomq repository advisory GHSA-6mwg-445v-2qrv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/nanomq/nanomq/security/advisories/GHSA-6mwg-445v-2qrv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61633",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-10"
   },
   "refs": "ghsa-repos:nanomq/nanomq\tGHSA-m7mp-rr3v-hmhr",
   "description": "nanomq/nanomq repository advisory GHSA-m7mp-rr3v-hmhr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/nanomq/nanomq/security/advisories/GHSA-m7mp-rr3v-hmhr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53767",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-10"
   },
   "refs": "ghsa-repos:xenocrat/chyrp-lite\tGHSA-8h86-c24h-5jp3",
   "description": "xenocrat/chyrp-lite repository advisory GHSA-8h86-c24h-5jp3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xenocrat/chyrp-lite/security/advisories/GHSA-8h86-c24h-5jp3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71323",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-10"
   },
   "refs": "ghsa-repos:xenocrat/chyrp-lite\tGHSA-753p-h5vp-7p9f",
   "description": "xenocrat/chyrp-lite repository advisory GHSA-753p-h5vp-7p9f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xenocrat/chyrp-lite/security/advisories/GHSA-753p-h5vp-7p9f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53768",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-10"
   },
   "refs": "ghsa-repos:xenocrat/chyrp-lite\tGHSA-r9w7-5h94-wq5x",
   "description": "xenocrat/chyrp-lite repository advisory GHSA-r9w7-5h94-wq5x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xenocrat/chyrp-lite/security/advisories/GHSA-r9w7-5h94-wq5x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66801",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-08-10",
    "csaf": "2026-08-11"
   },
   "refs": "csaf:Red Hat Product Security\tRHSA-2026:53530\thttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53530.json;redhat:CVE-2026-66801",
   "description": "multicluster-global-hub: Cross-hub lateral movement via shared spec-topic Write ACL and spoofable CloudEvent identity",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-66801",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53530.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-66801"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56618",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2741\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2741.json",
   "description": "CVE-2026-56618",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2741.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64953",
   "state": "RESERVED",
   "public_date": "2026-08-10",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-10"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2728\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2728.json",
   "description": "CVE-2026-64953",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 36,
   "clock_known": true,
   "hours_public": 864,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-10",
   "advisory_days_public": 36,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2728.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64786",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:apple/container\tGHSA-xwgf-4rc5-p4m4",
   "description": "apple/container repository advisory GHSA-xwgf-4rc5-p4m4",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/apple/container/security/advisories/GHSA-xwgf-4rc5-p4m4"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63491",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:kohler/hotcrp\tGHSA-4v58-pj7j-xc8j",
   "description": "kohler/hotcrp repository advisory GHSA-4v58-pj7j-xc8j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/kohler/hotcrp/security/advisories/GHSA-4v58-pj7j-xc8j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81881",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-q4w7-225g-64j9",
   "description": "radareorg/radare2 repository advisory GHSA-q4w7-225g-64j9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-q4w7-225g-64j9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81878",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-9phv-v2w8-56j3",
   "description": "radareorg/radare2 repository advisory GHSA-9phv-v2w8-56j3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-9phv-v2w8-56j3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63113",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:sharetribe/web-template\tGHSA-f5r9-7hmp-j694",
   "description": "sharetribe/web-template repository advisory GHSA-f5r9-7hmp-j694",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sharetribe/web-template/security/advisories/GHSA-f5r9-7hmp-j694"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63112",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:sharetribe/web-template\tGHSA-rcgh-6wcv-gq7v",
   "description": "sharetribe/web-template repository advisory GHSA-rcgh-6wcv-gq7v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/sharetribe/web-template/security/advisories/GHSA-rcgh-6wcv-gq7v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77580",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-xr7g-gv5j-ph8q",
   "description": "xibosignage/xibo-cms repository advisory GHSA-xr7g-gv5j-ph8q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-xr7g-gv5j-ph8q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77588",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-3xgq-r5vq-c9ff",
   "description": "xibosignage/xibo-cms repository advisory GHSA-3xgq-r5vq-c9ff",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-3xgq-r5vq-c9ff"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77579",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-vhmj-m55w-4xxc",
   "description": "xibosignage/xibo-cms repository advisory GHSA-vhmj-m55w-4xxc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-vhmj-m55w-4xxc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77578",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-pc3g-2hhm-46qc",
   "description": "xibosignage/xibo-cms repository advisory GHSA-pc3g-2hhm-46qc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-pc3g-2hhm-46qc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77577",
   "state": "RESERVED",
   "public_date": "2026-08-11",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-11"
   },
   "refs": "ghsa-repos:xibosignage/xibo-cms\tGHSA-mgjq-cpf4-pjjw",
   "description": "xibosignage/xibo-cms repository advisory GHSA-mgjq-cpf4-pjjw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 35,
   "clock_known": true,
   "hours_public": 840,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-11",
   "advisory_days_public": 35,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-mgjq-cpf4-pjjw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18724",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "alas,csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-08-14",
    "ubuntu": "2026-08-18",
    "ubuntu-osv": "2026-08-18",
    "redhat": "2026-08-12",
    "csaf": "2026-08-14"
   },
   "refs": "alas:CVE-2026-18724;csaf:SUSE Product Security Team\tCVE-2026-18724\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-18724.json;debian:open-iscsi;redhat:CVE-2026-18724;ubuntu-osv:UBUNTU-CVE-2026-18724;ubuntu:CVE-2026-18724",
   "description": "open-iscsi: open-iscsi: Stack buffer overflow in idbm record parsing",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "open-iscsi",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-18724.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-18724.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-18724",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-18724",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-18724",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-18724"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18725",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "alas,csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-08-14",
    "ubuntu": "2026-08-18",
    "ubuntu-osv": "2026-08-18",
    "redhat": "2026-08-12",
    "csaf": "2026-08-18"
   },
   "refs": "alas:CVE-2026-18725;csaf:SUSE Product Security Team\tCVE-2026-18725\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-18725.json;debian:open-iscsi;redhat:CVE-2026-18725;ubuntu-osv:UBUNTU-CVE-2026-18725;ubuntu:CVE-2026-18725",
   "description": "open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "open-iscsi",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-18725.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-18725.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-18725",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-18725",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-18725",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-18725"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73261",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-14",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-3fmr-92g4-wchx;ubuntu:CVE-2026-73261",
   "description": "[Built-in TCP/IP malformed TCP option handling]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73261",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-3fmr-92g4-wchx",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73261"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73260",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-14",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-f6wr-mg35-p25g;ubuntu:CVE-2026-73260",
   "description": "[Built-in TLS X.509 DER parsing bounds check]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73260",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-f6wr-mg35-p25g",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73260"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73252",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-14",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-hq58-98f5-2wg3;ubuntu:CVE-2026-73252",
   "description": "[Built-in TLS short-record handling]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73252",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-hq58-98f5-2wg3",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73252"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63626",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-14",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-pc66-j6r6-49x9;ubuntu:CVE-2026-63626",
   "description": "[Built-in TCP/IP PPP IPV6CP option parsing bounds check]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63626",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-pc66-j6r6-49x9",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63626"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12876",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa,ghsa-repos,osv,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "ubuntu": "2026-08-14",
    "ubuntu-osv": "2026-08-14",
    "ghsa": "2026-09-02",
    "ghsa-repos": "2026-08-12",
    "osv": "2026-09-02"
   },
   "refs": "debian:nltk;ghsa-repos:nltk/nltk\tGHSA-ff5c-cp5c-9wjf;ghsa:GHSA-ff5c-cp5c-9wjf;osv:PyPI:nltk;ubuntu-osv:UBUNTU-CVE-2026-12876;ubuntu:CVE-2026-12876",
   "description": "nltk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nltk",
   "ecosystem": "PyPI",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12876",
    "ghsa": "https://github.com/advisories/GHSA-ff5c-cp5c-9wjf",
    "ghsa-repos": "https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf",
    "osv": "https://osv.dev/list?q=CVE-2026-12876",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-12876",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12876"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52068",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-13",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-9qr7-6j3g-f76w;ubuntu:CVE-2026-52068",
   "description": "[rx_ndp_na NDP NA missing option length check -- OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52068",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-9qr7-6j3g-f76w",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52068"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52061",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-13",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-pfr9-hqr2-78rq;ubuntu:CVE-2026-52061",
   "description": "[mg_tls_recv_cert certificate chain length unchecked -- OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52061",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-pfr9-hqr2-78rq",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52061"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52053",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "debian,ghsa-repos,ubuntu",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-13",
    "ghsa-repos": "2026-08-12"
   },
   "refs": "debian:mongoose;ghsa-repos:cesanta/mongoose\tGHSA-g96q-9mw4-vr8x;ubuntu:CVE-2026-52053",
   "description": "[rx_ip6 IPv6 extension header OOB read; 16-bit len wrap]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52053",
    "ghsa-repos": "https://github.com/cesanta/mongoose/security/advisories/GHSA-g96q-9mw4-vr8x",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52053"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55074",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-12",
    "osv": "2026-08-12"
   },
   "refs": "ghsa:GHSA-cxgv-hp74-jj7r;osv:PyPI:ansible-jailexec",
   "description": "Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ansible-jailexec",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-cxgv-hp74-jj7r",
    "osv": "https://osv.dev/list?q=CVE-2026-55074"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55071",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-12",
    "osv": "2026-08-12"
   },
   "refs": "ghsa:GHSA-49m4-vp58-wgc9;osv:PyPI:stata-mcp",
   "description": "MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "stata-mcp",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-49m4-vp58-wgc9",
    "osv": "https://osv.dev/list?q=CVE-2026-55071"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-47132",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-12",
    "osv": "2026-08-12"
   },
   "refs": "ghsa:GHSA-6pvm-2vjj-rx4w;osv:Packagist:thorsten/phpmyfaq",
   "description": "phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "thorsten/phpmyfaq",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-6pvm-2vjj-rx4w",
    "osv": "https://osv.dev/list?q=CVE-2026-47132"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64680",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-12"
   },
   "refs": "ghsa-repos:apostrophecms/apostrophe\tGHSA-rgg4-476q-xgcg",
   "description": "apostrophecms/apostrophe repository advisory GHSA-rgg4-476q-xgcg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-rgg4-476q-xgcg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63668",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-12"
   },
   "refs": "ghsa-repos:apostrophecms/apostrophe\tGHSA-xmpp-f9v3-r7qh",
   "description": "apostrophecms/apostrophe repository advisory GHSA-xmpp-f9v3-r7qh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-xmpp-f9v3-r7qh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77531",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-12"
   },
   "refs": "ghsa-repos:cilium/cilium\tGHSA-xqhm-7xhv-6ppj",
   "description": "cilium/cilium repository advisory GHSA-xqhm-7xhv-6ppj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cilium/cilium/security/advisories/GHSA-xqhm-7xhv-6ppj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83620",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-12"
   },
   "refs": "ghsa-repos:cilium/cilium\tGHSA-33qq-jq9c-6gcc",
   "description": "cilium/cilium repository advisory GHSA-33qq-jq9c-6gcc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/cilium/cilium/security/advisories/GHSA-33qq-jq9c-6gcc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71385",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0294\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0294.json",
   "description": "CVE-2026-71385",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0294.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16858",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2820\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json",
   "description": "CVE-2026-16858",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-17208",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2820\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json",
   "description": "CVE-2026-17208",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-17217",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2820\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json",
   "description": "CVE-2026-17217",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-17498",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2820\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json",
   "description": "CVE-2026-17498",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18680",
   "state": "RESERVED",
   "public_date": "2026-08-12",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-12"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2820\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json",
   "description": "CVE-2026-18680",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 34,
   "clock_known": true,
   "hours_public": 816,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-12",
   "advisory_days_public": 34,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2820.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52079",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52079",
   "description": "[ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52079",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52079"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52078",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52078",
   "description": "[opendir() stack overflow via wcscat on MAX_PATH path]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52078",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52078"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52076",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52076",
   "description": "[cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52076",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52076"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52075",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52075",
   "description": "[mg_random rand() fallback used for TLS secrets]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52075",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52075"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52073",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52073",
   "description": "[ppp_handle_ipcp attacker-controlled IPCP length -- OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52073",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52073"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52072",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52072",
   "description": "[mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52072",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52072"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52071",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52071",
   "description": "[mg_tls_verify_cert_signature OOB read for short ECDSA integers]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52071",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52071"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52070",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52070",
   "description": "[rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52070",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52070"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52069",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52069",
   "description": "[rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52069",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52069"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52067",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52067",
   "description": "[rx_ip truncated DHCP options size_t underflow OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52067",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52067"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52066",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52066",
   "description": "[TLS certificate notAfter validated against hardcoded 2025-01-01 string]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52066",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52066"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52065",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52065",
   "description": "[mg_tls_client_recv_hello key_share extension OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52065",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52065"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52064",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52064",
   "description": "[DNS transaction ID is sequential -- enables response injection]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52064",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52064"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52062",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52062",
   "description": "[NDP RA allows any value for MTU]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52062",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52062"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52060",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52060",
   "description": "[TLS certificate notAfter validated against hardcoded 2025-01-01 string]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52060",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52060"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52059",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52059",
   "description": "[RSA-PSS CertificateVerify checks only 0xbc trailer]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52059",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52059"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52058",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52058",
   "description": "[mg_der_to_tlv long-form DER length OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52058",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52058"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52057",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52057",
   "description": "[mg_der_find_oid unbounded recursion on constructed DER tags]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52057",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52057"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52056",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52056",
   "description": "[skip_chunk off-by-one OOB read in chunked HTTP CRLF check]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52056",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52056"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52055",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52055",
   "description": "[mg_der_to_tlv long-form DER length OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52055",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52055"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52052",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52052",
   "description": "[mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52052",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52052"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52051",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52051",
   "description": "[mg_tls_server_recv_hello session_id_len OOB read]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52051",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52051"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52050",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52050",
   "description": "[precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52050",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52050"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52048",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52048",
   "description": "[MQTT v5 properties bounds check uses relative offset against absolute position]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52048",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52048"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52047",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "debian,ubuntu",
   "feed_count": 2,
   "dates": {
    "ubuntu": "2026-08-13"
   },
   "refs": "debian:mongoose;ubuntu:CVE-2026-52047",
   "description": "[w5100_rx wraparound RX path copies n instead of r bytes]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mongoose",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-52047",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-52047"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71537",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-13"
   },
   "refs": "ghsa-repos:Paymenter/Paymenter\tGHSA-5gmm-hjfj-8ff7",
   "description": "Paymenter/Paymenter repository advisory GHSA-5gmm-hjfj-8ff7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-13",
   "advisory_days_public": 33,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-5gmm-hjfj-8ff7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53526",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-13"
   },
   "refs": "ghsa-repos:dzikoysk/reposilite\tGHSA-7944-89x5-52q9",
   "description": "dzikoysk/reposilite repository advisory GHSA-7944-89x5-52q9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-13",
   "advisory_days_public": 33,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dzikoysk/reposilite/security/advisories/GHSA-7944-89x5-52q9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77460",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-13"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-28w2-h88g-6vgv",
   "description": "espocrm/espocrm repository advisory GHSA-28w2-h88g-6vgv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-13",
   "advisory_days_public": 33,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-28w2-h88g-6vgv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75505",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-13"
   },
   "refs": "ghsa-repos:espocrm/espocrm\tGHSA-24pg-2q7q-m5p6",
   "description": "espocrm/espocrm repository advisory GHSA-24pg-2q7q-m5p6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-13",
   "advisory_days_public": 33,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espocrm/espocrm/security/advisories/GHSA-24pg-2q7q-m5p6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73503",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-13"
   },
   "refs": "ghsa-repos:owncloud/security-advisories\tGHSA-j4jg-hf2g-h4j2",
   "description": "owncloud/security-advisories repository advisory GHSA-j4jg-hf2g-h4j2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-13",
   "advisory_days_public": 33,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-j4jg-hf2g-h4j2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67212",
   "state": "RESERVED",
   "public_date": "2026-08-13",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-13"
   },
   "refs": "zdi:ZDI-26-577",
   "description": "ZDI advisory ZDI-26-577",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 33,
   "clock_known": true,
   "hours_public": 792,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-13",
   "advisory_days_public": 33,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-577/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16457",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-08-16",
    "ubuntu": "2026-08-14",
    "ubuntu-osv": "2026-08-14"
   },
   "refs": "alas:CVE-2026-16457;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-16457;ubuntu:CVE-2026-16457",
   "description": "Virtqueue handler functions in device emulation code often look something like this: while (!virtio_queue_empty(vq)) { ...pop and process virtqueue element... } virtio-blk, virtio-scsi, virtio-crypto, and vhost-shadow-virtqueue use this pattern.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-16",
   "advisory_days_public": 30,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-16457.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-16457",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-16457",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-16457"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63318",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-08-16",
    "ubuntu": "2026-08-14",
    "ubuntu-osv": "2026-08-14"
   },
   "refs": "alas:CVE-2026-63318;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63318;ubuntu:CVE-2026-63318",
   "description": "QEMU's 9pfs readonly check at line 2108-2109 tests mode & O_TRUNC and mode & O_APPEND against the raw 9P open mode byte.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-16",
   "advisory_days_public": 30,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63318.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63318",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63318",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63318"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50626",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-08-16",
    "ubuntu": "2026-08-14",
    "ubuntu-osv": "2026-08-14"
   },
   "refs": "alas:CVE-2026-50626;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-50626;ubuntu:CVE-2026-50626",
   "description": "virtio-mmio reports VIRTQUEUE_MAX_SIZE (1024) as QUEUE_NUM_MAX for every queue, regardless of the size the device passes to virtio_add_queue(). This works by accident because QEMU mostly does not care about the ring size - the guest is the one allocating memory here.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-16",
   "advisory_days_public": 30,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-50626.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50626",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-50626",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50626"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66021",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-08-15",
    "ubuntu": "2026-08-14",
    "ubuntu-osv": "2026-08-14"
   },
   "refs": "alas:CVE-2026-66021;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-66021;ubuntu:CVE-2026-66021",
   "description": "virtio_gpu_resource_create_blob() stores the guest-controlled blob_size without checking it against the total size of the iov backing entries.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-15",
   "advisory_days_public": 31,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-66021.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-66021",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-66021",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-66021"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12841",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "debian,ubuntu,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-14",
    "ubuntu-osv": "2026-08-14"
   },
   "refs": "debian:nltk;ubuntu-osv:UBUNTU-CVE-2026-12841;ubuntu:CVE-2026-12841",
   "description": "nltk",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "nltk",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-12841",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-12841",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-12841"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55156",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-14",
    "osv": "2026-08-14"
   },
   "refs": "ghsa:GHSA-76pc-mqxp-3rq5;osv:npm:@ooples/token-optimizer-mcp",
   "description": "Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@ooples/token-optimizer-mcp",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-76pc-mqxp-3rq5",
    "osv": "https://osv.dev/list?q=CVE-2026-55156"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55157",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-14",
    "osv": "2026-08-14"
   },
   "refs": "ghsa:GHSA-49mq-fc6q-3h46;osv:npm:@ooples/token-optimizer-mcp",
   "description": "Token Optimizer MCP: OS command injection in smart_user via username in get-user-info",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "@ooples/token-optimizer-mcp",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-49mq-fc6q-3h46",
    "osv": "https://osv.dev/list?q=CVE-2026-55157"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-35511",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-14",
    "osv": "2026-08-14"
   },
   "refs": "ghsa:GHSA-29rf-f4vv-pvq6;osv:Go:github.com/authorizerdev/authorizer",
   "description": "Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/authorizerdev/authorizer",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-29rf-f4vv-pvq6",
    "osv": "https://osv.dev/list?q=CVE-2026-35511"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85744",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-v8vc-cmf9-gg2c",
   "description": "freescout-help-desk/freescout repository advisory GHSA-v8vc-cmf9-gg2c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-v8vc-cmf9-gg2c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85743",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-6w8v-qp43-vg2h",
   "description": "freescout-help-desk/freescout repository advisory GHSA-6w8v-qp43-vg2h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6w8v-qp43-vg2h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85742",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:freescout-help-desk/freescout\tGHSA-2g42-f97q-973x",
   "description": "freescout-help-desk/freescout repository advisory GHSA-2g42-f97q-973x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-2g42-f97q-973x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-60008",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-7452-653r-6gp8",
   "description": "go-gitea/gitea repository advisory GHSA-7452-653r-6gp8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-60008",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7452-653r-6gp8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73278",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-92j2-6qcg-c28c",
   "description": "go-gitea/gitea repository advisory GHSA-92j2-6qcg-c28c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73278",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73535",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-8xjr-x7rg-hp5h",
   "description": "go-gitea/gitea repository advisory GHSA-8xjr-x7rg-hp5h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73535",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8xjr-x7rg-hp5h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73539",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-579w-82gf-89m2",
   "description": "go-gitea/gitea repository advisory GHSA-579w-82gf-89m2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73539",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-579w-82gf-89m2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73800",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-r9ch-mqjm-g67v",
   "description": "go-gitea/gitea repository advisory GHSA-r9ch-mqjm-g67v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73800",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-r9ch-mqjm-g67v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73804",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-q55v-4cmj-xh65",
   "description": "go-gitea/gitea repository advisory GHSA-q55v-4cmj-xh65",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73804",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-q55v-4cmj-xh65"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73814",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-14",
    "csaf": "2026-08-16"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2863\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json;ghsa-repos:go-gitea/gitea\tGHSA-h62v-wmrr-5qjq",
   "description": "go-gitea/gitea repository advisory GHSA-h62v-wmrr-5qjq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73814",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2863.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-h62v-wmrr-5qjq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85711",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:leiweibau/Pi.Alert\tGHSA-66mg-wpcq-2phq",
   "description": "leiweibau/Pi.Alert repository advisory GHSA-66mg-wpcq-2phq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/leiweibau/Pi.Alert/security/advisories/GHSA-66mg-wpcq-2phq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81884",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-c2g2-2mc7-3x5w",
   "description": "radareorg/radare2 repository advisory GHSA-c2g2-2mc7-3x5w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-c2g2-2mc7-3x5w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81883",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-96m5-hvwp-674c",
   "description": "radareorg/radare2 repository advisory GHSA-96m5-hvwp-674c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-96m5-hvwp-674c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81882",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-r5cr-f9p6-5pvj",
   "description": "radareorg/radare2 repository advisory GHSA-r5cr-f9p6-5pvj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-r5cr-f9p6-5pvj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81885",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-43wr-4j49-rcxj",
   "description": "radareorg/radare2 repository advisory GHSA-43wr-4j49-rcxj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-43wr-4j49-rcxj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81886",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-3xrx-wh64-8xr8",
   "description": "radareorg/radare2 repository advisory GHSA-3xrx-wh64-8xr8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-3xrx-wh64-8xr8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81879",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-jqfq-hvcp-xh4p",
   "description": "radareorg/radare2 repository advisory GHSA-jqfq-hvcp-xh4p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-jqfq-hvcp-xh4p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81880",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-14"
   },
   "refs": "ghsa-repos:radareorg/radare2\tGHSA-fg6f-rj8g-25pq",
   "description": "radareorg/radare2 repository advisory GHSA-fg6f-rj8g-25pq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/radareorg/radare2/security/advisories/GHSA-fg6f-rj8g-25pq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19911",
   "state": "RESERVED",
   "public_date": "2026-08-14",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-14"
   },
   "refs": "zdi:ZDI-26-526",
   "description": "ZDI advisory ZDI-26-526",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 32,
   "clock_known": true,
   "hours_public": 768,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-14",
   "advisory_days_public": 32,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-526/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77457",
   "state": "RESERVED",
   "public_date": "2026-08-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-15"
   },
   "refs": "ghsa-repos:CyclopsMC/IntegratedScripting\tGHSA-w75f-hm5x-8f6x",
   "description": "CyclopsMC/IntegratedScripting repository advisory GHSA-w75f-hm5x-8f6x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 31,
   "clock_known": true,
   "hours_public": 744,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-15",
   "advisory_days_public": 31,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CyclopsMC/IntegratedScripting/security/advisories/GHSA-w75f-hm5x-8f6x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86035",
   "state": "RESERVED",
   "public_date": "2026-08-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-15"
   },
   "refs": "ghsa-repos:WeblateOrg/weblate\tGHSA-327h-qqgm-qv55",
   "description": "WeblateOrg/weblate repository advisory GHSA-327h-qqgm-qv55",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 31,
   "clock_known": true,
   "hours_public": 744,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-15",
   "advisory_days_public": 31,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WeblateOrg/weblate/security/advisories/GHSA-327h-qqgm-qv55"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86042",
   "state": "RESERVED",
   "public_date": "2026-08-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-15"
   },
   "refs": "ghsa-repos:WeblateOrg/weblate\tGHSA-f66g-8pcg-jm8r",
   "description": "WeblateOrg/weblate repository advisory GHSA-f66g-8pcg-jm8r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 31,
   "clock_known": true,
   "hours_public": 744,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-15",
   "advisory_days_public": 31,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/WeblateOrg/weblate/security/advisories/GHSA-f66g-8pcg-jm8r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73802",
   "state": "RESERVED",
   "public_date": "2026-08-15",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-15"
   },
   "refs": "ghsa-repos:go-gitea/gitea\tGHSA-x4q3-gcj3-m6cf",
   "description": "go-gitea/gitea repository advisory GHSA-x4q3-gcj3-m6cf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 31,
   "clock_known": true,
   "hours_public": 744,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-15",
   "advisory_days_public": 31,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19720",
   "state": "RESERVED",
   "public_date": "2026-08-16",
   "sources": "alas,csaf,debian,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-08-18",
    "ubuntu": "2026-08-17",
    "ubuntu-osv": "2026-08-17",
    "csaf": "2026-08-16"
   },
   "refs": "alas:CVE-2026-19720;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2860\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2860.json;debian:inetutils;ubuntu-osv:UBUNTU-CVE-2026-19720;ubuntu:CVE-2026-19720",
   "description": "talkd buffer overflow with long DNS names (from: )",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 30,
   "clock_known": true,
   "hours_public": 720,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-16",
   "advisory_days_public": 30,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "inetutils",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-19720.html",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2860.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-19720",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-19720",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-19720"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54148",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-17",
    "osv": "2026-08-17"
   },
   "refs": "ghsa:GHSA-p28p-j94q-pg32;osv:Maven:org.http4k:http4k-security-digest",
   "description": "http4k: `DigestAuthProvider.verify` did not bind to request URI",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.http4k",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-p28p-j94q-pg32",
    "osv": "https://osv.dev/list?q=CVE-2026-54148"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54147",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-17",
    "osv": "2026-08-17"
   },
   "refs": "ghsa:GHSA-vxxm-wwqh-mh47;osv:Maven:org.http4k:http4k-security-digest",
   "description": "http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "org.http4k",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-vxxm-wwqh-mh47",
    "osv": "https://osv.dev/list?q=CVE-2026-54147"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55062",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-17",
    "osv": "2026-08-17"
   },
   "refs": "ghsa:GHSA-m6jg-wr9m-cg2f;osv:Go:gitlab.com/uniget-org/cli",
   "description": "uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitlab.com/uniget-org/cli",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-m6jg-wr9m-cg2f",
    "osv": "https://osv.dev/list?q=CVE-2026-55062"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55061",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-17",
    "osv": "2026-08-17"
   },
   "refs": "ghsa:GHSA-qmcq-xw74-w667;osv:Go:gitlab.com/uniget-org/cli",
   "description": "uniget CLI has an EDITOR Command Injection",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitlab.com/uniget-org/cli",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-qmcq-xw74-w667",
    "osv": "https://osv.dev/list?q=CVE-2026-55061"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62356",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-17",
    "csaf": "2026-08-18"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11542-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11542-1.json;ghsa-repos:RedisBloom/RedisBloom\tGHSA-q5p6-hwxh-c23h",
   "description": "RedisBloom/RedisBloom repository advisory GHSA-q5p6-hwxh-c23h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11542-1.json",
    "ghsa-repos": "https://github.com/RedisBloom/RedisBloom/security/advisories/GHSA-q5p6-hwxh-c23h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71550",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-17"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-cx24-rr7r-mxrg",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-cx24-rr7r-mxrg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-cx24-rr7r-mxrg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71548",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-17",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2870\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2870.json;ghsa-repos:SuiteCRM/SuiteCRM\tGHSA-239h-ffjr-v957",
   "description": "SuiteCRM/SuiteCRM repository advisory GHSA-239h-ffjr-v957",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2870.json",
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-239h-ffjr-v957"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71549",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-17"
   },
   "refs": "ghsa-repos:SuiteCRM/SuiteCRM-Core\tGHSA-mjjw-75gv-j5g5",
   "description": "SuiteCRM/SuiteCRM-Core repository advisory GHSA-mjjw-75gv-j5g5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/SuiteCRM/SuiteCRM-Core/security/advisories/GHSA-mjjw-75gv-j5g5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67421",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2881\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json;ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-6256-27fm-4rgr",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-6256-27fm-4rgr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json",
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67418",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2881\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json;ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-jv99-v328-mvmm",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-jv99-v328-mvmm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json",
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-jv99-v328-mvmm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67420",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2881\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json;ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-86fm-44m9-rqjx",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-86fm-44m9-rqjx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json",
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-86fm-44m9-rqjx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67419",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2881\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json;ghsa-repos:rabbitmq/rabbitmq-server\tGHSA-h964-v5mf-22cq",
   "description": "rabbitmq/rabbitmq-server repository advisory GHSA-h964-v5mf-22cq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2881.json",
    "ghsa-repos": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62365",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2883\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2883.json;ghsa-repos:wazuh/wazuh\tGHSA-whhr-gxxr-f6pm",
   "description": "wazuh/wazuh repository advisory GHSA-whhr-gxxr-f6pm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2883.json",
    "ghsa-repos": "https://github.com/wazuh/wazuh/security/advisories/GHSA-whhr-gxxr-f6pm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61811",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2883\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2883.json;ghsa-repos:wazuh/wazuh\tGHSA-9wv5-7qwx-m9w5",
   "description": "wazuh/wazuh repository advisory GHSA-9wv5-7qwx-m9w5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2883.json",
    "ghsa-repos": "https://github.com/wazuh/wazuh/security/advisories/GHSA-9wv5-7qwx-m9w5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71540",
   "state": "RESERVED",
   "public_date": "2026-08-17",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-18",
    "csaf": "2026-08-17"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2883\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2883.json;ghsa-repos:wazuh/wazuh\tGHSA-78wx-4r6w-w73f",
   "description": "wazuh/wazuh repository advisory GHSA-78wx-4r6w-w73f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 29,
   "clock_known": true,
   "hours_public": 696,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-17",
   "advisory_days_public": 29,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2883.json",
    "ghsa-repos": "https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55224",
   "state": "RESERVED",
   "public_date": "2026-08-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-18",
    "osv": "2026-08-18"
   },
   "refs": "ghsa:GHSA-59xm-4m8c-g3xj;osv:Packagist:mineadmin/mineadmin",
   "description": "MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 28,
   "clock_known": true,
   "hours_public": 672,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-18",
   "advisory_days_public": 28,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mineadmin/mineadmin",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-59xm-4m8c-g3xj",
    "osv": "https://osv.dev/list?q=CVE-2026-55224"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55107",
   "state": "RESERVED",
   "public_date": "2026-08-18",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-18",
    "osv": "2026-08-18"
   },
   "refs": "ghsa:GHSA-7pwq-q9jf-539h;osv:RubyGems:kobako",
   "description": "kobako Sandbox Escape: guest eval reaches host RCE via method_missing \u2192 public_send (any bound Service)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 28,
   "clock_known": true,
   "hours_public": 672,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-18",
   "advisory_days_public": 28,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "kobako",
   "ecosystem": "RubyGems",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-7pwq-q9jf-539h",
    "osv": "https://osv.dev/list?q=CVE-2026-55107"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85059",
   "state": "RESERVED",
   "public_date": "2026-08-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-18"
   },
   "refs": "ghsa-repos:OP-TEE/optee_os\tGHSA-4qww-fw8c-64mg",
   "description": "OP-TEE/optee_os repository advisory GHSA-4qww-fw8c-64mg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 28,
   "clock_known": true,
   "hours_public": 672,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-18",
   "advisory_days_public": 28,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-4qww-fw8c-64mg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73863",
   "state": "RESERVED",
   "public_date": "2026-08-18",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-18"
   },
   "refs": "ghsa-repos:nanomq/nanomq\tGHSA-pf97-vm7h-q84m",
   "description": "nanomq/nanomq repository advisory GHSA-pf97-vm7h-q84m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 28,
   "clock_known": true,
   "hours_public": 672,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-18",
   "advisory_days_public": 28,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/nanomq/nanomq/security/advisories/GHSA-pf97-vm7h-q84m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54689",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-19",
    "osv": "2026-08-19"
   },
   "refs": "ghsa:GHSA-wppf-h75h-6pm6;osv:npm:mcp-searxng",
   "description": "SearXNG MCP Server: Additional hardened-mode SSRF bypasses",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mcp-searxng",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-wppf-h75h-6pm6",
    "osv": "https://osv.dev/list?q=CVE-2026-54689"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54688",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-19",
    "osv": "2026-08-19"
   },
   "refs": "ghsa:GHSA-q87f-qc2r-2gw4;osv:npm:mcp-searxng",
   "description": "SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "mcp-searxng",
   "ecosystem": "npm",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-q87f-qc2r-2gw4",
    "osv": "https://osv.dev/list?q=CVE-2026-54688"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-53964",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-19",
    "osv": "2026-08-19"
   },
   "refs": "ghsa:GHSA-w47q-945m-q9pc;osv:PyPI:document-merge-service",
   "description": "Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "document-merge-service",
   "ecosystem": "PyPI",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-w47q-945m-q9pc",
    "osv": "https://osv.dev/list?q=CVE-2026-53964"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65958",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:MacWarrior/clipbucket-v5\tGHSA-3v7j-cvjp-3xcq",
   "description": "MacWarrior/clipbucket-v5 repository advisory GHSA-3v7j-cvjp-3xcq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-3v7j-cvjp-3xcq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65821",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:MacWarrior/clipbucket-v5\tGHSA-cpf6-vvpr-hg2q",
   "description": "MacWarrior/clipbucket-v5 repository advisory GHSA-cpf6-vvpr-hg2q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-cpf6-vvpr-hg2q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65823",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:MacWarrior/clipbucket-v5\tGHSA-g22r-f6qr-x24m",
   "description": "MacWarrior/clipbucket-v5 repository advisory GHSA-g22r-f6qr-x24m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-g22r-f6qr-x24m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65826",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:MacWarrior/clipbucket-v5\tGHSA-pqr6-gpv5-j9mc",
   "description": "MacWarrior/clipbucket-v5 repository advisory GHSA-pqr6-gpv5-j9mc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-pqr6-gpv5-j9mc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71418",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-xjgq-3qw4-jp5f",
   "description": "OISF/suricata repository advisory GHSA-xjgq-3qw4-jp5f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-xjgq-3qw4-jp5f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71855",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:OISF/suricata\tGHSA-fvwh-wjcq-2586",
   "description": "OISF/suricata repository advisory GHSA-fvwh-wjcq-2586",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84301",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:labring/FastGPT\tGHSA-6jwp-qf29-hpj9",
   "description": "labring/FastGPT repository advisory GHSA-6jwp-qf29-hpj9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/labring/FastGPT/security/advisories/GHSA-6jwp-qf29-hpj9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-12521",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-19"
   },
   "refs": "ghsa-repos:zephyrproject-rtos/zephyr\tGHSA-g5v9-xmfp-7gxm",
   "description": "zephyrproject-rtos/zephyr repository advisory GHSA-g5v9-xmfp-7gxm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-g5v9-xmfp-7gxm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59980",
   "state": "RESERVED",
   "public_date": "2026-08-19",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-19"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11556-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11556-1.json",
   "description": "CVE-2026-59980",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 27,
   "clock_known": true,
   "hours_public": 648,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-19",
   "advisory_days_public": 27,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11556-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73639",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "debian,ubuntu,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-20",
    "ubuntu-osv": "2026-08-20"
   },
   "refs": "debian:libimager-perl;ubuntu-osv:UBUNTU-CVE-2026-73639;ubuntu:CVE-2026-73639",
   "description": "libimager-perl",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libimager-perl",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73639",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73639",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73639"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73638",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "debian,ubuntu,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-08-20",
    "ubuntu-osv": "2026-08-20"
   },
   "refs": "debian:libimager-perl;ubuntu-osv:UBUNTU-CVE-2026-73638;ubuntu:CVE-2026-73638",
   "description": "libimager-perl",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libimager-perl",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-73638",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-73638",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-73638"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63202",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-4899-mpch-38p3;osv:Maven:io.netty.incubator:netty-incubator-codec-bhttp",
   "description": "netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.netty.incubator",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-4899-mpch-38p3",
    "osv": "https://osv.dev/list?q=CVE-2026-63202"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61827",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-hmq9-67w8-j5pw;osv:Maven:io.netty.incubator:netty-incubator-codec-bhttp",
   "description": "netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.netty.incubator",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-hmq9-67w8-j5pw",
    "osv": "https://osv.dev/list?q=CVE-2026-61827"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63124",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-8cfx-wx3q-mh5q;osv:Maven:io.netty.incubator:netty-incubator-codec-bhttp",
   "description": "netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.netty.incubator",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-8cfx-wx3q-mh5q",
    "osv": "https://osv.dev/list?q=CVE-2026-63124"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61799",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-pgrf-4654-3gq8;osv:Maven:io.netty.incubator:netty-incubator-codec-bhttp",
   "description": "netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.netty.incubator",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-pgrf-4654-3gq8",
    "osv": "https://osv.dev/list?q=CVE-2026-61799"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61798",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-2mc4-j865-9q4r;osv:Maven:io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl",
   "description": "netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.netty.incubator",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-2mc4-j865-9q4r",
    "osv": "https://osv.dev/list?q=CVE-2026-61798"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54251",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-vmr9-j6wf-pmh2;osv:Maven:io.netty.incubator:netty-incubator-codec-ohttp",
   "description": "netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "io.netty.incubator",
   "ecosystem": "Maven",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-vmr9-j6wf-pmh2",
    "osv": "https://osv.dev/list?q=CVE-2026-54251"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54162",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-20",
    "osv": "2026-08-20"
   },
   "refs": "ghsa:GHSA-x3g7-qrwc-f6c5;osv:Go:github.com/alexandre-daubois/ember",
   "description": "Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "github.com/alexandre-daubois/ember",
   "ecosystem": "Go",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-x3g7-qrwc-f6c5",
    "osv": "https://osv.dev/list?q=CVE-2026-54162"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81182",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-20"
   },
   "refs": "ghsa-repos:Syslifters/sysreptor\tGHSA-x3m3-v8pv-442r",
   "description": "Syslifters/sysreptor repository advisory GHSA-x3m3-v8pv-442r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Syslifters/sysreptor/security/advisories/GHSA-x3m3-v8pv-442r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81181",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-20"
   },
   "refs": "ghsa-repos:Syslifters/sysreptor\tGHSA-wgx3-84xg-q93j",
   "description": "Syslifters/sysreptor repository advisory GHSA-wgx3-84xg-q93j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wgx3-84xg-q93j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76898",
   "state": "RESERVED",
   "public_date": "2026-08-20",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-20"
   },
   "refs": "ghsa-repos:jgraph/drawio\tGHSA-m3q9-cwfq-hcjc",
   "description": "jgraph/drawio repository advisory GHSA-m3q9-cwfq-hcjc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 26,
   "clock_known": true,
   "hours_public": 624,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-20",
   "advisory_days_public": 26,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jgraph/drawio/security/advisories/GHSA-m3q9-cwfq-hcjc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77682",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "csaf,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-27",
    "ubuntu-osv": "2026-08-27",
    "csaf": "2026-08-21"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-77682\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-77682.json;debian:epiphany-browser;ubuntu-osv:UBUNTU-CVE-2026-77682;ubuntu:CVE-2026-77682",
   "description": "[Use a user message to trigger form autofill]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "epiphany-browser",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-77682.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-77682",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-77682",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-77682"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76899",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-21"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-x6p7-vhgp-6r3q",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-x6p7-vhgp-6r3q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-x6p7-vhgp-6r3q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76902",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-21"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-93p7-j9r5-jc7q",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-93p7-j9r5-jc7q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-93p7-j9r5-jc7q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76900",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-21"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-fg6q-pfj7-fghw",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-fg6q-pfj7-fghw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-fg6q-pfj7-fghw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76901",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-21"
   },
   "refs": "ghsa-repos:1Panel-dev/CordysCRM\tGHSA-hxp2-5w5p-2grq",
   "description": "1Panel-dev/CordysCRM repository advisory GHSA-hxp2-5w5p-2grq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-hxp2-5w5p-2grq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77617",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-21"
   },
   "refs": "ghsa-repos:dartiss/code-embed\tGHSA-qrwc-v5hh-f395",
   "description": "dartiss/code-embed repository advisory GHSA-qrwc-v5hh-f395",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/dartiss/code-embed/security/advisories/GHSA-qrwc-v5hh-f395"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76907",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-21"
   },
   "refs": "ghsa-repos:suitenumerique/docs\tGHSA-p8v2-wjj3-3j9w",
   "description": "suitenumerique/docs repository advisory GHSA-p8v2-wjj3-3j9w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/suitenumerique/docs/security/advisories/GHSA-p8v2-wjj3-3j9w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77679",
   "state": "RESERVED",
   "public_date": "2026-08-21",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-21"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-77679\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-77679.json",
   "description": "epiphany: epiphany: path traversal in WebExtension XPI extraction (ZIP slip)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 25,
   "clock_known": true,
   "hours_public": 600,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-21",
   "advisory_days_public": 25,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-77679.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16658",
   "state": "RESERVED",
   "public_date": "2026-08-22",
   "sources": "alas,csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-09-02",
    "ubuntu": "2026-09-02",
    "ubuntu-osv": "2026-09-02",
    "redhat": "2026-08-22",
    "csaf": "2026-08-22"
   },
   "refs": "alas:CVE-2026-16658;csaf:Red Hat Product Security\tCVE-2026-16658\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16658.json;debian:ansible;redhat:CVE-2026-16658;ubuntu-osv:UBUNTU-CVE-2026-16658;ubuntu:CVE-2026-16658",
   "description": "A flaw was found in the community.proxmox Ansible collection's proxmox_pct_remote connection plugin.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 24,
   "clock_known": true,
   "hours_public": 576,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-22",
   "advisory_days_public": 24,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "ansible",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-16658.html",
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16658.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-16658",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-16658",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-16658",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-16658"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-43923",
   "state": "RESERVED",
   "public_date": "2026-08-22",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-22"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11573-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11573-1.json",
   "description": "CVE-2026-43923",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 24,
   "clock_known": true,
   "hours_public": 576,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-22",
   "advisory_days_public": 24,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11573-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63630",
   "state": "RESERVED",
   "public_date": "2026-08-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-23"
   },
   "refs": "ghsa-repos:alam00000/bentopdf\tGHSA-cx8x-7rrr-r9x8",
   "description": "alam00000/bentopdf repository advisory GHSA-cx8x-7rrr-r9x8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 23,
   "clock_known": true,
   "hours_public": 552,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-23",
   "advisory_days_public": 23,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/alam00000/bentopdf/security/advisories/GHSA-cx8x-7rrr-r9x8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77581",
   "state": "RESERVED",
   "public_date": "2026-08-23",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-23"
   },
   "refs": "ghsa-repos:alam00000/bentopdf\tGHSA-5xjf-rr5x-pcfj",
   "description": "alam00000/bentopdf repository advisory GHSA-5xjf-rr5x-pcfj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 23,
   "clock_known": true,
   "hours_public": 552,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-23",
   "advisory_days_public": 23,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/alam00000/bentopdf/security/advisories/GHSA-5xjf-rr5x-pcfj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57173",
   "state": "RESERVED",
   "public_date": "2026-08-23",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-23",
    "csaf": "2026-08-23"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2975\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2975.json;ghsa-repos:vllm-project/vllm\tGHSA-hcwq-8wjf-3gcr",
   "description": "vllm-project/vllm repository advisory GHSA-hcwq-8wjf-3gcr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 23,
   "clock_known": true,
   "hours_public": 552,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-23",
   "advisory_days_public": 23,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2975.json",
    "ghsa-repos": "https://github.com/vllm-project/vllm/security/advisories/GHSA-hcwq-8wjf-3gcr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-46381",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:CloudburstMC/Network\tGHSA-f43c-g459-93vr",
   "description": "CloudburstMC/Network repository advisory GHSA-f43c-g459-93vr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CloudburstMC/Network/security/advisories/GHSA-f43c-g459-93vr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63498",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-24",
    "csaf": "2026-08-24"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2981\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2981.json;ghsa-repos:grokability/snipe-it\tGHSA-396x-xmvh-p563",
   "description": "grokability/snipe-it repository advisory GHSA-396x-xmvh-p563",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2981.json",
    "ghsa-repos": "https://github.com/grokability/snipe-it/security/advisories/GHSA-396x-xmvh-p563"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63493",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-24",
    "csaf": "2026-08-24"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2981\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2981.json;ghsa-repos:grokability/snipe-it\tGHSA-hxcx-9h4f-42xx",
   "description": "grokability/snipe-it repository advisory GHSA-hxcx-9h4f-42xx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2981.json",
    "ghsa-repos": "https://github.com/grokability/snipe-it/security/advisories/GHSA-hxcx-9h4f-42xx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62368",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-24",
    "csaf": "2026-08-24"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2981\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2981.json;ghsa-repos:grokability/snipe-it\tGHSA-p9h3-gvpq-5539",
   "description": "grokability/snipe-it repository advisory GHSA-p9h3-gvpq-5539",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2981.json",
    "ghsa-repos": "https://github.com/grokability/snipe-it/security/advisories/GHSA-p9h3-gvpq-5539"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77605",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:notepad-plus-plus/notepad-plus-plus\tGHSA-w5xq-frjg-w4cw",
   "description": "notepad-plus-plus/notepad-plus-plus repository advisory GHSA-w5xq-frjg-w4cw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-w5xq-frjg-w4cw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85279",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:notepad-plus-plus/notepad-plus-plus\tGHSA-h2wq-6x75-h8q2",
   "description": "notepad-plus-plus/notepad-plus-plus repository advisory GHSA-h2wq-6x75-h8q2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-h2wq-6x75-h8q2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86054",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:notepad-plus-plus/notepad-plus-plus\tGHSA-pxgg-96p2-c3hx",
   "description": "notepad-plus-plus/notepad-plus-plus repository advisory GHSA-pxgg-96p2-c3hx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-pxgg-96p2-c3hx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86056",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:notepad-plus-plus/notepad-plus-plus\tGHSA-j85c-6wc9-p98p",
   "description": "notepad-plus-plus/notepad-plus-plus repository advisory GHSA-j85c-6wc9-p98p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-j85c-6wc9-p98p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85288",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:notepad-plus-plus/notepad-plus-plus\tGHSA-759j-g8j4-867p",
   "description": "notepad-plus-plus/notepad-plus-plus repository advisory GHSA-759j-g8j4-867p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-759j-g8j4-867p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85995",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-24"
   },
   "refs": "ghsa-repos:notepad-plus-plus/notepad-plus-plus\tGHSA-cx87-7hhq-m2j3",
   "description": "notepad-plus-plus/notepad-plus-plus repository advisory GHSA-cx87-7hhq-m2j3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-cx87-7hhq-m2j3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19774",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-08-24",
    "zdi": "2026-08-24"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-2984\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2984.json;zdi:ZDI-26-589",
   "description": "CVE-2026-19774",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2984.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-589/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19773",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-24"
   },
   "refs": "zdi:ZDI-26-590",
   "description": "ZDI advisory ZDI-26-590",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-590/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19504",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-24"
   },
   "refs": "zdi:ZDI-26-588",
   "description": "ZDI advisory ZDI-26-588",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-588/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19781",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-24"
   },
   "refs": "zdi:ZDI-26-587",
   "description": "ZDI advisory ZDI-26-587",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-587/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19886",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-24"
   },
   "refs": "zdi:ZDI-26-586",
   "description": "ZDI advisory ZDI-26-586",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-586/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-19885",
   "state": "RESERVED",
   "public_date": "2026-08-24",
   "sources": "zdi",
   "feed_count": 1,
   "dates": {
    "zdi": "2026-08-24"
   },
   "refs": "zdi:ZDI-26-585",
   "description": "ZDI advisory ZDI-26-585",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 22,
   "clock_known": true,
   "hours_public": 528,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-24",
   "advisory_days_public": 22,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-585/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84383",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "alas,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-04",
    "ubuntu-osv": "2026-09-04",
    "ghsa-repos": "2026-08-25"
   },
   "refs": "alas:CVE-2026-84383;debian:libheif;ghsa-repos:strukturag/libheif\tGHSA-g89c-p67h-r497;ubuntu-osv:UBUNTU-CVE-2026-84383;ubuntu:CVE-2026-84383",
   "description": "GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libheif",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-84383.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-84383",
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-84383",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-84383"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59823",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-26",
    "csaf": "2026-08-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3009\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3009.json;ghsa-repos:BerriAI/litellm\tGHSA-hx8v-g79f-8w5f",
   "description": "BerriAI/litellm repository advisory GHSA-hx8v-g79f-8w5f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3009.json",
    "ghsa-repos": "https://github.com/BerriAI/litellm/security/advisories/GHSA-hx8v-g79f-8w5f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-91120",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-h7cg-2vww-m45c",
   "description": "discourse/discourse repository advisory GHSA-h7cg-2vww-m45c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-h7cg-2vww-m45c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-91122",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-8m44-f6g9-7cg7",
   "description": "discourse/discourse repository advisory GHSA-8m44-f6g9-7cg7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-8m44-f6g9-7cg7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-91121",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-34rh-wjfv-65gq",
   "description": "discourse/discourse repository advisory GHSA-34rh-wjfv-65gq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-34rh-wjfv-65gq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-91123",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-6pwj-wgg8-4rjc",
   "description": "discourse/discourse repository advisory GHSA-6pwj-wgg8-4rjc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-6pwj-wgg8-4rjc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-91119",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:discourse/discourse\tGHSA-pv3p-p3m9-v8v3",
   "description": "discourse/discourse repository advisory GHSA-pv3p-p3m9-v8v3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/discourse/discourse/security/advisories/GHSA-pv3p-p3m9-v8v3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-25946",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-25",
    "csaf": "2026-08-25"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3010\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3010.json;ghsa-repos:go-gitea/gitea\tGHSA-9574-292w-9wmw",
   "description": "go-gitea/gitea repository advisory GHSA-9574-292w-9wmw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3010.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-9574-292w-9wmw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84448",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:strukturag/libheif\tGHSA-p58j-h3vm-3fp5",
   "description": "strukturag/libheif repository advisory GHSA-p58j-h3vm-3fp5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-p58j-h3vm-3fp5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84444",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:strukturag/libheif\tGHSA-j264-xvrp-5v7q",
   "description": "strukturag/libheif repository advisory GHSA-j264-xvrp-5v7q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84384",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:strukturag/libheif\tGHSA-24wx-9w62-c96w",
   "description": "strukturag/libheif repository advisory GHSA-24wx-9w62-c96w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84446",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:strukturag/libheif\tGHSA-xw34-mjcp-jqh8",
   "description": "strukturag/libheif repository advisory GHSA-xw34-mjcp-jqh8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-xw34-mjcp-jqh8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84447",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-25"
   },
   "refs": "ghsa-repos:strukturag/libheif\tGHSA-x8xm-cm2c-cfc8",
   "description": "strukturag/libheif repository advisory GHSA-x8xm-cm2c-cfc8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-x8xm-cm2c-cfc8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-78360",
   "state": "RESERVED",
   "public_date": "2026-08-25",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-08-25",
    "csaf": "2026-08-25"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-78360\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78360.json;redhat:CVE-2026-78360",
   "description": "anitya: anitya: missing authorization check in delete_user allows any authenticated user to delete arbitrary users",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 21,
   "clock_known": true,
   "hours_public": 504,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-25",
   "advisory_days_public": 21,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-78360",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78360.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-78360"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73551",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73551;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-2w8w-rfw7-8gg4;redhat:CVE-2026-73551",
   "description": "Fixed URL normalization of dot and dot-dot path segments containing parameters, which could cause access-control components and upstream applications to interpret a request path differently.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73551",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73551.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-2w8w-rfw7-8gg4",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73551"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73513",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73513;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-jjmm-fw8p-crpw;redhat:CVE-2026-73513",
   "description": "Fixed a heap use-after-free where an untrusted upstream could send HTTP/2 response trailers without the END_STREAM flag to an Envoy instance using oghttp2, corrupting stream state and terminating the process.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73513",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73513.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-jjmm-fw8p-crpw",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73513"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50572",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-50572;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-q8wp-gf7q-m8cv;redhat:CVE-2026-50572",
   "description": "Fixed a use-after-free in the ext_authz raw HTTP client where completing an authorization request could destroy the client while its completion handler was still executing.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-50572",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-50572.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-q8wp-gf7q-m8cv",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-50572"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73548",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73548;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-3vhp-c83q-jqc2;redhat:CVE-2026-73548",
   "description": "Fixed cross-user response poisoning involving generic, non-WebSocket HTTP upgrades, where request payload sent before an upgrade was accepted could contaminate a shared upstream connection.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73548",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73548.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-3vhp-c83q-jqc2",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73548"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73550",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73550;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-qgf6-qvhw-4hvh;redhat:CVE-2026-73550",
   "description": "Fixed an HTTP/2 memory-exhaustion issue where discarded duplicate Host headers were not counted toward request-header size and count limits.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73550",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73550.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-qgf6-qvhw-4hvh",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73550"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73549",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73549;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-jp5f-qr64-c9vw;redhat:CVE-2026-73549",
   "description": "Fixed an abnormal process termination for scoped IPv6 client addresses in original DST clusters with HTTP/3.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73549",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73549.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-jp5f-qr64-c9vw",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73549"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48521",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-48521;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-5vff-j9p4-38j3;redhat:CVE-2026-48521",
   "description": "An Envoy proxy handling HTTP/3 connections can dereference a null transport socket option during the selection of a connection pool.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-48521",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-48521.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-5vff-j9p4-38j3",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-48521"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73512",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73512;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-r6j2-mrm5-72mg;redhat:CVE-2026-73512",
   "description": "Fixed a use-after-free in the QUIC HTTP datagram handler where late HTTP/3 datagrams could reference a stream decoder that was already destroyed or replaced.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73512",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73512.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-r6j2-mrm5-72mg",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73512"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73511",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73511;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-m745-gh6x-349x;redhat:CVE-2026-73511",
   "description": "Fixed path matching for paths containing per-segment parameters, where Envoy and backends could select different resources for the same request and bypass path-based selection or authentication.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73511",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73511.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-m745-gh6x-349x",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73511"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73553",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73553;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-77x5-xqjg-hprq;redhat:CVE-2026-73553",
   "description": "Fixed an authorization bypass when ignore_path_parameters_in_path_matching was enabled, where a path such as /admin;x could bypass an RBAC policy for /admin while still reaching the protected route.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73553",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73553.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-77x5-xqjg-hprq",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73553"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73546",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73546;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-pv9h-4fxf-7vrg;redhat:CVE-2026-73546",
   "description": "Fixed a stored cross-site scripting issue in the HTML stats interface (/stats?format=html) where dynamically named statistics could introduce attacker-controlled content.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73546",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73546.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-pv9h-4fxf-7vrg",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73546"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73547",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73547;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-87ph-jqwm-pg6r;redhat:CVE-2026-73547",
   "description": "Fixed an abnormal process termination in the ext_authz filter when processing CONNECT requests without a :path pseudo-header.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73547",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73547.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-87ph-jqwm-pg6r",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73547"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73552",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "alas,csaf,ghsa-repos,redhat",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-08",
    "ghsa-repos": "2026-08-26",
    "redhat": "2026-08-26",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-73552;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11630-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json;ghsa-repos:envoyproxy/envoy\tGHSA-23xh-2qxr-3xv8;redhat:CVE-2026-73552",
   "description": "Fixed an issue where safe_regex matching treated accepted non-UTF-8 HTTP header bytes as a non-match; in RBAC policies using negative matching this could fail open and allow access to a protected resource.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-73552",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-73552.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11630-1.json",
    "ghsa-repos": "https://github.com/envoyproxy/envoy/security/advisories/GHSA-23xh-2qxr-3xv8",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-73552"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-44701",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "ghsa,osv",
   "feed_count": 2,
   "dates": {
    "ghsa": "2026-08-26",
    "osv": "2026-08-26"
   },
   "refs": "ghsa:GHSA-crx4-7mmq-j74j;osv:Packagist:devcode-it/openstamanager",
   "description": "OpenSTAManager has HTML Injection in modules/utenti/edit.php",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "devcode-it/openstamanager",
   "ecosystem": "Packagist",
   "source_urls": {
    "ghsa": "https://github.com/advisories/GHSA-crx4-7mmq-j74j",
    "osv": "https://osv.dev/list?q=CVE-2026-44701"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76821",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-26",
    "csaf": "2026-08-26"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3055\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3055.json;ghsa-repos:OpenCTI-Platform/opencti\tGHSA-7g3x-wc2m-9h9x",
   "description": "OpenCTI-Platform/opencti repository advisory GHSA-7g3x-wc2m-9h9x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3055.json",
    "ghsa-repos": "https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-7g3x-wc2m-9h9x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69132",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-26"
   },
   "refs": "ghsa-repos:fedify-dev/fedify\tGHSA-fx98-wc5v-jrg5",
   "description": "fedify-dev/fedify repository advisory GHSA-fx98-wc5v-jrg5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/fedify-dev/fedify/security/advisories/GHSA-fx98-wc5v-jrg5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77632",
   "state": "RESERVED",
   "public_date": "2026-08-26",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-26"
   },
   "refs": "ghsa-repos:fedify-dev/fedify\tGHSA-cxc3-7q96-6cpx",
   "description": "fedify-dev/fedify repository advisory GHSA-cxc3-7q96-6cpx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 20,
   "clock_known": true,
   "hours_public": 480,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-26",
   "advisory_days_public": 20,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/fedify-dev/fedify/security/advisories/GHSA-cxc3-7q96-6cpx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59944",
   "state": "RESERVED",
   "public_date": "2026-08-27",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-08-27",
    "csaf": "2026-08-28"
   },
   "refs": "alas:CVE-2026-59944;csaf:SUSE Product Security Team\topenSUSE-SU-2026:11633-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11633-1.json;debian:composer;ghsa-repos:composer/composer\tGHSA-96h3-5x6v-m776;ubuntu-osv:UBUNTU-CVE-2026-599",
   "description": "Package bin path can escape the package directory, bypassing the GHSA-gjfg-22fp-rrxx fix.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 19,
   "clock_known": true,
   "hours_public": 456,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-27",
   "advisory_days_public": 19,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "composer",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-59944.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11633-1.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-59944",
    "ghsa-repos": "https://github.com/composer/composer/security/advisories/GHSA-96h3-5x6v-m776",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-59944",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-59944"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81501",
   "state": "RESERVED",
   "public_date": "2026-08-27",
   "sources": "alpine,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-08-27"
   },
   "refs": "alpine:incus-feature;debian:incus;ghsa-repos:lxc/incus\tGHSA-c6wx-8679-hpr9;ubuntu-osv:UBUNTU-CVE-2026-81501;ubuntu:CVE-2026-81501",
   "description": "incus-feature",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 19,
   "clock_known": true,
   "hours_public": 456,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-27",
   "advisory_days_public": 19,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus-feature",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-81501",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81501",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-c6wx-8679-hpr9",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81501",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81501"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81500",
   "state": "RESERVED",
   "public_date": "2026-08-27",
   "sources": "alpine,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "ghsa-repos": "2026-08-27"
   },
   "refs": "alpine:incus-feature;debian:incus;ghsa-repos:lxc/incus\tGHSA-9pqw-c7m4-xvg7;ubuntu-osv:UBUNTU-CVE-2026-81500;ubuntu:CVE-2026-81500",
   "description": "incus-feature",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 19,
   "clock_known": true,
   "hours_public": 456,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-27",
   "advisory_days_public": 19,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "incus-feature",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-81500",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-81500",
    "ghsa-repos": "https://github.com/lxc/incus/security/advisories/GHSA-9pqw-c7m4-xvg7",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-81500",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-81500"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84985",
   "state": "RESERVED",
   "public_date": "2026-08-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-27"
   },
   "refs": "ghsa-repos:ckan/ckan\tGHSA-p5rh-49m9-56vx",
   "description": "ckan/ckan repository advisory GHSA-p5rh-49m9-56vx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 19,
   "clock_known": true,
   "hours_public": 456,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-27",
   "advisory_days_public": 19,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ckan/ckan/security/advisories/GHSA-p5rh-49m9-56vx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84986",
   "state": "RESERVED",
   "public_date": "2026-08-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-27"
   },
   "refs": "ghsa-repos:ckan/ckan\tGHSA-jgwg-vp4m-5xw5",
   "description": "ckan/ckan repository advisory GHSA-jgwg-vp4m-5xw5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 19,
   "clock_known": true,
   "hours_public": 456,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-27",
   "advisory_days_public": 19,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/ckan/ckan/security/advisories/GHSA-jgwg-vp4m-5xw5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69182",
   "state": "RESERVED",
   "public_date": "2026-08-27",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-27"
   },
   "refs": "ghsa-repos:gunet/openeclass\tGHSA-chpp-rhg9-4h48",
   "description": "gunet/openeclass repository advisory GHSA-chpp-rhg9-4h48",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 19,
   "clock_known": true,
   "hours_public": 456,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-27",
   "advisory_days_public": 19,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/gunet/openeclass/security/advisories/GHSA-chpp-rhg9-4h48"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-88064",
   "state": "RESERVED",
   "public_date": "2026-08-28",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-28"
   },
   "refs": "ghsa-repos:backstage/backstage\tGHSA-292q-8mf5-h6g3",
   "description": "backstage/backstage repository advisory GHSA-292q-8mf5-h6g3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 18,
   "clock_known": true,
   "hours_public": 432,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-28",
   "advisory_days_public": 18,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/backstage/backstage/security/advisories/GHSA-292q-8mf5-h6g3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69147",
   "state": "RESERVED",
   "public_date": "2026-08-28",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-08-28",
    "csaf": "2026-08-30"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3083\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3083.json;ghsa-repos:vllm-project/vllm\tGHSA-8pw2-6jv3-mj5j",
   "description": "vllm-project/vllm repository advisory GHSA-8pw2-6jv3-mj5j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 18,
   "clock_known": true,
   "hours_public": 432,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-28",
   "advisory_days_public": 18,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3083.json",
    "ghsa-repos": "https://github.com/vllm-project/vllm/security/advisories/GHSA-8pw2-6jv3-mj5j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-88003",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-29"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-25xj-pj36-wpp8",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-25xj-pj36-wpp8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-25xj-pj36-wpp8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70396",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-hxhc-246f-rvqc",
   "description": "go-gitea/gitea repository advisory GHSA-hxhc-246f-rvqc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-70396",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-hxhc-246f-rvqc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70400",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-x58h-3mx5-q44r",
   "description": "go-gitea/gitea repository advisory GHSA-x58h-3mx5-q44r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-70400",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-x58h-3mx5-q44r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70402",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-pq8x-xpgp-rvmh",
   "description": "go-gitea/gitea repository advisory GHSA-pq8x-xpgp-rvmh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-70402",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-pq8x-xpgp-rvmh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70407",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-ww9q-7j5q-hrv5",
   "description": "go-gitea/gitea repository advisory GHSA-ww9q-7j5q-hrv5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-70407",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-ww9q-7j5q-hrv5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71184",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-7w2r-xwp6-mh6c",
   "description": "go-gitea/gitea repository advisory GHSA-7w2r-xwp6-mh6c",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-71184",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7w2r-xwp6-mh6c"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71301",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-5w72-2mqm-qh46",
   "description": "go-gitea/gitea repository advisory GHSA-5w72-2mqm-qh46",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-71301",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-5w72-2mqm-qh46"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73504",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-f8ph-p9p5-vg2p",
   "description": "go-gitea/gitea repository advisory GHSA-f8ph-p9p5-vg2p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73504",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-f8ph-p9p5-vg2p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73126",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-r96c-jc75-rxv6",
   "description": "go-gitea/gitea repository advisory GHSA-r96c-jc75-rxv6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73126",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-r96c-jc75-rxv6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73130",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-8r3w-5682-jrqf",
   "description": "go-gitea/gitea repository advisory GHSA-8r3w-5682-jrqf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73130",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8r3w-5682-jrqf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73135",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-hch4-r2j8-xm72",
   "description": "go-gitea/gitea repository advisory GHSA-hch4-r2j8-xm72",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73135",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-hch4-r2j8-xm72"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73273",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-5xcq-p92v-43rf",
   "description": "go-gitea/gitea repository advisory GHSA-5xcq-p92v-43rf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-73273",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-5xcq-p92v-43rf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-60010",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-g5jj-gp8w-73h7",
   "description": "go-gitea/gitea repository advisory GHSA-g5jj-gp8w-73h7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-60010",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-g5jj-gp8w-73h7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-60018",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-46px-6cqx-c5fv",
   "description": "go-gitea/gitea repository advisory GHSA-46px-6cqx-c5fv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-60018",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-46px-6cqx-c5fv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-60021",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-5952-x23q-p23f",
   "description": "go-gitea/gitea repository advisory GHSA-5952-x23q-p23f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-60021",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-5952-x23q-p23f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62925",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-36q5-5423-vgx2",
   "description": "go-gitea/gitea repository advisory GHSA-36q5-5423-vgx2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-62925",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-36q5-5423-vgx2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63021",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-fqxf-w92m-prvq",
   "description": "go-gitea/gitea repository advisory GHSA-fqxf-w92m-prvq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-63021",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fqxf-w92m-prvq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63792",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-2xph-7j4g-43rg",
   "description": "go-gitea/gitea repository advisory GHSA-2xph-7j4g-43rg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-63792",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2xph-7j4g-43rg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66849",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-px3q-x2mm-55wg",
   "description": "go-gitea/gitea repository advisory GHSA-px3q-x2mm-55wg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-66849",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-px3q-x2mm-55wg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66853",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-w4wc-g858-3672",
   "description": "go-gitea/gitea repository advisory GHSA-w4wc-g858-3672",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-66853",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-w4wc-g858-3672"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66874",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-5xp7-r6cr-39ff",
   "description": "go-gitea/gitea repository advisory GHSA-5xp7-r6cr-39ff",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-66874",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-5xp7-r6cr-39ff"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66877",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-v2w8-m4gr-qj65",
   "description": "go-gitea/gitea repository advisory GHSA-v2w8-m4gr-qj65",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-66877",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-v2w8-m4gr-qj65"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-67577",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-rfm6-r2x5-cg56",
   "description": "go-gitea/gitea repository advisory GHSA-rfm6-r2x5-cg56",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-67577",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-rfm6-r2x5-cg56"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68957",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-wg93-gp4m-c6vr",
   "description": "go-gitea/gitea repository advisory GHSA-wg93-gp4m-c6vr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-68957",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-wg93-gp4m-c6vr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68964",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-wwmh-7r9x-fg49",
   "description": "go-gitea/gitea repository advisory GHSA-wwmh-7r9x-fg49",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-68964",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-wwmh-7r9x-fg49"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-78433",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "alpine,csaf,ghsa-repos",
   "feed_count": 3,
   "dates": {
    "ghsa-repos": "2026-08-29",
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json;ghsa-repos:go-gitea/gitea\tGHSA-frpv-2xgv-wxpq",
   "description": "go-gitea/gitea repository advisory GHSA-frpv-2xgv-wxpq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-78433",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
    "ghsa-repos": "https://github.com/go-gitea/gitea/security/advisories/GHSA-frpv-2xgv-wxpq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83822",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-29"
   },
   "refs": "ghsa-repos:roxy-wi/roxy-wi\tGHSA-hp23-3cx2-4h2r",
   "description": "roxy-wi/roxy-wi repository advisory GHSA-hp23-3cx2-4h2r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-hp23-3cx2-4h2r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83821",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-29"
   },
   "refs": "ghsa-repos:roxy-wi/roxy-wi\tGHSA-9xc3-25r9-425m",
   "description": "roxy-wi/roxy-wi repository advisory GHSA-9xc3-25r9-425m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-9xc3-25r9-425m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83818",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-29"
   },
   "refs": "ghsa-repos:roxy-wi/roxy-wi\tGHSA-5hgx-fmqx-rcg8",
   "description": "roxy-wi/roxy-wi repository advisory GHSA-5hgx-fmqx-rcg8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-5hgx-fmqx-rcg8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83819",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-29"
   },
   "refs": "ghsa-repos:roxy-wi/roxy-wi\tGHSA-3wqc-vcrv-gfgr",
   "description": "roxy-wi/roxy-wi repository advisory GHSA-3wqc-vcrv-gfgr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-3wqc-vcrv-gfgr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83820",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-29"
   },
   "refs": "ghsa-repos:roxy-wi/roxy-wi\tGHSA-3886-rcwf-vqjh",
   "description": "roxy-wi/roxy-wi repository advisory GHSA-3886-rcwf-vqjh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-3886-rcwf-vqjh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55543",
   "state": "RESERVED",
   "public_date": "2026-08-29",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-29"
   },
   "refs": "csaf:SUSE Product Security Team\topenSUSE-SU-2026:11645-1\thttps://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11645-1.json",
   "description": "CVE-2026-55543",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 17,
   "clock_known": true,
   "hours_public": 408,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-29",
   "advisory_days_public": 17,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11645-1.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49275",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "alas,alpine,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 7,
   "dates": {
    "alas": "2026-09-08",
    "ubuntu": "2026-09-07",
    "ubuntu-osv": "2026-09-07",
    "ghsa-repos": "2026-08-30",
    "csaf": "2026-08-31"
   },
   "refs": "alas:CVE-2026-49275;alpine:exiv2;csaf:SUSE Product Security Team\tCVE-2026-49275\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-49275.json;debian:exiv2;ghsa-repos:Exiv2/exiv2\tGHSA-hxph-pv7w-8649;ubuntu-osv:UBUNTU-CVE-2026-49275;ubuntu:CV",
   "description": "Out of bounds read in CrwMap::decodeBasic",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "exiv2",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-49275.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-49275",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-49275.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-49275",
    "ghsa-repos": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-49275",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-49275"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68547",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "alas,alpine,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 7,
   "dates": {
    "alas": "2026-09-08",
    "ubuntu": "2026-09-07",
    "ubuntu-osv": "2026-09-07",
    "ghsa-repos": "2026-08-30",
    "csaf": "2026-08-31"
   },
   "refs": "alas:CVE-2026-68547;alpine:exiv2;csaf:SUSE Product Security Team\tCVE-2026-68547\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-68547.json;debian:exiv2;ghsa-repos:Exiv2/exiv2\tGHSA-jcgh-p9v3-pw6j;ubuntu-osv:UBUNTU-CVE-2026-68547;ubuntu:CV",
   "description": "Heap out-of-bounds read in RemoteIo when reading block-aligned remote CRW files",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "exiv2",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-68547.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-68547",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-68547.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-68547",
    "ghsa-repos": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-68547",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-68547"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-68546",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "alas,alpine,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 7,
   "dates": {
    "alas": "2026-09-08",
    "ubuntu": "2026-09-07",
    "ubuntu-osv": "2026-09-07",
    "ghsa-repos": "2026-08-30",
    "csaf": "2026-08-31"
   },
   "refs": "alas:CVE-2026-68546;alpine:exiv2;csaf:SUSE Product Security Team\tCVE-2026-68546\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-68546.json;debian:exiv2;ghsa-repos:Exiv2/exiv2\tGHSA-3695-mjv8-3r52;ubuntu-osv:UBUNTU-CVE-2026-68546;ubuntu:CV",
   "description": "Heap out-of-bounds write in RemoteIo when reading from a malicious remote server (WebReady/Curl builds)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "exiv2",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-68546.html",
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-68546",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-68546.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-68546",
    "ghsa-repos": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-68546",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-68546"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-62984",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-30"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-x6gc-5g5m-hm3r",
   "description": "chamilo/chamilo-lms repository advisory GHSA-x6gc-5g5m-hm3r",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-x6gc-5g5m-hm3r"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70649",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-30"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-jvrf-c7q2-qghg",
   "description": "chamilo/chamilo-lms repository advisory GHSA-jvrf-c7q2-qghg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-jvrf-c7q2-qghg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70648",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-30"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-x63q-6gqg-qr8p",
   "description": "chamilo/chamilo-lms repository advisory GHSA-x63q-6gqg-qr8p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-x63q-6gqg-qr8p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70647",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-30"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-g5xh-m3w7-jmcq",
   "description": "chamilo/chamilo-lms repository advisory GHSA-g5xh-m3w7-jmcq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-g5xh-m3w7-jmcq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77478",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-30"
   },
   "refs": "ghsa-repos:containers/fuse-overlayfs\tGHSA-33p3-j627-gwr3",
   "description": "containers/fuse-overlayfs repository advisory GHSA-33p3-j627-gwr3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-33p3-j627-gwr3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-70406",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-08-30"
   },
   "refs": "alpine:gitea;csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3079\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json",
   "description": "CVE-2026-70406",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gitea",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-70406",
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3079.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-26504",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-30"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3097\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3097.json",
   "description": "CVE-2025-26504",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3097.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-14521",
   "state": "RESERVED",
   "public_date": "2026-08-30",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-08-30"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3098\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3098.json",
   "description": "CVE-2026-14521",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 16,
   "clock_known": true,
   "hours_public": 384,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-30",
   "advisory_days_public": 16,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3098.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-17516",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-02",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-17516;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-17516;ubuntu:CVE-2026-17516",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-17516.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-17516",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-17516",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-17516"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-15264",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-15264;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-15264;ubuntu:CVE-2026-15264",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-15264.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-15264",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-15264",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-15264"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18054",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-18054;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-18054;ubuntu:CVE-2026-18054",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-18054.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-18054",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-18054",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-18054"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63109",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-63109;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63109;ubuntu:CVE-2026-63109",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63109.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63109",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63109",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63109"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65928",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-65928;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-65928;ubuntu:CVE-2026-65928",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65928.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65928",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65928",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65928"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16288",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-16288;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-16288;ubuntu:CVE-2026-16288",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-16288.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-16288",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-16288",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-16288"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61476",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-61476;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-61476;ubuntu:CVE-2026-61476",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61476.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61476",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61476",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61476"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-50624",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-50624;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-50624;ubuntu:CVE-2026-50624",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-50624.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-50624",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-50624",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-50624"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58582",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-58582;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-58582;ubuntu:CVE-2026-58582",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58582.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58582",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-58582",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58582"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61402",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-61402;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-61402;ubuntu:CVE-2026-61402",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61402.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61402",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61402",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61402"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61405",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-61405;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-61405;ubuntu:CVE-2026-61405",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61405.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61405",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61405",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61405"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63320",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-63320;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63320;ubuntu:CVE-2026-63320",
   "description": "Host-side AddressSanitizer heap-buffer-overflow READ in current QEMU master through the virtio-net-pci receive filtering path on q35.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63320.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63320",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63320",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63320"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63321",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-63321;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63321;ubuntu:CVE-2026-63321",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63321.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63321",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63321",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63321"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61406",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-61406;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-61406;ubuntu:CVE-2026-61406",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61406.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61406",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61406",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61406"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63323",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-63323;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63323;ubuntu:CVE-2026-63323",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63323.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63323",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63323",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63323"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61404",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-61404;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-61404;ubuntu:CVE-2026-61404",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-61404.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-61404",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-61404",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-61404"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63110",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-63110;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63110;ubuntu:CVE-2026-63110",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63110.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63110",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63110",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63110"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58581",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-58581;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-58581;ubuntu:CVE-2026-58581",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-58581.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-58581",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-58581",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-58581"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65929",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-65929;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-65929;ubuntu:CVE-2026-65929",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65929.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65929",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65929",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65929"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66022",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-66022;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-66022;ubuntu:CVE-2026-66022",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-66022.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-66022",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-66022",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-66022"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63322",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-01",
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31"
   },
   "refs": "alas:CVE-2026-63322;debian:qemu;ubuntu-osv:UBUNTU-CVE-2026-63322;ubuntu:CVE-2026-63322",
   "description": "qemu",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "qemu",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-63322.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-63322",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-63322",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-63322"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-80220",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-02",
    "ubuntu-osv": "2026-09-02",
    "redhat": "2026-08-31",
    "csaf": "2026-09-03"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2026-80220\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-80220.json;debian:prometheus-postgres-exporter;redhat:CVE-2026-80220;ubuntu-osv:UBUNTU-CVE-2026-80220;ubuntu:CVE-2026-80220",
   "description": "prometheus-postgres-exporter",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "prometheus-postgres-exporter",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-80220.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-80220",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-80220",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-80220",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-80220"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-70292",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "csaf": "2026-09-01"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2025-70292\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2025-70292.json;debian:u-boot;ubuntu-osv:UBUNTU-CVE-2025-70292;ubuntu:CVE-2025-70292",
   "description": "u-boot",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "u-boot",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2025-70292.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2025-70292",
    "ubuntu": "https://ubuntu.com/security/CVE-2025-70292",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2025-70292"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-70291",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-08-31",
    "ubuntu-osv": "2026-08-31",
    "csaf": "2026-09-01"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2025-70291\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2025-70291.json;debian:u-boot;ubuntu-osv:UBUNTU-CVE-2025-70291;ubuntu:CVE-2025-70291",
   "description": "u-boot",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "u-boot",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2025-70291.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2025-70291",
    "ubuntu": "https://ubuntu.com/security/CVE-2025-70291",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2025-70291"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-54790",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-vv4r-cgmw-w6x2",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-vv4r-cgmw-w6x2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-vv4r-cgmw-w6x2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81185",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:MasaCMS/MasaCMS\tGHSA-x8cf-65cx-7pcp",
   "description": "MasaCMS/MasaCMS repository advisory GHSA-x8cf-65cx-7pcp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-x8cf-65cx-7pcp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81186",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:MasaCMS/MasaCMS\tGHSA-2686-mxpg-p7xx",
   "description": "MasaCMS/MasaCMS repository advisory GHSA-2686-mxpg-p7xx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-2686-mxpg-p7xx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81189",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:MasaCMS/MasaCMS\tGHSA-hxq8-42mv-9gjf",
   "description": "MasaCMS/MasaCMS repository advisory GHSA-hxq8-42mv-9gjf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-hxq8-42mv-9gjf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81188",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:MasaCMS/MasaCMS\tGHSA-gf5m-hwmv-w22x",
   "description": "MasaCMS/MasaCMS repository advisory GHSA-gf5m-hwmv-w22x",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-gf5m-hwmv-w22x"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81187",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:MasaCMS/MasaCMS\tGHSA-w46m-3w6f-v7m2",
   "description": "MasaCMS/MasaCMS repository advisory GHSA-w46m-3w6f-v7m2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-w46m-3w6f-v7m2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-82399",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-09-01",
    "csaf": "2026-08-31"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3104\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3104.json;ghsa-repos:coredns/coredns\tGHSA-mrg3-qvqr-jw29",
   "description": "coredns/coredns repository advisory GHSA-mrg3-qvqr-jw29",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3104.json",
    "ghsa-repos": "https://github.com/coredns/coredns/security/advisories/GHSA-mrg3-qvqr-jw29"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81876",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:hapifhir/org.hl7.fhir.core\tGHSA-gq9c-wmrm-5hvr",
   "description": "hapifhir/org.hl7.fhir.core repository advisory GHSA-gq9c-wmrm-5hvr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-gq9c-wmrm-5hvr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81875",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:hapifhir/org.hl7.fhir.core\tGHSA-3w98-rrpr-fprr",
   "description": "hapifhir/org.hl7.fhir.core repository advisory GHSA-3w98-rrpr-fprr",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-3w98-rrpr-fprr"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73972",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:music-assistant/server\tGHSA-m6c2-h3pf-84q7",
   "description": "music-assistant/server repository advisory GHSA-m6c2-h3pf-84q7",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/music-assistant/server/security/advisories/GHSA-m6c2-h3pf-84q7"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-73970",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-08-31"
   },
   "refs": "ghsa-repos:music-assistant/server\tGHSA-j369-4c4w-7qmq",
   "description": "music-assistant/server repository advisory GHSA-j369-4c4w-7qmq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/music-assistant/server/security/advisories/GHSA-j369-4c4w-7qmq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83589",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-08-31",
    "csaf": "2026-08-31"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-83589\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-83589.json;redhat:CVE-2026-83589",
   "description": "oauth-proxy: Open Redirect via /\\ and /\\t Bypass in Post-Login Redirect",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-83589",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-83589.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-83589"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-75762",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-08-31",
    "csaf": "2026-08-31"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-75762\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75762.json;redhat:CVE-2026-75762",
   "description": "multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-75762",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75762.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-75762"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77849",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-08-31",
    "csaf": "2026-08-31"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-77849\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-77849.json;redhat:CVE-2026-77849",
   "description": "grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in `pkg/specsyncer`",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-77849",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-77849.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-77849"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-80221",
   "state": "RESERVED",
   "public_date": "2026-08-31",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-08-31",
    "csaf": "2026-08-31"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-80221\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80221.json;redhat:CVE-2026-80221",
   "description": "grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 15,
   "clock_known": true,
   "hours_public": 360,
   "clock_origin": "advisory",
   "advisory_date": "2026-08-31",
   "advisory_days_public": 15,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-80221",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80221.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-80221"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84450",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-04",
    "ubuntu-osv": "2026-09-04",
    "ghsa-repos": "2026-09-01",
    "csaf": "2026-09-10"
   },
   "refs": "alas:CVE-2026-84450;csaf:SUSE Product Security Team\tCVE-2026-84450\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-84450.json;debian:libheif;ghsa-repos:strukturag/libheif\tGHSA-gh5q-69gg-c964;ubuntu-osv:UBUNTU-CVE-2026-84450;ubuntu:CVE-20",
   "description": "Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libheif",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-84450.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-84450.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-84450",
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-gh5q-69gg-c964",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-84450",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-84450"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84451",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "alas,csaf,debian,ghsa-repos,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-04",
    "ubuntu-osv": "2026-09-04",
    "ghsa-repos": "2026-09-01",
    "csaf": "2026-09-10"
   },
   "refs": "alas:CVE-2026-84451;csaf:SUSE Product Security Team\tCVE-2026-84451\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-84451.json;debian:libheif;ghsa-repos:strukturag/libheif\tGHSA-hh47-fhqr-cj2r;ubuntu-osv:UBUNTU-CVE-2026-84451;ubuntu:CVE-20",
   "description": "Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "libheif",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-84451.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-84451.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-84451",
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-hh47-fhqr-cj2r",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-84451",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-84451"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81877",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:chamilo/chamilo-lms\tGHSA-cxxm-wpv8-fwh9",
   "description": "chamilo/chamilo-lms repository advisory GHSA-cxxm-wpv8-fwh9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-cxxm-wpv8-fwh9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81503",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:contiki-ng/contiki-ng\tGHSA-fm37-p9mr-558p",
   "description": "contiki-ng/contiki-ng repository advisory GHSA-fm37-p9mr-558p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-fm37-p9mr-558p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77286",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:contiki-ng/contiki-ng\tGHSA-7jvc-x6mf-f3vq",
   "description": "contiki-ng/contiki-ng repository advisory GHSA-7jvc-x6mf-f3vq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-7jvc-x6mf-f3vq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63203",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:logto-io/logto\tGHSA-6g9q-qrx7-3jxf",
   "description": "logto-io/logto repository advisory GHSA-6g9q-qrx7-3jxf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/logto-io/logto/security/advisories/GHSA-6g9q-qrx7-3jxf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56739",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:logto-io/logto\tGHSA-3556-624q-c5w3",
   "description": "logto-io/logto repository advisory GHSA-3556-624q-c5w3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/logto-io/logto/security/advisories/GHSA-3556-624q-c5w3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48057",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:randombit/botan\tGHSA-3mh2-26h4-wrqc",
   "description": "randombit/botan repository advisory GHSA-3mh2-26h4-wrqc",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/randombit/botan/security/advisories/GHSA-3mh2-26h4-wrqc"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84449",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:strukturag/libheif\tGHSA-2c3g-p585-8rpq",
   "description": "strukturag/libheif repository advisory GHSA-2c3g-p585-8rpq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/strukturag/libheif/security/advisories/GHSA-2c3g-p585-8rpq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-18944",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-01"
   },
   "refs": "ghsa-repos:wp-graphql/wp-graphql\tGHSA-7922-x8p4-55p9",
   "description": "wp-graphql/wp-graphql repository advisory GHSA-7922-x8p4-55p9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-7922-x8p4-55p9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45529",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-09-01",
    "csaf": "2026-09-08",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;osv:Android:platform/packages/providers/TelephonyProvider;samsung:SMR-Sep-2026",
   "description": "In queryInternal of MmsSmsProvider.java, there is a possible way to access MMS/SMS data across user profiles due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/packages/providers/TelephonyProvider",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "osv": "https://osv.dev/list?q=CVE-2026-45529",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-45517",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-09-01",
    "csaf": "2026-09-08",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;osv:Android:platform/packages/providers/MediaProvider;samsung:SMR-Sep-2026",
   "description": "In screenArgsForPermissionCheckIfAny of MediaQueryForPreSelection.java, there is a possible way to access the images of other users due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/packages/providers/MediaProvider",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "osv": "https://osv.dev/list?q=CVE-2026-45517",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49913",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-09-01",
    "csaf": "2026-09-08",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;osv:Android:platform/hardware/interfaces;samsung:SMR-Sep-2026",
   "description": "In descramble of DescramblerImpl.cpp, there is a possible arbitrary memory access due to a precondition check failure.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/hardware/interfaces",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "osv": "https://osv.dev/list?q=CVE-2026-49913",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-49926",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,osv,samsung",
   "feed_count": 3,
   "dates": {
    "osv": "2026-09-01",
    "csaf": "2026-09-08",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;osv:Android:platform/external/libjxl;samsung:SMR-Sep-2026",
   "description": "In libjxl, there is a possible denial of service due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "platform/external/libjxl",
   "ecosystem": "Android",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "osv": "https://osv.dev/list?q=CVE-2026-49926",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55331",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55331"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55366",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55366"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0200",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0200"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56882",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible information disclosure due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56882"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57008",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Modem, there is a possible information disclosure due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-57008"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55305",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible information disclosure due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55305"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58683",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58683"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0159",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0159"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57012",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In the Setup Wizard, there is a possible remote package install due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-57012"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58704",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58704"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56967",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56967"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56975",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible denial of service due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56975"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56914",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible use-after-free due to improper locking.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56914"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56974",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56974"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55343",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55343"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55306",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Cellular Modem, there is a possible denial of service due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55306"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56941",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56941"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58773",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58773"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56986",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple files, there is a possible out-of-bounds read due to type confusion.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56986"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56985",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple files, there is a possible way to obtain signatures due to type confusion.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56985"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56992",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple files, there is a possible permission bypass due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56992"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57006",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In acfw_ffa.c, there is a possible secret read due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-57006"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0171",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0171"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0170",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0170"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56960",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible use-after-free due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56960"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56915",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56915"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58699",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58699"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56942",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56942"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56964",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible use-after-free due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56964"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56973",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56973"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58734",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58734"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56896",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In SatelliteDatagramReceivedBuilder::Build of satellitedatabuilder.cpp, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56896"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55358",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55358"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56970",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56970"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56989",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56989"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55301",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55301"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55351",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In VPU, there is a possible out-of-bounds write due to an integer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55351"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56945",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In VPU, there is a possible out-of-bounds write due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56945"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56982",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In VPU, there is a possible permission bypass due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56982"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57035",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-57035"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56900",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In restore_quickboot_csrs_s2m of training.rs, there is a possible out-of-bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56900"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55332",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55332"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0192",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Bootloader, there is a possible escalation of privilege due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0192"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56979",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56979"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55326",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible escalation of privilege due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55326"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58698",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58698"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58739",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58739"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58716",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible time-of-check to time-of-use due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58716"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55329",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Bootloader, there is a possible permission bypass due to an insecure default value.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55329"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56879",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56879"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55355",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Bootloader, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55355"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0197",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In VPU, there is a possible information dislclosure due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0197"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55302",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55302"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0194",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to an integer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0194"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58744",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible escalation of privilege due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58744"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58679",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58679"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58701",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58701"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56920",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56920"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58678",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Bootloader, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58678"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56932",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Trusted Execution Environment, there is a possible memory corruption due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56932"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58710",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58710"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56907",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In VPU, there is a possible shared memory overwrite due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56907"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56997",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56997"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56922",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In CPM, there is a possible permission bypass due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56922"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0183",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In CPM, there is a possible information disclosure due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0183"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56972",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56972"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58695",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58695"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0187",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0187"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55317",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In printf of printf.c, there is a possible out-of-bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55317"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58721",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible information disclosure due to uninitialized memory use.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58721"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58726",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58726"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56881",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56881"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55337",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In mfw_resource_set_access_by_perm of resources.c, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55337"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55365",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55365"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0189",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0189"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0186",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0186"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55364",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55364"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56889",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to an integer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56889"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56978",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56978"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55304",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55304"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56892",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56892"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58691",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58691"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58718",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58718"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55318",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible use-after-free due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55318"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56923",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56923"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56888",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to side channel information disclosure.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56888"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0177",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0177"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58747",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58747"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58766",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58766"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58751",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58751"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58755",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58755"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58767",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58767"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0179",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In Bootloader, there is a possible permission bypass due to a missing permission check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0179"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55323",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55323"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-0199",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-0199"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56958",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56958"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56950",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56950"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58731",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58731"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55357",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In CPM, there is a possible permission bypass due to an insecure default value.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55357"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56891",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56891"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58765",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In GPU, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58765"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-55359",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible permission bypass due to a logic error in the code.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-55359"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57042",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-57042"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56988",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56988"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-58724",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple locations, there is a possible use-after-free due to a race condition.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-58724"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57014",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-57014"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-56886",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "osv",
   "feed_count": 1,
   "dates": {
    "osv": "2026-09-01"
   },
   "refs": "osv:Android::unknown:",
   "description": "In multiple functions of stpropnci_prop_android.cc, there is a possible out-of-bounds write due to a missing bounds check.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "Android",
   "source_urls": {
    "osv": "https://osv.dev/list?q=CVE-2026-56886"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-33141",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3139\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3139.json",
   "description": "CVE-2025-33141",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3139.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-25275",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,samsung",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-09-08",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;samsung:SMR-Sep-2026",
   "description": "CVE-2026-25275",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-25294",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,samsung",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-09-08",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3251\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json;samsung:SMR-Sep-2026",
   "description": "CVE-2026-25294",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3251.json",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48173",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "csaf,samsung",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-09-06",
    "samsung": "2026-09-01"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3206\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json;samsung:SMR-Sep-2026",
   "description": "CVE-2026-48173",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json",
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-20499",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-09-01"
   },
   "refs": "samsung:SMR-Sep-2026",
   "description": "Samsung SMR Sep 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-28605",
   "state": "RESERVED",
   "public_date": "2026-09-01",
   "sources": "samsung",
   "feed_count": 1,
   "dates": {
    "samsung": "2026-09-01"
   },
   "refs": "samsung:SMR-Sep-2026",
   "description": "Samsung SMR Sep 2026",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 14,
   "clock_known": true,
   "hours_public": 336,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-01",
   "advisory_days_public": 14,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "samsung": "https://security.samsungmobile.com/securityUpdate.smsb"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77520",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-4w4r-h4x8-mg7h",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-4w4r-h4x8-mg7h",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-4w4r-h4x8-mg7h"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79917",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-m8gr-554p-8r82",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-m8gr-554p-8r82",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-m8gr-554p-8r82"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79916",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-2324-7xjr-9qxg",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-2324-7xjr-9qxg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-2324-7xjr-9qxg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77521",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-f36j-f34j-h3rx",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-f36j-f34j-h3rx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77523",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-g888-8cvh-9284",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-g888-8cvh-9284",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-g888-8cvh-9284"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77522",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-ffxw-frpx-8rww",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-ffxw-frpx-8rww",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-ffxw-frpx-8rww"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77525",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-7fmh-98f2-2cfg",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-7fmh-98f2-2cfg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-7fmh-98f2-2cfg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77519",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-r6g6-69fh-c39q",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-r6g6-69fh-c39q",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-r6g6-69fh-c39q"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77518",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-x65c-w438-c58f",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-x65c-w438-c58f",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-x65c-w438-c58f"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77517",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-58cm-c5jq-96vf",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-58cm-c5jq-96vf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-58cm-c5jq-96vf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77516",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-383v-fx78-pphm",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-383v-fx78-pphm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-383v-fx78-pphm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39372",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-7j67-2v6p-275v",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-7j67-2v6p-275v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-7j67-2v6p-275v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83603",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-qwh9-pq27-993w",
   "description": "netdata/netdata repository advisory GHSA-qwh9-pq27-993w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-qwh9-pq27-993w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83602",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-8hjg-8hcf-fmwp",
   "description": "netdata/netdata repository advisory GHSA-8hjg-8hcf-fmwp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-8hjg-8hcf-fmwp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83600",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-3mxw-fv2x-rhc6",
   "description": "netdata/netdata repository advisory GHSA-3mxw-fv2x-rhc6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-3mxw-fv2x-rhc6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83601",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-3qh4-842w-fvrm",
   "description": "netdata/netdata repository advisory GHSA-3qh4-842w-fvrm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-3qh4-842w-fvrm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83599",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-c8p4-cg3j-f4h2",
   "description": "netdata/netdata repository advisory GHSA-c8p4-cg3j-f4h2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-c8p4-cg3j-f4h2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83597",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-jmv4-pq25-crvv",
   "description": "netdata/netdata repository advisory GHSA-jmv4-pq25-crvv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-jmv4-pq25-crvv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-83598",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:netdata/netdata\tGHSA-8hxv-2mg6-ggw5",
   "description": "netdata/netdata repository advisory GHSA-8hxv-2mg6-ggw5",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85055",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-02"
   },
   "refs": "ghsa-repos:twentyhq/twenty\tGHSA-v93q-4jcx-7p9m",
   "description": "twentyhq/twenty repository advisory GHSA-v93q-4jcx-7p9m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/twentyhq/twenty/security/advisories/GHSA-v93q-4jcx-7p9m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76594",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-76594\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76594.json;redhat:CVE-2026-76594",
   "description": "advisor-backend: advisor-backend: Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-76594",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76594.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-76594"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76595",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-76595\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76595.json;redhat:CVE-2026-76595",
   "description": "advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-76595",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76595.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-76595"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84910",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/advanced_search",
   "description": "This module enables AJAX updates for advanced search, facet, and search result blocks.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/advanced_search",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84910"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84911",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/ai",
   "description": "This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/ai",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84911"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84912",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/ai",
   "description": "This submodule AI Translate enables you to automatically translate entities.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/ai",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84912"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84913",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/ai_translate",
   "description": "This module enables you to automatically translate entities.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/ai_translate",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84913"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84914",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/calculate_working_days",
   "description": "Calculate Working Days allows you to calculate working days between 2 dates.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/calculate_working_days",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84914"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84915",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/component_blocks",
   "description": "This module enables you use UI Patterns with blocks, for use in Layout Builder.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/component_blocks",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84915"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84923",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/otp_verification",
   "description": "This module enables you to add extra layer of verification for user registration.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/otp_verification",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84923"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84924",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/otp_verification",
   "description": "This module enables you to add an extra layer of verification for user registration.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/otp_verification",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84924"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84916",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/islandora",
   "description": "This `islandora_advanced_search` sub module enables AJAX updates for advanced search, facet, and search result blocks.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/islandora",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84916"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84917",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/jsonapi_role_access",
   "description": "This module enables you to restrict access to JSON:API routes based on specific user roles.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/jsonapi_role_access",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84917"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-16648",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/symfony_mailer_log",
   "description": "This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports > Mail log.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/symfony_mailer_log",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-16648"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81163",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/media_library_importer",
   "description": "A module to import media files into media library.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/media_library_importer",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-81163"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84918",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/monobank",
   "description": "The Monobank payment API module provides integration with Monobank acquiring payments.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/monobank",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84918"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84919",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/photoswipe",
   "description": "This module enables you to add dynamic caption support to PhotoSwipe image galleries.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/photoswipe",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84919"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84920",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/unpublished_node_permissions",
   "description": "This module creates permissions per node content type to control access to unpublished content.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/unpublished_node_permissions",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84920"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84921",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,osv",
   "feed_count": 2,
   "dates": {
    "osv": "2026-09-02",
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3168\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json;osv:Packagist:drupal/webform_submissions_delete",
   "description": "This module enables you to delete Webform submissions in bulk using a specified date range.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "drupal/webform_submissions_delete",
   "ecosystem": "Packagist",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3168.json",
    "osv": "https://osv.dev/list?q=CVE-2026-84921"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59346",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf,zdi",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-09-02",
    "zdi": "2026-09-09"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3169\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3169.json;zdi:ZDI-26-647",
   "description": "CVE-2026-59346",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3169.json",
    "zdi": "https://www.zerodayinitiative.com/advisories/ZDI-26-647/"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-59347",
   "state": "RESERVED",
   "public_date": "2026-09-02",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-02"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3169\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3169.json",
   "description": "CVE-2026-59347",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 13,
   "clock_known": true,
   "hours_public": 312,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-02",
   "advisory_days_public": 13,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3169.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65165",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-05",
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "alas:CVE-2026-65165;debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65165;ubuntu:CVE-2026-65165",
   "description": "Fix various issues around job steps and node count discrepancies",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-05",
   "advisory_days_public": 10,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65165.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65165",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65165",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65165"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65139",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "alas:CVE-2026-65139;debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65139;ubuntu:CVE-2026-65139",
   "description": "Fix various issues in unsafe operation/queries to the slurmdbd",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65139.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65139",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65139",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65139"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65108",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "alas:CVE-2026-65108;debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65108;ubuntu:CVE-2026-65108",
   "description": "Fix a slurmstepd stack overflow when a job environment contains an oversized SPANK option variable",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65108.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65108",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65108",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65108"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65109",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "alas:CVE-2026-65109;debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65109;ubuntu:CVE-2026-65109",
   "description": "Fix slurmstepd removing files outside the container spool directory when cleaning up an OCI containe, Fix slurmstepd leaving OCI container spool directories behind when ContainerPath contains a task id pattern",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65109.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65109",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65109",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65109"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85218",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,csaf,debian,ghsa-repos,redhat,ubuntu,ubuntu-osv",
   "feed_count": 7,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-07",
    "ubuntu-osv": "2026-09-07",
    "ghsa-repos": "2026-09-03",
    "redhat": "2026-09-03",
    "csaf": "2026-09-05"
   },
   "refs": "alas:CVE-2026-85218;csaf:SUSE Product Security Team\tCVE-2026-85218\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-85218.json;debian:bluez;ghsa-repos:bluez/bluez\tGHSA-m2vx-pw5f-rc8v;redhat:CVE-2026-85218;ubuntu-osv:UBUNTU-CVE-2026-85218;",
   "description": "A double stack-based buffer overflow was found in the BlueZ AVRCP controller implementation.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "bluez",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-85218.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-85218.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-85218",
    "ghsa-repos": "https://github.com/bluez/bluez/security/advisories/GHSA-m2vx-pw5f-rc8v",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-85218",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-85218",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-85218"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65138",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "alas:CVE-2026-65138;debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65138;ubuntu:CVE-2026-65138",
   "description": "Fix heap over-read when unpacking a malformed forward data RPC in slurmd.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-65138.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65138",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65138",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65138"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71223",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alas,csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-09-04",
    "ubuntu": "2026-09-07",
    "ubuntu-osv": "2026-09-07",
    "redhat": "2026-09-03",
    "csaf": "2026-09-03"
   },
   "refs": "alas:CVE-2026-71223;csaf:SUSE Product Security Team\tCVE-2026-71223\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-71223.json;debian:gfs2-utils;redhat:CVE-2026-71223;ubuntu-osv:UBUNTU-CVE-2026-71223;ubuntu:CVE-2026-71223",
   "description": "An integer overflow vulnerability was found in gfs2-utils.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "gfs2-utils",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-71223.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-71223.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-71223",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-71223",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-71223",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-71223"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65140",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "debian,ubuntu,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65140;ubuntu:CVE-2026-65140",
   "description": "[Fix a privilege escalation where an operator could alter Administrator accounts through the accounting database]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65140",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65140",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65140"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65107",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "debian,ubuntu,ubuntu-osv",
   "feed_count": 3,
   "dates": {
    "ubuntu": "2026-09-03",
    "ubuntu-osv": "2026-09-03"
   },
   "refs": "debian:slurm-wlm;ubuntu-osv:UBUNTU-CVE-2026-65107;ubuntu:CVE-2026-65107",
   "description": "[Fix sbcast shared objects skipping credential verification, Fix possible slurmd crash on invalid sbcast filenames]",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "tracker",
   "advisory_date": null,
   "advisory_days_public": null,
   "past_expectation": false,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "slurm-wlm",
   "ecosystem": "",
   "source_urls": {
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-65107",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-65107",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-65107"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79918",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-03"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-9mh9-v949-fwqh",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-9mh9-v949-fwqh",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-9mh9-v949-fwqh"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79919",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-03"
   },
   "refs": "ghsa-repos:1Panel-dev/MaxKB\tGHSA-6h35-c779-4v37",
   "description": "1Panel-dev/MaxKB repository advisory GHSA-6h35-c779-4v37",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-6h35-c779-4v37"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77276",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-03"
   },
   "refs": "ghsa-repos:CollaboraOnline/online\tGHSA-cf9v-hrj7-8p4v",
   "description": "CollaboraOnline/online repository advisory GHSA-cf9v-hrj7-8p4v",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/CollaboraOnline/online/security/advisories/GHSA-cf9v-hrj7-8p4v"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81508",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-03"
   },
   "refs": "ghsa-repos:espressif/esp-idf\tGHSA-xcpr-5mqp-9qvv",
   "description": "espressif/esp-idf repository advisory GHSA-xcpr-5mqp-9qvv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espressif/esp-idf/security/advisories/GHSA-xcpr-5mqp-9qvv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81507",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-03"
   },
   "refs": "ghsa-repos:espressif/esp-idf\tGHSA-v335-fxwc-rc44",
   "description": "espressif/esp-idf repository advisory GHSA-v335-fxwc-rc44",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/espressif/esp-idf/security/advisories/GHSA-v335-fxwc-rc44"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-80256",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "alpine,csaf",
   "feed_count": 2,
   "dates": {
    "csaf": "2026-09-03"
   },
   "refs": "alpine:curl;csaf:SUSE Product Security Team\tCVE-2026-80256\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-80256.json",
   "description": "CVE-2026-80256",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "curl",
   "ecosystem": "",
   "source_urls": {
    "alpine": "https://security.alpinelinux.org/vuln/CVE-2026-80256",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-80256.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2025-10478",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-03"
   },
   "refs": "csaf:CISA\tICSA-26-246-05\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-246-05.json",
   "description": "Rockwell Automation 1756-ENBT Module",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-246-05.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-77477",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-03"
   },
   "refs": "csaf:CISA\tICSA-26-246-01\thttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-246-01.json",
   "description": "OPCFoundation OPC UA LocalDiscoveryServer (LDS)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-246-01.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-61408",
   "state": "RESERVED",
   "public_date": "2026-09-03",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-03"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3184\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3184.json",
   "description": "CVE-2026-61408",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 12,
   "clock_known": true,
   "hours_public": 288,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-03",
   "advisory_days_public": 12,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3184.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-84471",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "alas,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "alas": "2026-09-05",
    "ubuntu": "2026-09-04",
    "ubuntu-osv": "2026-09-04"
   },
   "refs": "alas:CVE-2026-84471;debian:openvpn;ubuntu-osv:UBUNTU-CVE-2026-84471;ubuntu:CVE-2026-84471",
   "description": "openvpn",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-05",
   "advisory_days_public": 10,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "openvpn",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-84471.html",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-84471",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-84471",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-84471"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85498",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "alas,csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 6,
   "dates": {
    "alas": "2026-09-05",
    "ubuntu": "2026-09-07",
    "ubuntu-osv": "2026-09-07",
    "redhat": "2026-09-04",
    "csaf": "2026-09-05"
   },
   "refs": "alas:CVE-2026-85498;csaf:SUSE Product Security Team\tCVE-2026-85498\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-85498.json;debian:policykit-1;redhat:CVE-2026-85498;ubuntu-osv:UBUNTU-CVE-2026-85498;ubuntu:CVE-2026-85498",
   "description": "A flaw was found in polkit.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "policykit-1",
   "ecosystem": "",
   "source_urls": {
    "alas": "https://explore.alas.aws.amazon.com/CVE-2026-85498.html",
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-85498.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-85498",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-85498",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-85498",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-85498"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71197",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-04",
    "ubuntu-osv": "2026-09-04",
    "redhat": "2026-09-04",
    "csaf": "2026-09-04"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-71197\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71197.json;debian:glance;redhat:CVE-2026-71197;ubuntu-osv:UBUNTU-CVE-2026-71197;ubuntu:CVE-2026-71197",
   "description": "glance",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "glance",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71197.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-71197",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-71197",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-71197",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-71197"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-71196",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "csaf,debian,redhat,ubuntu,ubuntu-osv",
   "feed_count": 5,
   "dates": {
    "ubuntu": "2026-09-04",
    "ubuntu-osv": "2026-09-04",
    "redhat": "2026-09-04",
    "csaf": "2026-09-04"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-71196\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71196.json;debian:glance;redhat:CVE-2026-71196;ubuntu-osv:UBUNTU-CVE-2026-71196;ubuntu:CVE-2026-71196",
   "description": "glance",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "glance",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71196.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-71196",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-71196",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-71196",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-71196"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85292",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-346c-gqqq-mrm2",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-346c-gqqq-mrm2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-346c-gqqq-mrm2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85293",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-477r-xmgc-vcvj",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-477r-xmgc-vcvj",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-477r-xmgc-vcvj"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85291",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-x38q-xhjj-jr8w",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-x38q-xhjj-jr8w",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-x38q-xhjj-jr8w"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85290",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-g53q-v2pv-xr83",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-g53q-v2pv-xr83",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-g53q-v2pv-xr83"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85289",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-9372-vj68-hmc3",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-9372-vj68-hmc3",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-9372-vj68-hmc3"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85274",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-qf9q-2hxm-4wh9",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-qf9q-2hxm-4wh9",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-qf9q-2hxm-4wh9"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-64862",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:frappe/hrms\tGHSA-wfc6-cw72-cvhx",
   "description": "frappe/hrms repository advisory GHSA-wfc6-cw72-cvhx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/hrms/security/advisories/GHSA-wfc6-cw72-cvhx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85076",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:jhuckaby/Cronicle\tGHSA-9w42-v8cj-68gq",
   "description": "jhuckaby/Cronicle repository advisory GHSA-9w42-v8cj-68gq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/jhuckaby/Cronicle/security/advisories/GHSA-9w42-v8cj-68gq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-63645",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:openobserve/openobserve\tGHSA-v496-g5c9-vqxw",
   "description": "openobserve/openobserve repository advisory GHSA-v496-g5c9-vqxw",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/openobserve/openobserve/security/advisories/GHSA-v496-g5c9-vqxw"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-88976",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:udecode/plate\tGHSA-qrfj-mgw8-j9c6",
   "description": "udecode/plate repository advisory GHSA-qrfj-mgw8-j9c6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/udecode/plate/security/advisories/GHSA-qrfj-mgw8-j9c6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-88974",
   "state": "RESERVED",
   "public_date": "2026-09-04",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-04"
   },
   "refs": "ghsa-repos:wp-graphql/wp-graphql\tGHSA-5mmc-8pc9-wggg",
   "description": "wp-graphql/wp-graphql repository advisory GHSA-5mmc-8pc9-wggg",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 11,
   "clock_known": true,
   "hours_public": 264,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-04",
   "advisory_days_public": 11,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86067",
   "state": "RESERVED",
   "public_date": "2026-09-05",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-05"
   },
   "refs": "ghsa-repos:1Panel-dev/KubePi\tGHSA-qpwj-gxgw-5mgp",
   "description": "1Panel-dev/KubePi repository advisory GHSA-qpwj-gxgw-5mgp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 10,
   "clock_known": true,
   "hours_public": 240,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-05",
   "advisory_days_public": 10,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/1Panel-dev/KubePi/security/advisories/GHSA-qpwj-gxgw-5mgp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86003",
   "state": "RESERVED",
   "public_date": "2026-09-05",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-09-05",
    "csaf": "2026-09-06"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3198\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3198.json;ghsa-repos:coredns/coredns\tGHSA-9gm5-9rfh-m6vx",
   "description": "coredns/coredns repository advisory GHSA-9gm5-9rfh-m6vx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 10,
   "clock_known": true,
   "hours_public": 240,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-05",
   "advisory_days_public": 10,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3198.json",
    "ghsa-repos": "https://github.com/coredns/coredns/security/advisories/GHSA-9gm5-9rfh-m6vx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-76820",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "csaf,ghsa-repos",
   "feed_count": 2,
   "dates": {
    "ghsa-repos": "2026-09-07",
    "csaf": "2026-09-06"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3210\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3210.json;ghsa-repos:OpenCTI-Platform/opencti\tGHSA-f6pj-3m32-q934",
   "description": "OpenCTI-Platform/opencti repository advisory GHSA-f6pj-3m32-q934",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3210.json",
    "ghsa-repos": "https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-f6pj-3m32-q934"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86005",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-w8g3-j8rf-qc5j",
   "description": "chartbrew/chartbrew repository advisory GHSA-w8g3-j8rf-qc5j",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-w8g3-j8rf-qc5j"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85736",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-p5h6-f969-jpfv",
   "description": "chartbrew/chartbrew repository advisory GHSA-p5h6-f969-jpfv",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-p5h6-f969-jpfv"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85726",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-mr45-2r9x-cgwf",
   "description": "chartbrew/chartbrew repository advisory GHSA-mr45-2r9x-cgwf",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-mr45-2r9x-cgwf"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85712",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-6gv3-8wxh-6vfq",
   "description": "chartbrew/chartbrew repository advisory GHSA-6gv3-8wxh-6vfq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-6gv3-8wxh-6vfq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85708",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-3chp-cr6f-hp63",
   "description": "chartbrew/chartbrew repository advisory GHSA-3chp-cr6f-hp63",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-3chp-cr6f-hp63"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85295",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-06"
   },
   "refs": "ghsa-repos:chartbrew/chartbrew\tGHSA-qvv4-r3q6-8797",
   "description": "chartbrew/chartbrew repository advisory GHSA-qvv4-r3q6-8797",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/chartbrew/chartbrew/security/advisories/GHSA-qvv4-r3q6-8797"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48174",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-06"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3206\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json",
   "description": "CVE-2026-48174",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48175",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-06"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3206\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json",
   "description": "CVE-2026-48175",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48176",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-06"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3206\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json",
   "description": "CVE-2026-48176",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48179",
   "state": "RESERVED",
   "public_date": "2026-09-06",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-06"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3206\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json",
   "description": "CVE-2026-48179",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 9,
   "clock_known": true,
   "hours_public": 216,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-06",
   "advisory_days_public": 9,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3206.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85745",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-07"
   },
   "refs": "ghsa-repos:MariaDB/server\tGHSA-p7v9-24h4-mch8",
   "description": "MariaDB/server repository advisory GHSA-p7v9-24h4-mch8",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MariaDB/server/security/advisories/GHSA-p7v9-24h4-mch8"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85746",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-07"
   },
   "refs": "ghsa-repos:MariaDB/server\tGHSA-8fvj-c57c-pggx",
   "description": "MariaDB/server repository advisory GHSA-8fvj-c57c-pggx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MariaDB/server/security/advisories/GHSA-8fvj-c57c-pggx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85748",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-07"
   },
   "refs": "ghsa-repos:MariaDB/server\tGHSA-mv8g-9f7q-hprm",
   "description": "MariaDB/server repository advisory GHSA-mv8g-9f7q-hprm",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MariaDB/server/security/advisories/GHSA-mv8g-9f7q-hprm"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-85985",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-07"
   },
   "refs": "ghsa-repos:MariaDB/server\tGHSA-2245-9hm3-wxf6",
   "description": "MariaDB/server repository advisory GHSA-2245-9hm3-wxf6",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MariaDB/server/security/advisories/GHSA-2245-9hm3-wxf6"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86047",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-07"
   },
   "refs": "ghsa-repos:MariaDB/server\tGHSA-wxr3-wm3p-7w6p",
   "description": "MariaDB/server repository advisory GHSA-wxr3-wm3p-7w6p",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/MariaDB/server/security/advisories/GHSA-wxr3-wm3p-7w6p"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-86066",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-07"
   },
   "refs": "ghsa-repos:horilla/horilla-hr\tGHSA-65vj-5p5g-pv5m",
   "description": "horilla/horilla-hr repository advisory GHSA-65vj-5p5g-pv5m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/horilla/horilla-hr/security/advisories/GHSA-65vj-5p5g-pv5m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-57582",
   "state": "RESERVED",
   "public_date": "2026-09-07",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-07"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0343\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0343.json",
   "description": "CVE-2026-57582",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 8,
   "clock_known": true,
   "hours_public": 192,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-07",
   "advisory_days_public": 8,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0343.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79604",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,debian,ubuntu,ubuntu-osv",
   "feed_count": 4,
   "dates": {
    "ubuntu": "2026-09-08",
    "ubuntu-osv": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3248\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3248.json;debian:xen;ubuntu-osv:UBUNTU-CVE-2026-79604;ubuntu:CVE-2026-79604",
   "description": "oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain.",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "xen",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3248.json",
    "debian": "https://security-tracker.debian.org/tracker/CVE-2026-79604",
    "ubuntu": "https://ubuntu.com/security/CVE-2026-79604",
    "ubuntu-osv": "https://ubuntu.com/security/CVE-2026-79604"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-39353",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:InvoicePlane/InvoicePlane\tGHSA-v735-2x3r-gwpp",
   "description": "InvoicePlane/InvoicePlane repository advisory GHSA-v735-2x3r-gwpp",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-v735-2x3r-gwpp"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48070",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:docmost/docmost\tGHSA-95f8-h5hf-8248",
   "description": "docmost/docmost repository advisory GHSA-95f8-h5hf-8248",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docmost/docmost/security/advisories/GHSA-95f8-h5hf-8248"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48072",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:docmost/docmost\tGHSA-9f58-29hm-mgp2",
   "description": "docmost/docmost repository advisory GHSA-9f58-29hm-mgp2",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docmost/docmost/security/advisories/GHSA-9f58-29hm-mgp2"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-48073",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:docmost/docmost\tGHSA-rxm9-xp9h-4c84",
   "description": "docmost/docmost repository advisory GHSA-rxm9-xp9h-4c84",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docmost/docmost/security/advisories/GHSA-rxm9-xp9h-4c84"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52850",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:docmost/docmost\tGHSA-5vhf-cgf2-c9cq",
   "description": "docmost/docmost repository advisory GHSA-5vhf-cgf2-c9cq",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docmost/docmost/security/advisories/GHSA-5vhf-cgf2-c9cq"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-52853",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:docmost/docmost\tGHSA-84fx-mvqx-p5gx",
   "description": "docmost/docmost repository advisory GHSA-84fx-mvqx-p5gx",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docmost/docmost/security/advisories/GHSA-84fx-mvqx-p5gx"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65827",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:docmost/docmost\tGHSA-frjw-66gr-799m",
   "description": "docmost/docmost repository advisory GHSA-frjw-66gr-799m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/docmost/docmost/security/advisories/GHSA-frjw-66gr-799m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-66057",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "ghsa-repos",
   "feed_count": 1,
   "dates": {
    "ghsa-repos": "2026-09-08"
   },
   "refs": "ghsa-repos:frappe/frappe\tGHSA-78c5-55xg-jm7m",
   "description": "frappe/frappe repository advisory GHSA-78c5-55xg-jm7m",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "ghsa-repos": "https://github.com/frappe/frappe/security/advisories/GHSA-78c5-55xg-jm7m"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87053",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87053\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87053.json;redhat:CVE-2026-87053",
   "description": "operator-sdk-builder: operator-sdk-builder: Final container image runs as root (USER root never reverted)",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87053",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87053.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87053"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87054",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87054\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87054.json;redhat:CVE-2026-87054",
   "description": "operator-sdk-builder: operator-sdk-builder: containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87054",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87054.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87054"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87055",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87055\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87055.json;redhat:CVE-2026-87055",
   "description": "operator-sdk-builder: operator-sdk-builder: Base image referenced by mutable tag rather than sha256 digest",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87055",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87055.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87055"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87056",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87056\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87056.json;redhat:CVE-2026-87056",
   "description": "operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87056",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87056.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87056"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87049",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87049\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87049.json;redhat:CVE-2026-87049",
   "description": "operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87049",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87049.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87049"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87050",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87050\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87050.json;redhat:CVE-2026-87050",
   "description": "operator-foundry: operator-foundry: GitHub Actions and reusable workflow not pinned to commit SHA",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87050",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87050.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87050"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87051",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87051\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87051.json;redhat:CVE-2026-87051",
   "description": "operator-foundry: operator-foundry: resolveAndValidatePath performs lexical containment only \u2014 symlinks can escape the build context",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87051",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87051.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87051"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87052",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87052\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87052.json;redhat:CVE-2026-87052",
   "description": "operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87052",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87052.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87052"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87057",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87057\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87057.json;redhat:CVE-2026-87057",
   "description": "olm-operator-konflux-sample: olm-operator-konflux-sample: Runtime base images referenced by mutable floating tags",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87057",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87057.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87057"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87058",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87058\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87058.json;redhat:CVE-2026-87058",
   "description": "olm-operator-konflux-sample: olm-operator-konflux-sample: Hermetic build disabled by default; bundle build performs live network fetches",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87058",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87058.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87058"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87059",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87059\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87059.json;redhat:CVE-2026-87059",
   "description": "olm-operator-konflux-sample: olm-operator-konflux-sample: Unpinned pip dependency installation in bundle builder stage",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87059",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87059.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87059"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87060",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87060\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87060.json;redhat:CVE-2026-87060",
   "description": "olm-operator-konflux-sample: olm-operator-konflux-sample: Renovate automerge enabled with base-image update exclusions",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87060",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87060.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87060"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87061",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87061\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87061.json;redhat:CVE-2026-87061",
   "description": "olm-operator-konflux-sample: olm-operator-konflux-sample: bundle-hack/update_bundle.sh lacks fail-fast shell options",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87061",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87061.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87061"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87062",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87062\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87062.json;redhat:CVE-2026-87062",
   "description": "konflux-operator-tasks: konflux-operator-tasks: GitHub Actions referenced by mutable tag/branch instead of commit SHA",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87062",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87062.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87062"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87063",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87063\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87063.json;redhat:CVE-2026-87063",
   "description": "konflux-operator-tasks: konflux-operator-tasks: tkn CLI installed from network without checksum or signature verification",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87063",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87063.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87063"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87064",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87064\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87064.json;redhat:CVE-2026-87064",
   "description": "konflux-operator-tasks: konflux-operator-tasks: GitHub workflows lack explicit least-privilege permissions blocks",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87064",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87064.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87064"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-87065",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf,redhat",
   "feed_count": 2,
   "dates": {
    "redhat": "2026-09-08",
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Red Hat Product Security\tCVE-2026-87065\thttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87065.json;redhat:CVE-2026-87065",
   "description": "konflux-operator-tasks: konflux-operator-tasks: Tekton task steps run as root without defense-in-depth securityContext hardening",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "CVE-2026-87065",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87065.json",
    "redhat": "https://access.redhat.com/security/cve/CVE-2026-87065"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79606",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:SUSE Product Security Team\tCVE-2026-79606\thttps://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-79606.json",
   "description": "CVE-2026-79606",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-79606.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69639",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0353\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0353.json",
   "description": "CVE-2026-69639",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-69774",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0353\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0353.json",
   "description": "CVE-2026-69774",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0353.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-81961",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Nationaal Cyber Security Centrum\tNCSC-2026-0347\thttps://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0347.json",
   "description": "CVE-2026-81961",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0347.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-10841",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3275\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json",
   "description": "CVE-2026-10841",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11537",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11537",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11538",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11538",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11539",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11539",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11540",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11540",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11545",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11545",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11548",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3275\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json",
   "description": "CVE-2026-11548",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11549",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3275\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json",
   "description": "CVE-2026-11549",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11710",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11710",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11711",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3255\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json",
   "description": "CVE-2026-11711",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3255.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-11722",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3275\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json",
   "description": "CVE-2026-11722",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3275.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65949",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3253\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json",
   "description": "CVE-2026-65949",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65950",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3253\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json",
   "description": "CVE-2026-65950",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65951",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3253\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json",
   "description": "CVE-2026-65951",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-65952",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3253\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json",
   "description": "CVE-2026-65952",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3253.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-79605",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3248\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3248.json",
   "description": "CVE-2026-79605",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3248.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  },
  {
   "cve_id": "CVE-2026-9596",
   "state": "RESERVED",
   "public_date": "2026-09-08",
   "sources": "csaf",
   "feed_count": 1,
   "dates": {
    "csaf": "2026-09-08"
   },
   "refs": "csaf:Bundesamt f\u00fcr Sicherheit in der Informationstechnik\tWID-SEC-W-2026-3239\thttps://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3239.json",
   "description": "CVE-2026-9596",
   "state_verified_this_run": true,
   "public_date_origin": "feed",
   "days_public": 7,
   "clock_known": true,
   "hours_public": 168,
   "clock_origin": "advisory",
   "advisory_date": "2026-09-08",
   "advisory_days_public": 7,
   "past_expectation": true,
   "disclosure_order": "unmeasurable",
   "self_disclosed": false,
   "rule": "4.5.1.6",
   "rule_strength": "SHOULD",
   "rule_basis": "unattributed",
   "rule_certainty": "unmeasurable",
   "package": "",
   "ecosystem": "",
   "source_urls": {
    "csaf": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3239.json"
   },
   "veto_evaluated": false,
   "owner_nameable": false
  }
 ]
}