Skip to content

Commit ea2398f

Browse files
Sync EUVD catalog: Tue Sep 1 00:41:00 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent a9479e3 commit ea2398f

2,090 files changed

Lines changed: 21210 additions & 2964 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2024/05/EUVD-2024-1469.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "9e0c8f1f-bde2-3323-89f4-371cbd10e814",
44
"description": "A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.",
55
"datePublished": "May 9, 2024, 2:57:21 PM",
6-
"dateUpdated": "Aug 21, 2026, 5:56:37 PM",
6+
"dateUpdated": "Aug 31, 2026, 5:00:31 PM",
77
"baseScore": 8.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",

advisories/2024/07/EUVD-2024-47981.json

Lines changed: 31 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -3,61 +3,82 @@
33
"enisaUuid": "effba28d-637b-38a8-b4dd-07ba523914b7",
44
"description": "A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.",
55
"datePublished": "Jul 1, 2024, 12:37:25 PM",
6-
"dateUpdated": "Dec 11, 2025, 6:17:03 AM",
6+
"dateUpdated": "Aug 31, 2026, 4:48:18 PM",
77
"baseScore": 8.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://access.redhat.com/errata/RHSA-2024:4312\nhttps://access.redhat.com/errata/RHSA-2024:4340\nhttps://access.redhat.com/errata/RHSA-2024:4389\nhttps://access.redhat.com/errata/RHSA-2024:4469\nhttps://access.redhat.com/errata/RHSA-2024:4474\nhttps://access.redhat.com/errata/RHSA-2024:4479\nhttps://access.redhat.com/errata/RHSA-2024:4484\nhttps://access.redhat.com/security/cve/CVE-2024-6387\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2294604\nhttps://santandersecurityresearch.github.io/blog/sshing_the_masses.html\nhttps://www.openssh.com/txt/release-9.8\nhttps://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-6387\nhttps://github.com/rapier1/hpn-ssh/issues/87\nhttps://github.com/oracle/oracle-linux/issues/149\nhttps://github.com/microsoft/azurelinux/issues/9555\nhttps://github.com/PowerShell/Win32-OpenSSH/issues/2249\nhttps://github.com/Azure/AKS/issues/4379\nhttps://github.com/AlmaLinux/updates/issues/629\nhttps://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e19697cad09\nhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010\nhttps://security-tracker.debian.org/tracker/CVE-2024-6387\nhttps://security.netapp.com/advisory/ntap-20240701-0001\nhttps://sig-security.rocky.page/issues/CVE-2024-6387\nhttps://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution\nhttps://support.apple.com/kb/HT214118\nhttps://support.apple.com/kb/HT214119\nhttps://support.apple.com/kb/HT214120\nhttps://ubuntu.com/security/CVE-2024-6387\nhttps://ubuntu.com/security/notices/USN-6859-1\nhttps://www.akamai.com/blog/security-research/2024-openssh-vulnerability-regression-what-to-know-and-do\nhttps://www.arista.com/en/support/advisories-notices/security-advisory/19904-security-advisory-0100\nhttps://www.exploit-db.com/exploits/52269\nhttps://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc\nhttps://www.splunk.com/en_us/blog/security/cve-2024-6387-regresshion-vulnerability.html\nhttps://www.suse.com/security/cve/CVE-2024-6387.html\nhttps://www.theregister.com/2024/07/01/regresshion_openssh\nhttps://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387\nhttps://archlinux.org/news/the-sshd-service-needs-to-be-restarted-after-upgrading-to-openssh-98p1\nhttps://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux\nhttps://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server\nhttps://explore.alas.aws.amazon.com/CVE-2024-6387.html\nhttps://forum.vmssoftware.com/viewtopic.php?f=8&t=9132\nhttps://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc\nhttps://github.com/PowerShell/Win32-OpenSSH/discussions/2248\nhttps://github.com/zgzhang/cve-2024-6387-poc\nhttps://lists.almalinux.org/archives/list/announce@lists.almalinux.org/thread/23BF5BMGFVEVUI2WNVAGMLKT557EU7VY\nhttps://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html\nhttps://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html\nhttps://news.ycombinator.com/item?id=40843778\nhttps://packetstorm.news/files/id/190587\nhttp://seclists.org/fulldisclosure/2024/Jul/18\nhttp://seclists.org/fulldisclosure/2024/Jul/19\nhttp://seclists.org/fulldisclosure/2024/Jul/20\nhttp://www.openwall.com/lists/oss-security/2024/07/01/12\nhttp://www.openwall.com/lists/oss-security/2024/07/01/13\nhttp://www.openwall.com/lists/oss-security/2024/07/02/1\nhttp://www.openwall.com/lists/oss-security/2024/07/03/1\nhttp://www.openwall.com/lists/oss-security/2024/07/03/11\nhttp://www.openwall.com/lists/oss-security/2024/07/03/2\nhttp://www.openwall.com/lists/oss-security/2024/07/03/3\nhttp://www.openwall.com/lists/oss-security/2024/07/03/4\nhttp://www.openwall.com/lists/oss-security/2024/07/03/5\nhttp://www.openwall.com/lists/oss-security/2024/07/04/1\nhttp://www.openwall.com/lists/oss-security/2024/07/04/2\nhttp://www.openwall.com/lists/oss-security/2024/07/08/2\nhttp://www.openwall.com/lists/oss-security/2024/07/08/3\nhttp://www.openwall.com/lists/oss-security/2024/07/09/2\nhttp://www.openwall.com/lists/oss-security/2024/07/09/5\nhttp://www.openwall.com/lists/oss-security/2024/07/10/1\nhttp://www.openwall.com/lists/oss-security/2024/07/10/2\nhttp://www.openwall.com/lists/oss-security/2024/07/10/3\nhttp://www.openwall.com/lists/oss-security/2024/07/10/4\nhttp://www.openwall.com/lists/oss-security/2024/07/10/6\nhttp://www.openwall.com/lists/oss-security/2024/07/11/1\nhttp://www.openwall.com/lists/oss-security/2024/07/11/3\nhttp://www.openwall.com/lists/oss-security/2024/07/23/4\nhttp://www.openwall.com/lists/oss-security/2024/07/23/6\nhttp://www.openwall.com/lists/oss-security/2024/07/28/2\nhttp://www.openwall.com/lists/oss-security/2024/07/28/3\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2024:4312\nhttps://access.redhat.com/errata/RHSA-2024:4340\nhttps://access.redhat.com/errata/RHSA-2024:4389\nhttps://access.redhat.com/errata/RHSA-2024:4469\nhttps://access.redhat.com/errata/RHSA-2024:4474\nhttps://access.redhat.com/errata/RHSA-2024:4479\nhttps://access.redhat.com/errata/RHSA-2024:4484\nhttps://access.redhat.com/security/cve/CVE-2024-6387\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2294604\nhttps://santandersecurityresearch.github.io/blog/sshing_the_masses.html\nhttps://www.openssh.com/txt/release-9.8\nhttps://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt\n",
1111
"aliases": "CVE-2024-6387\nGHSA-2x8c-95vh-gfv4\n",
1212
"assigner": "redhat",
13-
"epss": 48.06,
13+
"epss": 99.51,
1414
"enisaIdProduct": [
1515
{
1616
"id": "2071bd3a-7bb1-304f-94a1-87fb9ba57751",
1717
"product": {
18-
"name": "Red Hat Enterprise Linux 9"
18+
"name": "Red Hat Enterprise Linux 9",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
1922
},
2023
"product_version": "patch: 0:8.7p1-38.el9_4.1"
2124
},
2225
{
2326
"id": "535949f9-174a-36bb-98d1-1832b173412a",
2427
"product": {
25-
"name": "Red Hat OpenShift Container Platform 4.15"
28+
"name": "Red Hat OpenShift Container Platform 4.15",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
2632
},
2733
"product_version": "patch: 415.92.202407091355-0"
2834
},
2935
{
3036
"id": "8223aef8-bd71-32b8-9221-75ebe4c2c84c",
3137
"product": {
32-
"name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions"
38+
"name": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
3342
},
3443
"product_version": "patch: 0:8.7p1-12.el9_0.1"
3544
},
3645
{
3746
"id": "b7b21ea6-83f9-3878-b5af-25843dc65dcc",
3847
"product": {
39-
"name": "Red Hat OpenShift Container Platform 4.13"
48+
"name": "Red Hat OpenShift Container Platform 4.13",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
4052
},
4153
"product_version": "patch: 413.92.202407091321-0"
4254
},
4355
{
4456
"id": "ddf6aed2-58c4-3c07-b32d-4584d3881864",
4557
"product": {
46-
"name": "Red Hat Enterprise Linux 9.2 Extended Update Support"
58+
"name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
4762
},
4863
"product_version": "patch: 0:8.7p1-30.el9_2.4"
4964
},
5065
{
5166
"id": "e7449d31-c1ac-37c9-bbe4-600a4043658a",
5267
"product": {
53-
"name": "Red Hat OpenShift Container Platform 4.16"
68+
"name": "Red Hat OpenShift Container Platform 4.16",
69+
"vendor": {
70+
"name": "Red Hat"
71+
}
5472
},
5573
"product_version": "patch: 416.94.202407081958-0"
5674
},
5775
{
5876
"id": "f683dc31-f291-318a-8075-70ca70cb7272",
5977
"product": {
60-
"name": "Red Hat OpenShift Container Platform 4.14"
78+
"name": "Red Hat OpenShift Container Platform 4.14",
79+
"vendor": {
80+
"name": "Red Hat"
81+
}
6182
},
6283
"product_version": "patch: 414.92.202407091253-0"
6384
}

advisories/2024/08/EUVD-2024-48876.json

Lines changed: 47 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -3,89 +3,122 @@
33
"enisaUuid": "dbca31b4-ae8b-3302-9c87-05126dd23595",
44
"description": "A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.",
55
"datePublished": "Aug 5, 2024, 1:19:27 PM",
6-
"dateUpdated": "Nov 6, 2025, 11:16:17 PM",
6+
"dateUpdated": "Aug 31, 2026, 5:00:39 PM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.0",
99
"baseScoreVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10-
"references": "https://access.redhat.com/errata/RHSA-2024:10518\nhttps://access.redhat.com/errata/RHSA-2024:10528\nhttps://access.redhat.com/errata/RHSA-2024:10813\nhttps://access.redhat.com/errata/RHSA-2024:6811\nhttps://access.redhat.com/errata/RHSA-2024:6818\nhttps://access.redhat.com/errata/RHSA-2024:6964\nhttps://access.redhat.com/errata/RHSA-2024:7408\nhttps://access.redhat.com/errata/RHSA-2024:8991\nhttps://access.redhat.com/errata/RHSA-2024:9136\nhttps://access.redhat.com/errata/RHSA-2024:9620\nhttps://access.redhat.com/errata/RHSA-2024:9912\nhttps://access.redhat.com/security/cve/CVE-2024-7409\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2302487\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-7409\nhttps://lists.debian.org/debian-lts-announce/2025/09/msg00011.html\nhttps://security.netapp.com/advisory/ntap-20250502-0008\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2024:10518\nhttps://access.redhat.com/errata/RHSA-2024:10528\nhttps://access.redhat.com/errata/RHSA-2024:10813\nhttps://access.redhat.com/errata/RHSA-2024:6811\nhttps://access.redhat.com/errata/RHSA-2024:6818\nhttps://access.redhat.com/errata/RHSA-2024:6964\nhttps://access.redhat.com/errata/RHSA-2024:7408\nhttps://access.redhat.com/errata/RHSA-2024:8991\nhttps://access.redhat.com/errata/RHSA-2024:9136\nhttps://access.redhat.com/errata/RHSA-2024:9620\nhttps://access.redhat.com/errata/RHSA-2024:9912\nhttps://access.redhat.com/security/cve/CVE-2024-7409\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2302487\n",
1111
"aliases": "GHSA-7c7g-wccp-rrhj\nCVE-2024-7409\n",
1212
"assigner": "redhat",
13-
"epss": 1.71,
13+
"epss": 1.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "072f4f62-0d84-3329-b5a8-1e3ca45520e7",
1717
"product": {
18-
"name": "Red Hat OpenShift Container Platform 4.17"
18+
"name": "Red Hat OpenShift Container Platform 4.17",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
1922
},
2023
"product_version": "patch: 417.94.202411261220-0"
2124
},
2225
{
2326
"id": "0fa6d882-f8f9-37c1-85f7-4016655f287b",
2427
"product": {
25-
"name": "Red Hat Enterprise Linux 9.4 Extended Update Support"
28+
"name": "Red Hat Enterprise Linux 9.4 Extended Update Support",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
2632
},
2733
"product_version": "patch: 17:8.2.0-11.el9_4.8"
2834
},
2935
{
3036
"id": "1a97ac85-466a-373d-9617-2370883623dc",
3137
"product": {
32-
"name": "Red Hat Enterprise Linux 9.2 Extended Update Support"
38+
"name": "Red Hat Enterprise Linux 9.2 Extended Update Support",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
3342
},
3443
"product_version": "patch: 17:7.2.0-14.el9_2.14"
3544
},
3645
{
3746
"id": "2c14e721-2b8a-36f8-b7b2-7983cd0085c0",
3847
"product": {
39-
"name": "Red Hat OpenShift Container Platform 4.13"
48+
"name": "Red Hat OpenShift Container Platform 4.13",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
4052
},
4153
"product_version": "patch: 413.92.202409180051-0"
4254
},
4355
{
4456
"id": "30a2999b-abb7-3af9-b97e-286eb1cb6159",
4557
"product": {
46-
"name": "Red Hat OpenShift Container Platform 4.16"
58+
"name": "Red Hat OpenShift Container Platform 4.16",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
4762
},
4863
"product_version": "patch: 416.94.202411261619-0"
4964
},
5065
{
5166
"id": "3b527fea-d047-38bb-af0a-63229a95379e",
5267
"product": {
53-
"name": "Red Hat OpenShift Container Platform 4.15"
68+
"name": "Red Hat OpenShift Container Platform 4.15",
69+
"vendor": {
70+
"name": "Red Hat"
71+
}
5472
},
5573
"product_version": "patch: 415.92.202411050056-0"
5674
},
5775
{
5876
"id": "53095694-7a65-3e75-8cb7-583516c429cf",
5977
"product": {
60-
"name": "Red Hat OpenShift Container Platform 4.13"
78+
"name": "Red Hat OpenShift Container Platform 4.13",
79+
"vendor": {
80+
"name": "Red Hat"
81+
}
6182
},
6283
"product_version": "patch: 413.92.202411212100-0"
6384
},
6485
{
6586
"id": "6c09c5aa-7618-3f9f-95d9-da6b46d3d215",
6687
"product": {
67-
"name": "Red Hat Enterprise Linux 9"
88+
"name": "Red Hat Enterprise Linux 9",
89+
"vendor": {
90+
"name": "Red Hat"
91+
}
6892
},
6993
"product_version": "patch: 17:9.0.0-10.el9_5"
7094
},
7195
{
7296
"id": "6f0d1731-a141-360f-afa9-c92fd99dec2f",
7397
"product": {
74-
"name": "Red Hat OpenShift Container Platform 4.14"
98+
"name": "Red Hat OpenShift Container Platform 4.14",
99+
"vendor": {
100+
"name": "Red Hat"
101+
}
75102
},
76103
"product_version": "patch: 414.92.202411130444-0"
77104
},
78105
{
79106
"id": "af449792-463d-318d-bcde-bdfd371f2b55",
80107
"product": {
81-
"name": "Red Hat OpenShift Container Platform 4.15"
108+
"name": "Red Hat OpenShift Container Platform 4.15",
109+
"vendor": {
110+
"name": "Red Hat"
111+
}
82112
},
83113
"product_version": "patch: 415.92.202409162258-0"
84114
},
85115
{
86116
"id": "b702bbba-f08b-3c9f-8cce-d5c293c1a28e",
87117
"product": {
88-
"name": "Red Hat Enterprise Linux 8"
118+
"name": "Red Hat Enterprise Linux 8",
119+
"vendor": {
120+
"name": "Red Hat"
121+
}
89122
},
90123
"product_version": "patch: 8100020240905091210.489197e6"
91124
}

advisories/2024/11/EUVD-2024-33602.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "3957bcbe-3edc-36f0-a909-511ea444eb3f",
44
"description": "A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.",
55
"datePublished": "Nov 7, 2024, 4:02:34 PM",
6-
"dateUpdated": "Aug 11, 2026, 2:55:19 PM",
6+
"dateUpdated": "Aug 31, 2026, 4:48:41 PM",
77
"baseScore": 7.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
1010
"references": "https://access.redhat.com/errata/RHSA-2024:10232\nhttps://access.redhat.com/errata/RHSA-2024:10244\nhttps://access.redhat.com/errata/RHSA-2024:10379\nhttps://access.redhat.com/errata/RHSA-2024:10518\nhttps://access.redhat.com/errata/RHSA-2024:10528\nhttps://access.redhat.com/errata/RHSA-2024:10852\nhttps://access.redhat.com/errata/RHSA-2024:6122\nhttps://access.redhat.com/security/cve/CVE-2024-10963\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2324291\nhttps://github.com/linux-pam/linux-pam/issues/834\nhttps://github.com/linux-pam/linux-pam/pull/835\n",
1111
"aliases": "GHSA-rw99-6hrh-fmjr\nCVE-2024-10963\n",
1212
"assigner": "redhat",
13-
"epss": 0.79,
13+
"epss": 0.78,
1414
"enisaIdProduct": [
1515
{
1616
"id": "0017ce19-21ab-328e-a870-ff7e94ec0f25",

advisories/2024/11/EUVD-2024-3365.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "a208643d-f5b3-3bbc-a5bf-e78841f4a1c9",
44
"description": "A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service.\nThe attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.",
55
"datePublished": "Nov 25, 2024, 7:29:52 AM",
6-
"dateUpdated": "Aug 4, 2026, 10:38:20 PM",
6+
"dateUpdated": "Aug 31, 2026, 12:27:33 AM",
77
"baseScore": 4.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",

advisories/2024/11/EUVD-2024-3384.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "e11d570e-0261-3d98-a912-50b4b3ddff01",
44
"description": "A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data specified directly in environment variables during the build process is also stored as a default values, making it accessible during runtime. Indirect usage of environment variables for SPI options and Quarkus properties is also vulnerable due to unconditional expansion by PropertyMapper logic, capturing sensitive data as default values in all Keycloak versions up to 26.0.2.",
55
"datePublished": "Nov 25, 2024, 7:37:05 AM",
6-
"dateUpdated": "Aug 4, 2026, 7:11:54 PM",
6+
"dateUpdated": "Aug 31, 2026, 12:27:50 AM",
77
"baseScore": 5.9,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",

advisories/2024/11/EUVD-2024-3389.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "2234dbc0-f4b0-3cad-8822-812b8038d79f",
44
"description": "A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.",
55
"datePublished": "Nov 25, 2024, 7:37:04 AM",
6-
"dateUpdated": "Aug 4, 2026, 10:45:03 AM",
6+
"dateUpdated": "Aug 31, 2026, 12:27:42 AM",
77
"baseScore": 6.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",

advisories/2025/01/EUVD-2024-50581.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "05e3a76c-8055-388a-9e22-2ca124296b93",
44
"description": "A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.",
55
"datePublished": "Jan 14, 2025, 5:37:16 PM",
6-
"dateUpdated": "Aug 23, 2026, 1:24:12 AM",
6+
"dateUpdated": "Aug 31, 2026, 4:49:07 PM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",

0 commit comments

Comments
 (0)