Skip to content

Commit caf6ed2

Browse files
Sync EUVD catalog: Sun May 10 00:49:43 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent b238277 commit caf6ed2

148 files changed

Lines changed: 5350 additions & 285 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2017-11587",
3+
"enisaUuid": "7cfd1893-17b6-3322-9e75-ccda49c19e95",
4+
"description": "An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the \"Quick Look\" component. It allows remote attackers to trigger telephone calls to arbitrary numbers via a tel: URL in a PDF document, as exploited in the wild in October 2016.",
5+
"datePublished": "Apr 2, 2017, 1:36:00 AM",
6+
"dateUpdated": "May 9, 2026, 3:55:43 AM",
7+
"baseScore": 3.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
10+
"references": "https://www.engadget.com/2017/03/31/apple-fixes-ios-loophole-911-overload/\nhttp://www.securitytracker.com/id/1038139\nhttp://www.securityfocus.com/bid/97138\nhttps://support.apple.com/HT207617\n",
11+
"aliases": "CVE-2017-2404\nGHSA-v4vc-g9wm-7cc9\n",
12+
"assigner": "apple",
13+
"epss": 0.53,
14+
"enisaIdProduct": [
15+
{
16+
"id": "36cbff21-0cad-3fa7-a4f8-f08677270f09",
17+
"product": {
18+
"name": "n/a"
19+
},
20+
"product_version": "n/a"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "d875dad5-9b8c-3b8a-898e-49bdc6d431c9",
26+
"vendor": {
27+
"name": "n/a"
28+
}
29+
}
30+
]
31+
}

advisories/2025/12/EUVD-2025-204462.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "fe776e52-787b-302b-bf1c-1b6401223f46",
44
"description": "A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.",
55
"datePublished": "Dec 19, 2025, 7:11:12 AM",
6-
"dateUpdated": "Dec 19, 2025, 5:18:05 PM",
6+
"dateUpdated": "May 9, 2026, 3:40:53 AM",
77
"baseScore": 5.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
10-
"references": "https://www.foxit.com/support/security-bulletins.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-66498\n",
10+
"references": "https://www.foxit.com/support/security-bulletins.html\n",
1111
"aliases": "GHSA-w4jg-8w9c-f6rv\nCVE-2025-66498\n",
1212
"assigner": "Foxit",
13-
"epss": 0.02,
13+
"epss": 0.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "21e446af-a920-32bc-a35c-3b47ca15ab7c",

advisories/2025/12/EUVD-2025-204463.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "cd1c30fe-90d1-3466-92be-5cc715fd46bc",
44
"description": "A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.",
55
"datePublished": "Dec 19, 2025, 7:10:30 AM",
6-
"dateUpdated": "Dec 19, 2025, 5:18:44 PM",
6+
"dateUpdated": "May 9, 2026, 3:39:59 AM",
77
"baseScore": 5.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
10-
"references": "https://www.foxit.com/support/security-bulletins.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-66497\n",
10+
"references": "https://www.foxit.com/support/security-bulletins.html\n",
1111
"aliases": "CVE-2025-66497\nGHSA-53hw-7r73-89x3\n",
1212
"assigner": "Foxit",
13-
"epss": 0.02,
13+
"epss": 0.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "10fc162c-fe29-347f-95b8-772185a3bb3f",

advisories/2025/12/EUVD-2025-204464.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "3b66c3b8-5346-3328-be4a-3750999356fa",
44
"description": "A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.",
55
"datePublished": "Dec 19, 2025, 7:10:13 AM",
6-
"dateUpdated": "Dec 19, 2025, 5:19:26 PM",
6+
"dateUpdated": "May 9, 2026, 3:39:03 AM",
77
"baseScore": 5.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
10-
"references": "https://www.foxit.com/support/security-bulletins.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-66496\n",
10+
"references": "https://www.foxit.com/support/security-bulletins.html\n",
1111
"aliases": "CVE-2025-66496\nGHSA-vf25-p22q-rg8q\n",
1212
"assigner": "Foxit",
13-
"epss": 0.02,
13+
"epss": 0.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "1c1a282b-40b3-3e33-b2db-1daca3b7e478",

advisories/2026/03/EUVD-2026-13097.json

Lines changed: 73 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "e56690d0-bd77-3749-b1dc-cfa65800ac55",
44
"description": "A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.",
55
"datePublished": "Mar 19, 2026, 1:50:27 PM",
6-
"dateUpdated": "Apr 30, 2026, 12:47:07 PM",
6+
"dateUpdated": "May 9, 2026, 12:08:34 AM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
10-
"references": "https://access.redhat.com/errata/RHSA-2026:10065\nhttps://access.redhat.com/errata/RHSA-2026:10097\nhttps://access.redhat.com/errata/RHSA-2026:11768\nhttps://access.redhat.com/errata/RHSA-2026:8492\nhttps://access.redhat.com/errata/RHSA-2026:8510\nhttps://access.redhat.com/errata/RHSA-2026:8517\nhttps://access.redhat.com/errata/RHSA-2026:8521\nhttps://access.redhat.com/errata/RHSA-2026:8534\nhttps://access.redhat.com/errata/RHSA-2026:8864\nhttps://access.redhat.com/errata/RHSA-2026:8865\nhttps://access.redhat.com/errata/RHSA-2026:8866\nhttps://access.redhat.com/errata/RHSA-2026:8867\nhttps://access.redhat.com/errata/RHSA-2026:8873\nhttps://access.redhat.com/errata/RHSA-2026:8908\nhttps://access.redhat.com/errata/RHSA-2026:8944\nhttps://access.redhat.com/errata/RHSA-2026:9026\nhttps://access.redhat.com/errata/RHSA-2026:9592\nhttps://access.redhat.com/errata/RHSA-2026:9832\nhttps://access.redhat.com/security/cve/CVE-2026-4424\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2449006\nhttps://github.com/libarchive/libarchive/pull/2898\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:10065\nhttps://access.redhat.com/errata/RHSA-2026:10097\nhttps://access.redhat.com/errata/RHSA-2026:11768\nhttps://access.redhat.com/errata/RHSA-2026:12274\nhttps://access.redhat.com/errata/RHSA-2026:13812\nhttps://access.redhat.com/errata/RHSA-2026:14937\nhttps://access.redhat.com/errata/RHSA-2026:8492\nhttps://access.redhat.com/errata/RHSA-2026:8510\nhttps://access.redhat.com/errata/RHSA-2026:8517\nhttps://access.redhat.com/errata/RHSA-2026:8521\nhttps://access.redhat.com/errata/RHSA-2026:8534\nhttps://access.redhat.com/errata/RHSA-2026:8864\nhttps://access.redhat.com/errata/RHSA-2026:8865\nhttps://access.redhat.com/errata/RHSA-2026:8866\nhttps://access.redhat.com/errata/RHSA-2026:8867\nhttps://access.redhat.com/errata/RHSA-2026:8873\nhttps://access.redhat.com/errata/RHSA-2026:8908\nhttps://access.redhat.com/errata/RHSA-2026:8944\nhttps://access.redhat.com/errata/RHSA-2026:9026\nhttps://access.redhat.com/errata/RHSA-2026:9592\nhttps://access.redhat.com/errata/RHSA-2026:9832\nhttps://access.redhat.com/security/cve/CVE-2026-4424\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2449006\nhttps://github.com/libarchive/libarchive/pull/2898\n",
1111
"aliases": "CVE-2026-4424\n",
1212
"assigner": "redhat",
13-
"epss": 0.3,
13+
"epss": 0.36,
1414
"enisaIdProduct": [
1515
{
1616
"id": "05626d50-27c6-3681-96e1-5ea1ea171357",
@@ -54,13 +54,27 @@
5454
},
5555
"product_version": "patch: 0:3.3.3-6.el8_6.1"
5656
},
57+
{
58+
"id": "24a88f97-354e-36f3-9b42-41df316be4aa",
59+
"product": {
60+
"name": "RHEL-8 based Middleware Containers"
61+
},
62+
"product_version": "patch: 7.13.5-3.1777325680"
63+
},
5764
{
5865
"id": "2d6aa4b8-b701-3247-9a7d-29979268e057",
5966
"product": {
6067
"name": "Red Hat Update Infrastructure 5"
6168
},
6269
"product_version": "patch: 1776868774"
6370
},
71+
{
72+
"id": "2f9ce043-df34-3ae8-8c6e-b217e3cfd13d",
73+
"product": {
74+
"name": "RHEL-8 based Middleware Containers"
75+
},
76+
"product_version": "patch: 7.13.5-4.1777325708"
77+
},
6478
{
6579
"id": "2fd13481-e2cb-3256-ae54-6493d8d0b55c",
6680
"product": {
@@ -75,6 +89,13 @@
7589
},
7690
"product_version": "patch: 3.8.7-1.hum1"
7791
},
92+
{
93+
"id": "3e5a3c34-7cf5-3afa-a73d-1f76ab3980ea",
94+
"product": {
95+
"name": "RHEL-8 based Middleware Containers"
96+
},
97+
"product_version": "patch: 7.13.5-4.1777325710"
98+
},
7899
{
79100
"id": "4d115ff4-89e1-3aa0-adc5-f0aa11f6467e",
80101
"product": {
@@ -96,6 +117,13 @@
96117
},
97118
"product_version": "patch: 0:3.1.2-14.el7_9.2"
98119
},
120+
{
121+
"id": "59072756-0d7a-3043-95bd-e0e1d8934f2b",
122+
"product": {
123+
"name": "Red Hat Discovery 2"
124+
},
125+
"product_version": "patch: 1778101579"
126+
},
99127
{
100128
"id": "647daefa-b9e7-33af-a399-679694464c75",
101129
"product": {
@@ -138,13 +166,41 @@
138166
},
139167
"product_version": "patch: 0:3.5.3-9.el9_7"
140168
},
169+
{
170+
"id": "943c4a1e-a069-3b5a-9c91-af630c979b43",
171+
"product": {
172+
"name": "RHEL-8 based Middleware Containers"
173+
},
174+
"product_version": "patch: 7.13.5-4.1777325677"
175+
},
141176
{
142177
"id": "94e13645-338b-32d0-8812-b0ca13380273",
143178
"product": {
144179
"name": "Red Hat Update Infrastructure 5"
145180
},
146181
"product_version": "patch: 1776868842"
147182
},
183+
{
184+
"id": "95367dd3-a7da-3995-b486-0643ef8612de",
185+
"product": {
186+
"name": "RHEL-8 based Middleware Containers"
187+
},
188+
"product_version": "patch: 7.13.5-4.1777325711"
189+
},
190+
{
191+
"id": "98de134e-89b9-3f00-86ec-aa90e54f5e90",
192+
"product": {
193+
"name": "RHEL-8 based Middleware Containers"
194+
},
195+
"product_version": "patch: 7.13.5-4.1777325709"
196+
},
197+
{
198+
"id": "9b5a3298-6df0-3d4d-b9c3-8e4e5a5b4762",
199+
"product": {
200+
"name": "Red Hat Discovery 2"
201+
},
202+
"product_version": "patch: 1778156756"
203+
},
148204
{
149205
"id": "9ca3ac2a-1a76-3a25-874b-9739d1817b60",
150206
"product": {
@@ -194,6 +250,20 @@
194250
},
195251
"product_version": "patch: 1776868772"
196252
},
253+
{
254+
"id": "d007452d-73eb-3e33-bc5c-0520289039be",
255+
"product": {
256+
"name": "RHEL-8 based Middleware Containers"
257+
},
258+
"product_version": "patch: 7.13.5-4.1777325680"
259+
},
260+
{
261+
"id": "d1f159c0-b6a6-34f3-a308-c8cef58a53d1",
262+
"product": {
263+
"name": "Red Hat OpenShift Container Platform 4.12"
264+
},
265+
"product_version": "patch: 412.86.202604281506-0"
266+
},
197267
{
198268
"id": "d6600a3f-bd85-3e67-9243-d349fc0f5af9",
199269
"product": {

advisories/2026/03/EUVD-2026-17073.json

Lines changed: 66 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "af65621c-2a3d-3460-bb5e-6ec0ed762505",
44
"description": "A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.",
55
"datePublished": "Mar 30, 2026, 7:47:28 AM",
6-
"dateUpdated": "Apr 30, 2026, 1:35:40 PM",
6+
"dateUpdated": "May 9, 2026, 12:08:54 AM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
10-
"references": "https://access.redhat.com/errata/RHSA-2026:10065\nhttps://access.redhat.com/errata/RHSA-2026:10097\nhttps://access.redhat.com/errata/RHSA-2026:11768\nhttps://access.redhat.com/errata/RHSA-2026:8510\nhttps://access.redhat.com/errata/RHSA-2026:8517\nhttps://access.redhat.com/errata/RHSA-2026:8521\nhttps://access.redhat.com/errata/RHSA-2026:8534\nhttps://access.redhat.com/errata/RHSA-2026:8864\nhttps://access.redhat.com/errata/RHSA-2026:8866\nhttps://access.redhat.com/errata/RHSA-2026:8867\nhttps://access.redhat.com/errata/RHSA-2026:8873\nhttps://access.redhat.com/errata/RHSA-2026:8908\nhttps://access.redhat.com/errata/RHSA-2026:8944\nhttps://access.redhat.com/errata/RHSA-2026:9026\nhttps://access.redhat.com/errata/RHSA-2026:9592\nhttps://access.redhat.com/errata/RHSA-2026:9832\nhttps://access.redhat.com/security/cve/CVE-2026-5121\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2452945\nhttps://github.com/advisories/GHSA-2vwv-vqpv-v8vc\nhttps://github.com/libarchive/libarchive/pull/2934\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:10065\nhttps://access.redhat.com/errata/RHSA-2026:10097\nhttps://access.redhat.com/errata/RHSA-2026:11768\nhttps://access.redhat.com/errata/RHSA-2026:12274\nhttps://access.redhat.com/errata/RHSA-2026:13812\nhttps://access.redhat.com/errata/RHSA-2026:14937\nhttps://access.redhat.com/errata/RHSA-2026:8510\nhttps://access.redhat.com/errata/RHSA-2026:8517\nhttps://access.redhat.com/errata/RHSA-2026:8521\nhttps://access.redhat.com/errata/RHSA-2026:8534\nhttps://access.redhat.com/errata/RHSA-2026:8864\nhttps://access.redhat.com/errata/RHSA-2026:8866\nhttps://access.redhat.com/errata/RHSA-2026:8867\nhttps://access.redhat.com/errata/RHSA-2026:8873\nhttps://access.redhat.com/errata/RHSA-2026:8908\nhttps://access.redhat.com/errata/RHSA-2026:8944\nhttps://access.redhat.com/errata/RHSA-2026:9026\nhttps://access.redhat.com/errata/RHSA-2026:9592\nhttps://access.redhat.com/errata/RHSA-2026:9832\nhttps://access.redhat.com/security/cve/CVE-2026-5121\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2452945\nhttps://github.com/advisories/GHSA-2vwv-vqpv-v8vc\nhttps://github.com/libarchive/libarchive/pull/2934\n",
1111
"aliases": "CVE-2026-5121\nGHSA-2vwv-vqpv-v8vc\n",
1212
"assigner": "redhat",
13-
"epss": 0.1,
13+
"epss": 0.09,
1414
"enisaIdProduct": [
1515
{
1616
"id": "0c537b04-62f1-3ea3-9343-64524999d385",
@@ -19,6 +19,20 @@
1919
},
2020
"product_version": "patch: 1776868842"
2121
},
22+
{
23+
"id": "18fe47fe-ceb1-34e9-a4a7-7af1b49e2a3b",
24+
"product": {
25+
"name": "RHEL-8 based Middleware Containers"
26+
},
27+
"product_version": "patch: 7.13.5-4.1777325708"
28+
},
29+
{
30+
"id": "1bde1d59-6f95-3c6a-84d4-561a21acb09b",
31+
"product": {
32+
"name": "Red Hat Discovery 2"
33+
},
34+
"product_version": "patch: 1778156756"
35+
},
2236
{
2337
"id": "1fc49404-be72-36c6-be06-3f99f68956ac",
2438
"product": {
@@ -54,6 +68,27 @@
5468
},
5569
"product_version": "patch: 1776868772"
5670
},
71+
{
72+
"id": "43511389-e869-340a-ba38-e15c598ece91",
73+
"product": {
74+
"name": "RHEL-8 based Middleware Containers"
75+
},
76+
"product_version": "patch: 7.13.5-4.1777325710"
77+
},
78+
{
79+
"id": "43986ce7-50c7-3924-9eef-1a89c2edb946",
80+
"product": {
81+
"name": "RHEL-8 based Middleware Containers"
82+
},
83+
"product_version": "patch: 7.13.5-4.1777325709"
84+
},
85+
{
86+
"id": "44df5012-95e4-3902-9bac-fea613ad4a90",
87+
"product": {
88+
"name": "RHEL-8 based Middleware Containers"
89+
},
90+
"product_version": "patch: 7.13.5-4.1777325711"
91+
},
5792
{
5893
"id": "46f36589-4f84-38fd-9750-efb4ade76c9a",
5994
"product": {
@@ -96,13 +131,27 @@
96131
},
97132
"product_version": "patch: sha256:8fbf461b33717d3463e4f802b1a257b7e43d60c3e9568f710df83db36a04a4fe"
98133
},
134+
{
135+
"id": "61490e8b-3371-3a06-a89a-89e21a25fa83",
136+
"product": {
137+
"name": "Red Hat OpenShift Container Platform 4.12"
138+
},
139+
"product_version": "patch: 412.86.202604281506-0"
140+
},
99141
{
100142
"id": "626d3976-9046-3a82-9935-1851132c2816",
101143
"product": {
102144
"name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions"
103145
},
104146
"product_version": "patch: 0:3.5.3-2.el9_0.4"
105147
},
148+
{
149+
"id": "6c8d97c0-953b-37f8-b21c-f7093f529896",
150+
"product": {
151+
"name": "RHEL-8 based Middleware Containers"
152+
},
153+
"product_version": "patch: 7.13.5-3.1777325680"
154+
},
106155
{
107156
"id": "7ba056af-782c-3e8d-8519-0d87ccb57755",
108157
"product": {
@@ -180,6 +229,20 @@
180229
},
181230
"product_version": "patch: 1776868961"
182231
},
232+
{
233+
"id": "c35c54cd-e4d1-3b7a-84fb-8d45c25485fb",
234+
"product": {
235+
"name": "RHEL-8 based Middleware Containers"
236+
},
237+
"product_version": "patch: 7.13.5-4.1777325677"
238+
},
239+
{
240+
"id": "d803996f-47d8-354b-9767-802c62b26abe",
241+
"product": {
242+
"name": "RHEL-8 based Middleware Containers"
243+
},
244+
"product_version": "patch: 7.13.5-4.1777325680"
245+
},
183246
{
184247
"id": "d9d0357a-aef7-357d-8a0a-d82002025e5d",
185248
"product": {

advisories/2026/04/EUVD-2026-20897.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "20bb6425-f941-37c2-aa93-a30af8a376b7",
44
"description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
55
"datePublished": "Apr 9, 2026, 2:41:18 PM",
6-
"dateUpdated": "Apr 9, 2026, 2:41:18 PM",
6+
"dateUpdated": "May 9, 2026, 10:21:48 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
1010
"references": "https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645\nhttps://github.com/pnggroup/libpng/issues/836\nhttps://github.com/pnggroup/libpng/issues/837\nhttps://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a\nhttps://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc\n",
1111
"aliases": "CVE-2026-34757\n",
1212
"assigner": "GitHub_M",
13-
"epss": 0.0,
13+
"epss": 0.02,
1414
"enisaIdProduct": [
1515
{
1616
"id": "5ace09b8-9125-3b57-938c-4290916dcaf5",

advisories/2026/05/EUVD-2025-209740.json

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,15 @@
22
"id": "EUVD-2025-209740",
33
"enisaUuid": "2ba227e5-1984-3714-8427-3c4c0c5981d4",
44
"description": "The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup.\n\nUsers are recommended to upgrade to version 4.22.0.1, which fixes the issue.",
5-
"datePublished": "May 8, 2026, 3:31:20 PM",
6-
"dateUpdated": "May 8, 2026, 3:31:20 PM",
7-
"baseScore": 0.0,
8-
"references": "https://lists.apache.org/thread/n8mt5b7wkpysstb8w7rr9f02kc5cq2xm\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-66170\n",
5+
"datePublished": "May 8, 2026, 12:06:32 PM",
6+
"dateUpdated": "May 9, 2026, 6:42:58 AM",
7+
"baseScore": 6.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
10+
"references": "https://lists.apache.org/thread/n8mt5b7wkpysstb8w7rr9f02kc5cq2xm\n",
911
"aliases": "CVE-2025-66170\nGHSA-7p28-jcmx-86m5\n",
1012
"assigner": "apache",
11-
"epss": 0.0,
13+
"epss": 0.01,
1214
"enisaIdProduct": [
1315
{
1416
"id": "1d72bcc7-c15b-30e2-a68a-b0f447fd69d6",

0 commit comments

Comments
 (0)