Skip to content

Commit 5507bb0

Browse files
Sync EUVD catalog: Thu Jun 25 00:54:32 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 2d3f4ae commit 5507bb0

531 files changed

Lines changed: 44909 additions & 66 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/05/EUVD-2026-27657.json

Lines changed: 17 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,28 @@
11
{
22
"id": "EUVD-2026-27657",
33
"enisaUuid": "e88b8d19-8e1d-3f21-852c-4e0b027f94ad",
4-
"description": "Keylime has a hardcoded attestation challenge nonce that allows replay attacks",
5-
"datePublished": "May 11, 2026, 2:42:46 PM",
6-
"dateUpdated": "May 11, 2026, 2:42:46 PM",
4+
"description": "A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.",
5+
"datePublished": "May 6, 2026, 10:19:39 AM",
6+
"dateUpdated": "Jun 24, 2026, 1:55:59 AM",
77
"baseScore": 6.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L",
10-
"references": "https://access.redhat.com/security/cve/CVE-2026-6420\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2458889\nhttps://github.com/keylime/keylime/security/advisories/GHSA-q8w6-w55c-ccv5\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6420\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:28582\nhttps://access.redhat.com/security/cve/CVE-2026-6420\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2458889\n",
1111
"aliases": "GHSA-wc6p-4gwj-jcr8\nGHSA-q8w6-w55c-ccv5\nCVE-2026-6420\n",
1212
"assigner": "redhat",
13-
"epss": 0.01,
14-
"enisaIdProduct": [],
13+
"epss": 0.12,
14+
"enisaIdProduct": [
15+
{
16+
"id": "24e5591c-bef5-3f4e-a0d3-8e1a91da4d3b",
17+
"product": {
18+
"name": "Red Hat Enterprise Linux 10",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
22+
},
23+
"product_version": "patch: 0:7.14.1-5.el10_2.1"
24+
}
25+
],
1526
"enisaIdVendor": [
1627
{
1728
"id": "0e6945f1-e713-3b01-9a1a-2377a30af463",

advisories/2026/05/EUVD-2026-31201.json

Lines changed: 23 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,32 @@
33
"enisaUuid": "873ff1cd-6c4e-31ce-a50b-3664076698f3",
44
"description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
55
"datePublished": "May 20, 2026, 11:34:56 PM",
6-
"dateUpdated": "May 21, 2026, 6:39:41 PM",
6+
"dateUpdated": "Jun 24, 2026, 1:53:43 AM",
77
"baseScore": 6.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
10-
"references": "https://access.redhat.com/security/cve/CVE-2026-9149\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2460380\nhttps://github.com/openSUSE/libsolv/pull/617\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:28236\nhttps://access.redhat.com/security/cve/CVE-2026-9149\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2460380\nhttps://github.com/openSUSE/libsolv/pull/617\n",
1111
"aliases": "CVE-2026-9149\nGHSA-9q56-xf64-q987\n",
1212
"assigner": "redhat",
13-
"epss": 0.0,
14-
"enisaIdProduct": [],
15-
"enisaIdVendor": []
13+
"epss": 0.27,
14+
"enisaIdProduct": [
15+
{
16+
"id": "63f0ff15-fc98-3e20-bb89-3d3d421fe800",
17+
"product": {
18+
"name": "Red Hat Enterprise Linux 10",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
22+
},
23+
"product_version": "patch: 0:0.7.33-5.el10_2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "10b0a7b5-7bc0-307b-9308-081a8d9085cf",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
}
33+
]
1634
}

advisories/2026/05/EUVD-2026-31202.json

Lines changed: 23 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,32 @@
33
"enisaUuid": "7431ef8a-2536-3342-a2ce-446eb1645097",
44
"description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
55
"datePublished": "May 20, 2026, 11:07:18 PM",
6-
"dateUpdated": "May 21, 2026, 2:25:03 PM",
6+
"dateUpdated": "Jun 24, 2026, 1:53:48 AM",
77
"baseScore": 6.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
10-
"references": "https://access.redhat.com/security/cve/CVE-2026-9150\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2460379\nhttps://github.com/openSUSE/libsolv/pull/616\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:28236\nhttps://access.redhat.com/security/cve/CVE-2026-9150\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2460379\nhttps://github.com/openSUSE/libsolv/pull/616\n",
1111
"aliases": "CVE-2026-9150\nGHSA-p4w9-3pj8-mhq7\n",
1212
"assigner": "redhat",
13-
"epss": 0.0,
14-
"enisaIdProduct": [],
15-
"enisaIdVendor": []
13+
"epss": 0.35,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7f13ce6a-22b7-320e-b6ad-af3609256286",
17+
"product": {
18+
"name": "Red Hat Enterprise Linux 10",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
22+
},
23+
"product_version": "patch: 0:0.7.33-5.el10_2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "c415e311-1ee2-324f-91bf-9354e9699ee1",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
}
33+
]
1634
}

advisories/2026/05/EUVD-2026-31859.json

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "b5dddaf4-5729-3191-a82a-becc49f709ef",
44
"description": "A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.",
55
"datePublished": "May 26, 2026, 4:16:07 PM",
6-
"dateUpdated": "May 28, 2026, 2:54:04 AM",
6+
"dateUpdated": "Jun 24, 2026, 1:53:49 AM",
77
"baseScore": 7.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
10-
"references": "https://access.redhat.com/errata/RHSA-2026:21333\nhttps://access.redhat.com/security/cve/CVE-2026-48864\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2460425\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:21333\nhttps://access.redhat.com/errata/RHSA-2026:28236\nhttps://access.redhat.com/security/cve/CVE-2026-48864\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2460425\n",
1111
"aliases": "CVE-2026-48864\nGHSA-2927-mfhv-37vh\n",
1212
"assigner": "redhat",
13-
"epss": 0.01,
13+
"epss": 0.2,
1414
"enisaIdProduct": [
1515
{
1616
"id": "182f2392-96b9-3390-ac88-a2b39d79be32",
@@ -21,6 +21,16 @@
2121
}
2222
},
2323
"product_version": "patch: 0.7.38-2.hum1"
24+
},
25+
{
26+
"id": "233238da-2002-3cc8-8dd1-bb95479f1693",
27+
"product": {
28+
"name": "Red Hat Enterprise Linux 10",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
},
33+
"product_version": "patch: 0:0.7.33-5.el10_2"
2434
}
2535
],
2636
"enisaIdVendor": [

advisories/2026/06/EUVD-2020-31259.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "2a01225b-6979-3402-9c84-4dd517bd7150",
44
"description": "Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
55
"datePublished": "Jun 23, 2026, 6:00:16 PM",
6-
"dateUpdated": "Jun 23, 2026, 6:00:16 PM",
6+
"dateUpdated": "Jun 24, 2026, 3:56:28 AM",
77
"baseScore": 7.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210326",
3+
"enisaUuid": "863c8d48-7bc2-3399-a4ef-dd5a9d9093b4",
4+
"description": "Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including blind and error-based extraction of data from the credential table.",
5+
"datePublished": "Jun 24, 2026, 11:53:05 AM",
6+
"dateUpdated": "Jun 24, 2026, 2:53:40 PM",
7+
"baseScore": 8.5,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9c4c-g95m-c8cp\nhttps://www.vulncheck.com/advisories/flowise-sql-injection-in-importchatflows-api-via-chatflow-id-parameter\n",
11+
"aliases": "CVE-2025-71332\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "10141949-13fb-3f36-bec1-31292db23230",
17+
"product": {
18+
"name": "Flowise",
19+
"vendor": {
20+
"name": "FlowiseAI"
21+
}
22+
},
23+
"product_version": "0 \u22642.2.7"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "45b647fd-cc8c-3ce3-9057-aedbd0da2bb9",
29+
"vendor": {
30+
"name": "Flowise"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210327",
3+
"enisaUuid": "fa4b337b-956a-32ae-9439-6b6e4eea2a69",
4+
"description": "picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code that bypasses picklescan detection and executes arbitrary commands when pickle.load() is called.",
5+
"datePublished": "Jun 24, 2026, 11:53:06 AM",
6+
"dateUpdated": "Jun 24, 2026, 12:49:30 PM",
7+
"baseScore": 7.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-3vg9-h568-4w9m\nhttps://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-idlelib-debugobj-objecttreeitem-settext\n",
11+
"aliases": "CVE-2025-71354\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1933e5f6-0cd1-3c95-8840-caf324eaf892",
17+
"product": {
18+
"name": "picklescan",
19+
"vendor": {
20+
"name": "mmaitre314"
21+
}
22+
},
23+
"product_version": "0 <0.0.29"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "71fde1ce-e9b5-3f04-b5ec-c2de41b4f302",
29+
"vendor": {
30+
"name": "Picklescan"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210328",
3+
"enisaUuid": "b1df1ec5-661e-336d-8daa-05bafbc6e97e",
4+
"description": "picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load().",
5+
"datePublished": "Jun 24, 2026, 11:53:07 AM",
6+
"dateUpdated": "Jun 24, 2026, 4:02:42 PM",
7+
"baseScore": 7.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-8r4j-24qv-fmq9\nhttps://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-undetected-idlelib-calltip-calltip-fetch-tip\n",
11+
"aliases": "CVE-2025-71361\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "b318b423-63cf-371b-8f74-c91e2549c8ca",
17+
"product": {
18+
"name": "picklescan",
19+
"vendor": {
20+
"name": "mmaitre314"
21+
}
22+
},
23+
"product_version": "0 <0.0.29"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "b808532c-b4be-31e8-88c0-cff6cf027bdc",
29+
"vendor": {
30+
"name": "Picklescan"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210329",
3+
"enisaUuid": "28198fb9-4f20-3aa5-b5d0-1c11ab8ad39f",
4+
"description": "Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the pages containing the listing of files will return HTTP error 500 and render the web interface unusable for the repository or wiki. The issue is present in file internal/route/repo/wiki.go and internal/route/repo/view.go where the pages try to recover commit information. If errors are returned while recovering commit information, the page will return a 500 error and stop rendering, resulting in a denial of service. This vulnerability is fixed in 0.14.3.",
5+
"datePublished": "Jun 24, 2026, 8:03:07 PM",
6+
"dateUpdated": "Jun 24, 2026, 8:03:07 PM",
7+
"baseScore": 4.9,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
10+
"references": "https://github.com/gogs/gogs/security/advisories/GHSA-3qq3-668m-v9mj\n",
11+
"aliases": "GHSA-3qq3-668m-v9mj\nCVE-2025-64719\n",
12+
"assigner": "GitHub_M",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "aaeeab90-7b7b-35d5-99b5-83328a78f25b",
17+
"product": {
18+
"name": "gogs",
19+
"vendor": {
20+
"name": "gogs"
21+
}
22+
},
23+
"product_version": "< 0.14.3"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "329af614-978b-30b3-8883-1fd66809236f",
29+
"vendor": {
30+
"name": "gogs"
31+
}
32+
}
33+
]
34+
}

advisories/2026/06/EUVD-2026-36906.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,16 @@
11
{
22
"id": "EUVD-2026-36906",
33
"enisaUuid": "b528685a-84e5-3022-981e-bdf0f7d0893b",
4-
"description": "OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template engine uses a single shared text/template.Template instance (tpl package-level variable in service/internal/tpl/templates.go) across all goroutines. Every action execution calls tpl.Parse(source) followed by t.Execute() on this shared instance with no synchronization. When two or more actions execute concurrently (which is the normal case \u2014 each ExecRequest spawns a goroutine), a race condition occurs: one goroutine's Parse overwrites the template tree while another goroutine is calling Execute, causing cross-user command contamination, Go runtime panic, and incorrect command execution. This issue has been resolved in version 3000.13.0.",
5-
"datePublished": "Jun 15, 2026, 7:59:27 PM",
6-
"dateUpdated": "Jun 15, 2026, 7:59:27 PM",
4+
"description": "OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination",
5+
"datePublished": "Jun 24, 2026, 5:38:12 PM",
6+
"dateUpdated": "Jun 24, 2026, 5:38:12 PM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-7fq5-7wr8-rjwj\nhttps://github.com/OliveTin/OliveTin/releases/tag/3000.13.0\n",
11-
"aliases": "CVE-2026-48708\n",
10+
"references": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-7fq5-7wr8-rjwj\nhttps://github.com/OliveTin/OliveTin/releases/tag/3000.13.0\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48708\nhttps://github.com/OliveTin/OliveTin/commit/d74da9314005954dd49fa20dabf272247bc76519\n",
11+
"aliases": "GHSA-7fq5-7wr8-rjwj\nCVE-2026-48708\n",
1212
"assigner": "GitHub_M",
13-
"epss": 0.0,
13+
"epss": 0.35,
1414
"enisaIdProduct": [
1515
{
1616
"id": "b4ee2b02-5033-3a59-bd8f-b0502378d2ce",

0 commit comments

Comments
 (0)