Skip to content

Commit c4d5d38

Browse files
Sync EUVD catalog: Mon Sep 7 00:37:13 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 14eab53 commit c4d5d38

157 files changed

Lines changed: 8549 additions & 393 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2025/02/EUVD-2025-2098.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "ae3690f2-258c-3b04-9a61-d53956eb284f",
44
"description": "A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.",
55
"datePublished": "Feb 12, 2025, 2:27:45 PM",
6-
"dateUpdated": "Sep 4, 2026, 2:18:16 PM",
6+
"dateUpdated": "Sep 6, 2026, 1:37:43 AM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
@@ -33,9 +33,9 @@
3333
"product_version": "patch: 1:27.2-11.el9_5.1"
3434
},
3535
{
36-
"id": "2181d66c-e6f8-3197-a1c4-fe4a8fa049b5",
36+
"id": "1cca1330-c465-3796-ad3e-6fd7c30b7eb5",
3737
"product": {
38-
"name": "Builds for Red Hat OpenShift 1.3.1",
38+
"name": "Builds for Red Hat OpenShift 1.3.2",
3939
"vendor": {
4040
"name": "Red Hat"
4141
}

advisories/2025/02/EUVD-2025-4485.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "3e67f26c-2de4-3f2c-94bf-75d8025332ec",
44
"description": "A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.",
55
"datePublished": "Feb 10, 2025, 3:27:46 PM",
6-
"dateUpdated": "Sep 5, 2026, 5:03:41 PM",
6+
"dateUpdated": "Sep 6, 2026, 9:14:34 PM",
77
"baseScore": 5.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
@@ -32,6 +32,16 @@
3232
},
3333
"product_version": "patch: 2:18.2.1-381.el8cp"
3434
},
35+
{
36+
"id": "08723281-00f2-3801-a0ca-c0201ff86aa5",
37+
"product": {
38+
"name": "Red Hat Ceph Storage 9",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
42+
},
43+
"product_version": "patch: 1776359884"
44+
},
3545
{
3646
"id": "09b21c25-43aa-3656-b1c3-caaa5b322d01",
3747
"product": {
@@ -212,16 +222,6 @@
212222
},
213223
"product_version": "patch: v1.16.4-1747979846"
214224
},
215-
{
216-
"id": "cb906647-3db4-3922-a8a3-30bc6a24ccd2",
217-
"product": {
218-
"name": "Red Hat Ceph Storage 9.0",
219-
"vendor": {
220-
"name": "Red Hat"
221-
}
222-
},
223-
"product_version": "patch: 1776359884"
224-
},
225225
{
226226
"id": "e7ba1676-e950-3542-a2e6-a2a4b7e63ea1",
227227
"product": {

advisories/2025/04/EUVD-2025-9524.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "3c00498b-7691-3e1b-9a72-54b485f418e6",
44
"description": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.",
55
"datePublished": "Apr 2, 2025, 11:07:43 AM",
6-
"dateUpdated": "Sep 5, 2026, 5:33:31 PM",
6+
"dateUpdated": "Sep 6, 2026, 9:45:59 PM",
77
"baseScore": 4.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",

advisories/2025/04/EUVD-2025-9549.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "15628cee-8c54-37b3-b2b0-4f0b1d50c213",
44
"description": "A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.\nThis can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.",
55
"datePublished": "Apr 2, 2025, 11:09:55 AM",
6-
"dateUpdated": "Sep 5, 2026, 5:33:32 PM",
6+
"dateUpdated": "Sep 6, 2026, 9:46:06 PM",
77
"baseScore": 4.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",

advisories/2025/05/EUVD-2025-13592.json

Lines changed: 50 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "d222098e-3470-3ad4-8f3b-202bdc93e820",
44
"description": "A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.",
55
"datePublished": "May 6, 2025, 2:48:39 PM",
6-
"dateUpdated": "Sep 5, 2026, 4:28:00 PM",
6+
"dateUpdated": "Sep 6, 2026, 7:58:03 PM",
77
"baseScore": 4.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
@@ -23,9 +23,19 @@
2323
"product_version": "patch: 0:2.80.4-4.el10_0.6"
2424
},
2525
{
26-
"id": "097a2cde-5598-3c9d-a9fd-2ea77768c3c7",
26+
"id": "0ad555e7-6b11-390b-b655-0881b9e47ed7",
2727
"product": {
28-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
28+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
},
33+
"product_version": "patch: rhosdt-3.6-1753265330"
34+
},
35+
{
36+
"id": "0b1f6cb7-3e08-3924-ae86-30b444c5cde1",
37+
"product": {
38+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
2939
"vendor": {
3040
"name": "Red Hat"
3141
}
@@ -53,9 +63,9 @@
5363
"product_version": "patch: 0:2.56.4-8.el8_2.2"
5464
},
5565
{
56-
"id": "351949fc-7925-36b4-be8e-a0ffbfdd14e2",
66+
"id": "248cb581-e2c3-3a91-b238-9a69e3f2909f",
5767
"product": {
58-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
68+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
5969
"vendor": {
6070
"name": "Red Hat"
6171
}
@@ -93,14 +103,24 @@
93103
"product_version": "patch: 0:2.56.4-162.el8_8"
94104
},
95105
{
96-
"id": "5063791a-d80e-3c04-ab23-8c3bcdddfc5d",
106+
"id": "5145ee54-3c53-3de8-bbc6-c7bfe6350e12",
97107
"product": {
98-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
108+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
99109
"vendor": {
100110
"name": "Red Hat"
101111
}
102112
},
103-
"product_version": "patch: rhosdt-3.6-1753265342"
113+
"product_version": "patch: rhosdt-3.6-1753265411"
114+
},
115+
{
116+
"id": "5a45b436-6a39-3f05-a2a3-8db1c0d872a3",
117+
"product": {
118+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
119+
"vendor": {
120+
"name": "Red Hat"
121+
}
122+
},
123+
"product_version": "patch: rhosdt-3.6-1753269432"
104124
},
105125
{
106126
"id": "5b6313c9-03b1-3491-83b8-1f9eeeb9a8c6",
@@ -122,6 +142,26 @@
122142
},
123143
"product_version": "patch: 0:2.68.4-16.el9_6.2"
124144
},
145+
{
146+
"id": "7849d4f2-07fe-35e2-aaac-57d74398ba85",
147+
"product": {
148+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
149+
"vendor": {
150+
"name": "Red Hat"
151+
}
152+
},
153+
"product_version": "patch: rhosdt-3.6-1753265394"
154+
},
155+
{
156+
"id": "7dc0760f-90b2-374c-8649-fb9e5fa4baf6",
157+
"product": {
158+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
159+
"vendor": {
160+
"name": "Red Hat"
161+
}
162+
},
163+
"product_version": "patch: rhosdt-3.6-1753265342"
164+
},
125165
{
126166
"id": "80bec807-6392-3ea0-97c4-2c711abc34af",
127167
"product": {
@@ -143,9 +183,9 @@
143183
"product_version": "patch: 0:2.56.4-158.el8_6.2"
144184
},
145185
{
146-
"id": "ba437907-1268-335e-9dc6-9d3a532d3d64",
186+
"id": "8fde987b-225c-338c-8dd1-8207fa5bd81d",
147187
"product": {
148-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
188+
"name": "Red Hat OpenShift distributed tracing 3.6.0",
149189
"vendor": {
150190
"name": "Red Hat"
151191
}
@@ -172,16 +212,6 @@
172212
},
173213
"product_version": "patch: 0:2.56.4-166.el8_10"
174214
},
175-
{
176-
"id": "dd58141b-0e06-3c39-bf20-ca161b0eead8",
177-
"product": {
178-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
179-
"vendor": {
180-
"name": "Red Hat"
181-
}
182-
},
183-
"product_version": "patch: rhosdt-3.6-1753269432"
184-
},
185215
{
186216
"id": "ddac9b6e-43bb-32bf-8dca-7ae554669bf8",
187217
"product": {
@@ -192,26 +222,6 @@
192222
},
193223
"product_version": "patch: 0:2.56.4-158.el8_6.2"
194224
},
195-
{
196-
"id": "ddca59d0-2646-3702-9c29-299fc4995285",
197-
"product": {
198-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
199-
"vendor": {
200-
"name": "Red Hat"
201-
}
202-
},
203-
"product_version": "patch: rhosdt-3.6-1753265330"
204-
},
205-
{
206-
"id": "e285e5d4-afca-3132-b8a2-eab578fe6233",
207-
"product": {
208-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
209-
"vendor": {
210-
"name": "Red Hat"
211-
}
212-
},
213-
"product_version": "patch: rhosdt-3.6-1753265394"
214-
},
215225
{
216226
"id": "f0e0a410-488a-3ed7-8313-e0e403a973f1",
217227
"product": {
@@ -222,16 +232,6 @@
222232
},
223233
"product_version": "patch: 0:2.56.4-162.el8_8"
224234
},
225-
{
226-
"id": "f19d09bd-8aec-3d48-a278-3aa2b68cbffe",
227-
"product": {
228-
"name": "Red Hat OpenShift distributed tracing 3.6.1",
229-
"vendor": {
230-
"name": "Red Hat"
231-
}
232-
},
233-
"product_version": "patch: rhosdt-3.6-1753265411"
234-
},
235235
{
236236
"id": "ffc15292-78ef-3d23-8f01-d6f77c45ee4e",
237237
"product": {

advisories/2025/05/EUVD-2025-16308.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "07c15a9d-0599-3306-957c-8189492862ad",
44
"description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
55
"datePublished": "May 27, 2025, 8:52:58 PM",
6-
"dateUpdated": "Sep 5, 2026, 4:00:41 PM",
6+
"dateUpdated": "Sep 6, 2026, 9:46:10 PM",
77
"baseScore": 4.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
@@ -82,6 +82,16 @@
8282
},
8383
"product_version": "patch: 1782510941"
8484
},
85+
{
86+
"id": "53eec7b0-84e8-3f79-b376-ab0325f33d8a",
87+
"product": {
88+
"name": "Cost Management 4",
89+
"vendor": {
90+
"name": "Red Hat"
91+
}
92+
},
93+
"product_version": "patch: 1783539156"
94+
},
8595
{
8696
"id": "5b0dbea9-8ce0-30cf-81fa-c57affef064b",
8797
"product": {
@@ -192,16 +202,6 @@
192202
},
193203
"product_version": "patch: 1782501180"
194204
},
195-
{
196-
"id": "e4c5f4a4-17b9-3f3e-9aa5-1f8d7a5d0f38",
197-
"product": {
198-
"name": "Cost Management Metrics Operator 4",
199-
"vendor": {
200-
"name": "Red Hat"
201-
}
202-
},
203-
"product_version": "patch: 1783539156"
204-
},
205205
{
206206
"id": "e95c78ec-c8e1-317b-9843-25ce38ca23f0",
207207
"product": {

advisories/2025/06/EUVD-2025-17572.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "f8a0a0e3-5848-3b1f-a267-f702d529f3a5",
44
"description": "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.",
55
"datePublished": "Jun 9, 2025, 7:53:48 PM",
6-
"dateUpdated": "Sep 5, 2026, 3:18:47 PM",
6+
"dateUpdated": "Sep 6, 2026, 3:56:32 AM",
77
"baseScore": 7.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
@@ -182,16 +182,6 @@
182182
},
183183
"product_version": "patch: 1.36.0-11"
184184
},
185-
{
186-
"id": "6364de2d-3241-385b-a59c-3ce1efbfc2d0",
187-
"product": {
188-
"name": "File Integrity Operator 1",
189-
"vendor": {
190-
"name": "Red Hat"
191-
}
192-
},
193-
"product_version": "patch: v1.3"
194-
},
195185
{
196186
"id": "6509d724-9e3f-3b36-a982-0eaa22fe3bc0",
197187
"product": {
@@ -541,6 +531,16 @@
541531
}
542532
},
543533
"product_version": "patch: 414.92.202510211419-0"
534+
},
535+
{
536+
"id": "f9b8dca3-77d9-3904-8c7f-1cba6c643c42",
537+
"product": {
538+
"name": "OpenShift File Integrity Operator - FIO 1",
539+
"vendor": {
540+
"name": "Red Hat"
541+
}
542+
},
543+
"product_version": "patch: v1.3"
544544
}
545545
],
546546
"enisaIdVendor": [

advisories/2025/06/EUVD-2025-18412.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "42bf11b0-c478-39d2-b637-c43c3c5f83df",
44
"description": "A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path=\"...\"/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.",
55
"datePublished": "Jun 16, 2025, 3:24:31 PM",
6-
"dateUpdated": "Sep 1, 2026, 11:47:46 AM",
6+
"dateUpdated": "Sep 6, 2026, 3:57:12 AM",
77
"baseScore": 9.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
@@ -42,6 +42,16 @@
4242
},
4343
"product_version": "patch: 414.92.202510211419-0"
4444
},
45+
{
46+
"id": "2dedd805-8c67-32a2-a9fe-5cd9b27a7e3f",
47+
"product": {
48+
"name": "OpenShift File Integrity Operator - FIO 1",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
52+
},
53+
"product_version": "patch: v1.3"
54+
},
4555
{
4656
"id": "35d1d51a-b60f-3a29-84ca-68949841e9e5",
4757
"product": {
@@ -232,16 +242,6 @@
232242
},
233243
"product_version": "patch: 4.19.9.6.202510140714-0"
234244
},
235-
{
236-
"id": "af93fc95-debf-3eef-b993-c25c426fe409",
237-
"product": {
238-
"name": "File Integrity Operator 1",
239-
"vendor": {
240-
"name": "Red Hat"
241-
}
242-
},
243-
"product_version": "patch: v1.3"
244-
},
245245
{
246246
"id": "b9b0792b-b20b-3b1a-b9da-651e26d702af",
247247
"product": {

0 commit comments

Comments
 (0)